<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Romil Patel</title>
    <description>The latest articles on DEV Community by Romil Patel (@romil_patel_542899705cd26).</description>
    <link>https://dev.to/romil_patel_542899705cd26</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3968720%2Fc3ad89b8-e9ec-42d9-bb33-3814f92ddefe.png</url>
      <title>DEV Community: Romil Patel</title>
      <link>https://dev.to/romil_patel_542899705cd26</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/romil_patel_542899705cd26"/>
    <language>en</language>
    <item>
      <title>Does This CVE Affect Me? I Built an AI Agent That Shows Its Evidence</title>
      <dc:creator>Romil Patel</dc:creator>
      <pubDate>Thu, 01 Oct 2026 20:35:17 +0000</pubDate>
      <link>https://dev.to/romil_patel_542899705cd26/does-this-cve-affect-me-i-built-an-ai-agent-that-shows-its-evidence-56b8</link>
      <guid>https://dev.to/romil_patel_542899705cd26/does-this-cve-affect-me-i-built-an-ai-agent-that-shows-its-evidence-56b8</guid>
      <description>&lt;p&gt;&lt;em&gt;This is a submission for the &lt;a href="https://dev.to/challenges/sanity-2026-09-16"&gt;Sanity Challenge, Path One: Ship an Agent That Queries Real Content&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What I Built
&lt;/h2&gt;

&lt;p&gt;I built &lt;strong&gt;AI Security Advisory Assistant&lt;/strong&gt;, an evidence-first tool for researching known vulnerabilities in npm packages.&lt;/p&gt;

&lt;p&gt;A developer enters a package, an optional installed version, and a security question. The app returns documented affected ranges, source-listed fixes, deployment conditions to verify, and links to original advisories. Its Coverage and Activity views show which sources and operations actually completed.&lt;/p&gt;

&lt;p&gt;The app also accepts a &lt;code&gt;package-lock.json&lt;/code&gt; and checks the exact installed versions of direct and transitive dependencies against published advisories. This is an advisory lookup, not a scan of application code or a guarantee that a deployment is safe.&lt;/p&gt;

&lt;h2&gt;
  
  
  Demo
&lt;/h2&gt;

&lt;p&gt;  &lt;iframe src="https://www.youtube.com/embed/cm5qu7IXYig" width="710" height="399"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;

&lt;p&gt;The app currently runs locally and does not yet have a public deployment.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step-by-step screenshots
&lt;/h2&gt;

&lt;p&gt;These screenshots show a local research session and a sample dependency-file check.&lt;/p&gt;

&lt;h3&gt;
  
  
  1. Start a security research question
&lt;/h3&gt;

&lt;p&gt;Open the Research page. Enter the software name and, if known, its installed version.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F5fne9rpdwi4ui5dxvsb1.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F5fne9rpdwi4ui5dxvsb1.png" alt="Empty security research form" width="800" height="453"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  2. Ask a specific, versioned question
&lt;/h3&gt;

&lt;p&gt;For this example, enter &lt;strong&gt;Next.js&lt;/strong&gt;, version &lt;strong&gt;14.2.24&lt;/strong&gt;, and ask whether &lt;strong&gt;CVE-2025-29927&lt;/strong&gt; applies, what fixes are listed, and which deployment conditions need review. Select &lt;strong&gt;Run research&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzhyv39i0emxyb877jcfl.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzhyv39i0emxyb877jcfl.png" alt="Research form filled with the Next.js version and CVE question" width="799" height="449"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  3. Read the research overview
&lt;/h3&gt;

&lt;p&gt;The overview shows advisory findings, affected version ranges, documented fixes, and conditions to verify. Open the original advisory before acting on a result.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbotm4ny3q3g9llsqb7lz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbotm4ny3q3g9llsqb7lz.png" alt="Research overview with advisory findings and fixes" width="800" height="525"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  4. Check coverage before trusting the answer
&lt;/h3&gt;

&lt;p&gt;The Coverage tab records the resolved npm package, how many live advisories were retrieved and matched, whether the Knowledge Base check completed, and the timing of each source. A failed source means incomplete coverage.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqlqstmpcu2e0kmjo41ig.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqlqstmpcu2e0kmjo41ig.png" alt="Coverage tab showing completed OSV and Knowledge Base checks" width="800" height="370"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  5. Inspect the evidence
&lt;/h3&gt;

&lt;p&gt;The Sources tab shows the retrieved Knowledge Base entry and links to original advisory records. I use those links to verify claims and deployment conditions against their sources.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fh1rg7h3jti5cgg7nttl0.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fh1rg7h3jti5cgg7nttl0.png" alt="Sources tab with Knowledge Base and original advisory links" width="800" height="525"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  6. Review the activity trail
&lt;/h3&gt;

&lt;p&gt;The Activity tab shows the operations performed for this request, including package resolution, live lookup, Knowledge Base reads, and record verification.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpyj1u0k3ry2yg1tc6hvt.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpyj1u0k3ry2yg1tc6hvt.png" alt="Activity tab showing the operations performed" width="800" height="449"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  7. Pick a sample lockfile
&lt;/h3&gt;

&lt;p&gt;The repository includes a &lt;a href="https://github.com/romilp619/ai-security-advisory-assistant/blob/main/examples/dependency-demo/package-lock.json" rel="noopener noreferrer"&gt;demo &lt;code&gt;package-lock.json&lt;/code&gt;&lt;/a&gt;. I use it to demonstrate the Dependencies feature.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6sqgcwpfi0emhvqx2zdp.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6sqgcwpfi0emhvqx2zdp.png" alt="Sample package-lock.json in File Explorer" width="800" height="233"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  8. Upload the lockfile
&lt;/h3&gt;

&lt;p&gt;Open &lt;strong&gt;Dependencies&lt;/strong&gt; and choose the lockfile, or drag and drop it onto the upload area. The app parses the JSON as data; it does not install packages or run scripts.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fyzhxm8j4dwoaz51qp6rh.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fyzhxm8j4dwoaz51qp6rh.png" alt="Dependencies upload area for package-lock.json" width="800" height="257"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  9. Review exact dependency matches
&lt;/h3&gt;

&lt;p&gt;The result groups matching source records by installed package and version. Each advisory has a link for reviewing its listed fix and conditions.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpul2kye1bp6ms1wowo8a.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpul2kye1bp6ms1wowo8a.png" alt="Dependency results grouped by package and installed version" width="800" height="517"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  How It Works
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Architecture
&lt;/h3&gt;



&lt;pre data-lang="mermaid"&gt;&lt;code&gt;flowchart TB
  User["Your question"] --&amp;gt; App["Next.js app"]
  App --&amp;gt; Live["OSV.dev"]
  App --&amp;gt; Curated["Sanity Knowledge Base"]
  App --&amp;gt; Model["DeepSeek V4.1 Flash"]
  Live --&amp;gt; Check["Verify evidence"]
  Curated --&amp;gt; Check
  Model --&amp;gt; Check
  Check --&amp;gt; Answer["Cited answer"]&lt;/code&gt;&lt;/pre&gt;



&lt;p&gt;The model helps choose relevant Knowledge Base paths and passages. Application code checks the retrieved evidence and version conclusions before presenting the result.&lt;/p&gt;

&lt;h2&gt;
  
  
  Code
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://github.com/romilp619/ai-security-advisory-assistant" rel="noopener noreferrer"&gt;AI Security Advisory Assistant on GitHub&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The repository includes the application, Sanity schema, advisory importer, sample lockfile, setup guide, screenshots, and verification record.&lt;/p&gt;

&lt;h2&gt;
  
  
  How I Used Sanity
&lt;/h2&gt;

&lt;p&gt;These screenshots show my Sanity setup. Account details, identifiers, and trial information are obscured &lt;strong&gt;in the screenshots&lt;/strong&gt; where visible. No token is shown.&lt;/p&gt;

&lt;h3&gt;
  
  
  1. Keep the existing project and dataset
&lt;/h3&gt;

&lt;p&gt;I configured the app and local Sanity Studio for my existing &lt;strong&gt;AI Security Advisory Assistant&lt;/strong&gt; project and its &lt;code&gt;production&lt;/code&gt; dataset. I did not create a second project or dataset. The project settings screen confirms which project I used.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fneecbcxb1q445tppvej1.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fneecbcxb1q445tppvej1.png" alt="Redacted Sanity project settings for AI Security Advisory Assistant" width="800" height="502"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  2. Import selected source advisories
&lt;/h3&gt;

&lt;p&gt;&lt;code&gt;data/advisory-sources.json&lt;/code&gt; lists original GitHub Security Advisories. &lt;code&gt;npm run ingest&lt;/code&gt; fetches and validates them as a dry run; &lt;code&gt;npm run ingest -- --apply&lt;/code&gt; writes reviewed records into &lt;code&gt;production&lt;/code&gt; using an Editor token kept in my local environment.&lt;/p&gt;

&lt;p&gt;At the time of capture, the curated collection contained &lt;strong&gt;122 published advisory documents&lt;/strong&gt;. The organization activity view records that I attached the dataset to the &lt;strong&gt;Security Advisories&lt;/strong&gt; Knowledge Base and created the &lt;strong&gt;Security Advisor&lt;/strong&gt; Context MCP endpoint.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzq2xxepnru3u7xr3cc84.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzq2xxepnru3u7xr3cc84.png" alt="Redacted Sanity activity showing dataset attachment and Context MCP endpoint creation" width="800" height="497"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  3. Build a navigable Knowledge Base
&lt;/h3&gt;

&lt;p&gt;In Sanity Context, I selected the &lt;code&gt;production&lt;/code&gt; dataset as the source and built its entries. At the time of capture, the screen showed &lt;strong&gt;122 source documents&lt;/strong&gt;, a &lt;strong&gt;Ready&lt;/strong&gt; source, and &lt;strong&gt;28 generated entries&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Documents are the stored advisories. Entries organize related information into shorter, cited paths that the agent can navigate. Their counts differ because an entry can draw on multiple documents, and the counts can change after a rebuild.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fw890eri966p4dsqro2j7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fw890eri966p4dsqro2j7.png" alt="Sanity Context source showing 122 documents and 28 ready Knowledge Base entries" width="800" height="421"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  4. Retrieve and verify at request time
&lt;/h3&gt;

&lt;p&gt;The Next.js server connects to the &lt;strong&gt;Security Advisor&lt;/strong&gt; MCP endpoint and calls &lt;code&gt;initial_context&lt;/code&gt; and &lt;code&gt;knowledge_base_read&lt;/code&gt;. It uses a separate project Viewer token to read the published advisory records behind cited entries.&lt;/p&gt;

&lt;p&gt;The model helps select relevant paths and passages. Application code checks that paths, quotes, source links, and version conclusions agree with the records. The server also queries OSV.dev for live npm advisories, so results are not limited to the curated documents.&lt;/p&gt;

&lt;h3&gt;
  
  
  5. Refresh after imports
&lt;/h3&gt;

&lt;p&gt;When source records change, I rerun ingestion, rebuild the existing Knowledge Base, wait for &lt;strong&gt;Entries up to date&lt;/strong&gt;, and run a live test and browser query. The Context endpoint and Viewer tokens stay server-side. The Editor token is only for importing, never for the public app.&lt;/p&gt;

&lt;h3&gt;
  
  
  6. Inspect the generated evidence
&lt;/h3&gt;

&lt;p&gt;The Entries view groups advisories by package and topic. This Next.js entry brings related cache-poisoning and XSS records together with affected ranges, fixes, conditions, and numbered source citations. The agent can navigate to a relevant entry through MCP instead of reading every source document.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fykrjtxvjrqde7rm8rc4x.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fykrjtxvjrqde7rm8rc4x.png" alt="Sanity Knowledge Base entry grouping Next.js advisories with version details and citations" width="799" height="441"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Sanity Project Details
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Project ID:&lt;/strong&gt; &lt;code&gt;o7qa6o3y&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Dataset:&lt;/strong&gt; &lt;code&gt;production&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Knowledge Base:&lt;/strong&gt; Security Advisories&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Context MCP endpoint:&lt;/strong&gt; Security Advisor&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Built With
&lt;/h2&gt;

&lt;p&gt;Next.js, React, TypeScript, Node.js, Sanity Content Lake, Sanity Context MCP, OSV.dev, GitHub Security Advisories, Vercel AI SDK, DeepSeek V4.1 Flash through Token Harbor, Vitest, and Playwright.&lt;/p&gt;

&lt;h2&gt;
  
  
  Final Thoughts
&lt;/h2&gt;

&lt;p&gt;For setup, start with &lt;a href="https://github.com/romilp619/ai-security-advisory-assistant/blob/main/docs/GITHUB_SETUP.md" rel="noopener noreferrer"&gt;Setup&lt;/a&gt;. For the exact tests performed, see &lt;a href="https://github.com/romilp619/ai-security-advisory-assistant/blob/main/VERIFICATION.md" rel="noopener noreferrer"&gt;VERIFICATION.md&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Thanks for reading.&lt;/p&gt;

</description>
      <category>sanitychallenge</category>
      <category>devchallenge</category>
      <category>ai</category>
      <category>sanity</category>
    </item>
    <item>
      <title>SmartStadiumX 🏟️ Bringing Real-Time Intelligence to Stadium Experiences</title>
      <dc:creator>Romil Patel</dc:creator>
      <pubDate>Sun, 07 Jun 2026 04:58:27 +0000</pubDate>
      <link>https://dev.to/romil_patel_542899705cd26/smartstadiumx-bringing-real-time-intelligence-to-stadium-experiences-532n</link>
      <guid>https://dev.to/romil_patel_542899705cd26/smartstadiumx-bringing-real-time-intelligence-to-stadium-experiences-532n</guid>
      <description>&lt;h2&gt;
  
  
  What I Built
&lt;/h2&gt;

&lt;p&gt;SmartStadiumX is a full-stack MERN application designed to improve the experience of attending large sporting events.&lt;/p&gt;

&lt;p&gt;Modern stadiums often struggle with three major challenges:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Crowd congestion in high-traffic areas&lt;/li&gt;
&lt;li&gt;Long food and service queues&lt;/li&gt;
&lt;li&gt;Poor venue navigation for attendees&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;SmartStadiumX tackles these issues through a real-time platform that connects fans, administrators, staff members, and vendors into a single ecosystem.&lt;/p&gt;

&lt;p&gt;The platform includes four dedicated portals:&lt;/p&gt;

&lt;h3&gt;
  
  
  Fan Portal
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Live stadium navigation&lt;/li&gt;
&lt;li&gt;Real-time congestion monitoring&lt;/li&gt;
&lt;li&gt;Food ordering directly from seats&lt;/li&gt;
&lt;li&gt;QR ticket access&lt;/li&gt;
&lt;li&gt;Rewards and loyalty points&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Admin Command Centre
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Live crowd heatmaps&lt;/li&gt;
&lt;li&gt;Revenue and order analytics&lt;/li&gt;
&lt;li&gt;Emergency alert broadcasting&lt;/li&gt;
&lt;li&gt;Zone occupancy management&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Staff Portal
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Assigned zone monitoring&lt;/li&gt;
&lt;li&gt;Incident response tracking&lt;/li&gt;
&lt;li&gt;Crowd rerouting assistance&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Vendor Portal
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Menu management&lt;/li&gt;
&lt;li&gt;Product availability controls&lt;/li&gt;
&lt;li&gt;Live order tracking&lt;/li&gt;
&lt;li&gt;Status updates for customers&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The application uses Socket.IO to provide real-time communication between all connected users, creating a dynamic stadium management experience.&lt;/p&gt;




&lt;h2&gt;
  
  
  Link of My Project
&lt;/h2&gt;


&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
    &lt;div class="c-embed__content"&gt;
      &lt;div class="c-embed__body flex items-center justify-between"&gt;
        &lt;a href="https://smartstadiumx-390235103315.asia-south1.run.app/login" rel="noopener noreferrer" class="c-link fw-bold flex items-center"&gt;
          &lt;span class="mr-2"&gt;smartstadiumx-390235103315.asia-south1.run.app&lt;/span&gt;
          

        &lt;/a&gt;
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;


&lt;h3&gt;
  
  
  Repository
&lt;/h3&gt;

&lt;p&gt;GitHub: &lt;a href="https://github.com/romilp619/SmartStadiumX" rel="noopener noreferrer"&gt;https://github.com/romilp619/SmartStadiumX&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Screenshots
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fo7ufl883t6s55ad4pa54.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fo7ufl883t6s55ad4pa54.png" alt="SmartStadiumX login page featuring quick demo login buttons for Fan, Admin, Staff, and Vendor roles" width="800" height="449"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxxskfu6b8d0yw0p6ecak.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxxskfu6b8d0yw0p6ecak.png" alt="Register first and then login page" width="800" height="470"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fauqodsafwrcoutdy4i34.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fauqodsafwrcoutdy4i34.png" alt="Dashborad after login" width="799" height="429"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fjt63opl85mh7dops1vy9.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fjt63opl85mh7dops1vy9.png" alt="Live score dashboard" width="799" height="441"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F76x5xps5cbzbj51rd4yy.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F76x5xps5cbzbj51rd4yy.png" alt="Food ordering page" width="800" height="412"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F33hw4yjsr1ugldsfscs8.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F33hw4yjsr1ugldsfscs8.png" alt="Order Tracking" width="800" height="431"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fi8ynajjrxi73725077eh.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fi8ynajjrxi73725077eh.png" alt="Just Click on vendor button and login as vendor page" width="800" height="476"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fcsbrv33oyapm4kwmnb63.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fcsbrv33oyapm4kwmnb63.png" alt="Vendor Kitchen page" width="800" height="368"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The application includes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Interactive stadium maps&lt;/li&gt;
&lt;li&gt;Real-time congestion visualization&lt;/li&gt;
&lt;li&gt;Live order tracking&lt;/li&gt;
&lt;li&gt;Multi-role dashboards&lt;/li&gt;
&lt;li&gt;Vendor management tools&lt;/li&gt;
&lt;li&gt;Analytics dashboards&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  The Comeback Story
&lt;/h2&gt;

&lt;p&gt;SmartStadiumX started as an ambitious idea but remained unfinished due to the complexity of coordinating multiple user roles and real-time interactions.&lt;/p&gt;

&lt;p&gt;Before this challenge, several important pieces were either incomplete or only partially implemented:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Real-time crowd monitoring workflows&lt;/li&gt;
&lt;li&gt;Vendor order management&lt;/li&gt;
&lt;li&gt;Fan rewards integration&lt;/li&gt;
&lt;li&gt;Socket.IO synchronization across dashboards&lt;/li&gt;
&lt;li&gt;Demo data seeding for easier testing&lt;/li&gt;
&lt;li&gt;Multi-role user experience refinements&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The Finish-Up-A-Thon motivated me to revisit the project and push it across the finish line.&lt;/p&gt;

&lt;p&gt;During the challenge I:&lt;/p&gt;

&lt;p&gt;✅ Completed the end-to-end food ordering flow&lt;/p&gt;

&lt;p&gt;✅ Finished real-time order updates using WebSockets&lt;/p&gt;

&lt;p&gt;✅ Improved congestion monitoring and zone management&lt;/p&gt;

&lt;p&gt;✅ Added role-specific dashboards&lt;/p&gt;

&lt;p&gt;✅ Implemented demo account support&lt;/p&gt;

&lt;p&gt;✅ Enhanced UI consistency with Tailwind CSS&lt;/p&gt;

&lt;p&gt;✅ Created a seeded demo environment for quick evaluation&lt;/p&gt;

&lt;p&gt;What was once a collection of partially connected features became a complete, functional platform demonstrating how technology can improve large-scale event experiences.&lt;/p&gt;




&lt;h2&gt;
  
  
  My Experience with GitHub Copilot
&lt;/h2&gt;

&lt;p&gt;GitHub Copilot played a major role in helping me finish SmartStadiumX.&lt;/p&gt;

&lt;p&gt;Throughout development, Copilot assisted with:&lt;/p&gt;

&lt;h3&gt;
  
  
  Socket.IO Integration
&lt;/h3&gt;

&lt;p&gt;Copilot accelerated event handler creation, client-server communication logic, and real-time update workflows.&lt;/p&gt;

&lt;h3&gt;
  
  
  React Development
&lt;/h3&gt;

&lt;p&gt;It helped scaffold components, routing structures, hooks, and state management patterns, reducing repetitive work.&lt;/p&gt;

&lt;h3&gt;
  
  
  Express APIs
&lt;/h3&gt;

&lt;p&gt;Copilot generated boilerplate CRUD endpoints, middleware patterns, and request validation structures that allowed me to focus on application logic.&lt;/p&gt;

&lt;h3&gt;
  
  
  MongoDB &amp;amp; Mongoose
&lt;/h3&gt;

&lt;p&gt;Schema creation, model relationships, and query patterns became significantly faster with Copilot suggestions.&lt;/p&gt;

&lt;h3&gt;
  
  
  Refactoring &amp;amp; Debugging
&lt;/h3&gt;

&lt;p&gt;When revisiting older code, Copilot helped identify cleaner implementations and reduced the time needed to understand previously unfinished sections.&lt;/p&gt;

&lt;p&gt;The biggest benefit wasn't simply writing code faster—it was maintaining momentum. Instead of getting stuck on implementation details, I could continue building features and focus on delivering a complete product.&lt;/p&gt;




&lt;h2&gt;
  
  
  Tech Stack
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Frontend
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;React (Vite)&lt;/li&gt;
&lt;li&gt;Tailwind CSS&lt;/li&gt;
&lt;li&gt;React Router&lt;/li&gt;
&lt;li&gt;Socket.IO Client&lt;/li&gt;
&lt;li&gt;Recharts&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Backend
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Node.js&lt;/li&gt;
&lt;li&gt;Express.js&lt;/li&gt;
&lt;li&gt;MongoDB&lt;/li&gt;
&lt;li&gt;Mongoose&lt;/li&gt;
&lt;li&gt;Socket.IO&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Real-Time Features
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Live crowd updates&lt;/li&gt;
&lt;li&gt;Instant order synchronization&lt;/li&gt;
&lt;li&gt;Multi-dashboard event broadcasting&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  What's Next?
&lt;/h2&gt;

&lt;p&gt;Future improvements I would like to explore:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;AI-powered crowd prediction&lt;/li&gt;
&lt;li&gt;Indoor turn-by-turn navigation&lt;/li&gt;
&lt;li&gt;Dynamic vendor staffing recommendations&lt;/li&gt;
&lt;li&gt;Push notifications for congestion alerts&lt;/li&gt;
&lt;li&gt;Mobile app support&lt;/li&gt;
&lt;li&gt;Integration with real stadium sensor systems&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;SmartStadiumX demonstrates how real-time technology can transform the stadium experience for fans while giving venue operators better visibility and control.&lt;/p&gt;

</description>
      <category>devchallenge</category>
      <category>githubchallenge</category>
    </item>
  </channel>
</rss>
