{
  "id": 6693978,
  "title": "I am just a developer 😭",
  "url": "https://urgent.news/2026/09/11/i-am-just-a-developer",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-11T03:08:16.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/banana_cool/i-am-just-a-developer-1gpn"
  },
  "original_language": "en",
  "account": "So the story goes like this. The developer created a package named UI Tools, but an earlier version (0.1.0-beta through 0.1.8-beta) had a serious security flaw in its terminal feature. The issue was inadequate authentication controls for the terminal functionality. The developer addressed the vulnerability and updated the package to version 0.2.1-beta, which now has a stricter security model. The terminal feature is no longer part of the default export; it must be explicitly imported.\n\nThe developer is frustrated by AI-generated summaries that label them as a \"malicious actor\" or \"threat actor,\" as some security databases inaccurately report versions as affected, such as DependencyWatch, which incorrectly lists version 1.0.0 as affected. The developer clarified that their package does not install malicious code automatically; it requires explicit use of the terminal functionality.\n\nThe developer also pointed out that being a developer who made a security mistake does not equate to being a threat actor. They acknowledge that putting a server-side terminal/PTY feature in a package called UI Tools may have been an architectural mistake but not a malicious one. Despite the past incident, the developer emphasizes that they are still just a developer and not a threat actor.",
  "summary": "So here's the thing. I made a package called UI Tools , and some early versions were flagged for a serious security vulnerability involving its terminal feature. The affected versions were 0.1.0-beta through 0.1.8-beta . The problem was that the terminal functionality did not have adequate authentication controls. I fixed it. The package has since gone through several security changes, and the…",
  "key_points": [
    "Developer released UI Tools package with terminal vulnerability",
    "Version 0.2.1-beta fixed security flaw in terminal feature",
    "Developer frustrated by AI summaries labeling them as threat actor"
  ],
  "editors_take": "The developer's frustration highlights a need for more nuanced reporting on security vulnerabilities, as inaccurate labeling can have serious repercussions for individuals who make mistakes, not malicious actors.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}