Observed Signal · Apr 20, 2026 · Technical Release · Source: DEV Community · Impact: 2/5 · Sentiment: Positive
VS Code Extension Validates VAST XML As You Type
An engineer published vastlint, an open-source VAST linter, and released a VS Code extension that validates VAST XML in-editor. vastlint-core is a Rust library with 108 rules; the VS Code extension loads it as a WebAssembly module so validation runs locally with no network calls. The extension highlights spec violations inline, auto-detects VAST versions, integrates with Problems panel, and supports per-rule configuration in settings.json. The same core powers a CLI, a RapidAPI REST endpoint, an MCP server, and an online validator at vastlint.org. The tool targets common failure modes in video/CTV tags to catch errors before QA or partner delivery.
Provides practical, open-source developer tooling that can reduce VAST-related delivery failures for video and CTV campaigns by catching spec violations earlier; useful to ad ops and engineering teams but not industry-shifting.
Track IAB Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- vastlint is an open-source VAST linter with 108 rules written in Rust.
- A VS Code extension was released that runs the validator in-process via WebAssembly.
- The core library (vastlint-core) is published on crates.io and powers a CLI, a RapidAPI REST API, an MCP server, and an online validator at vastlint.org.
- The extension auto-detects VAST version, shows inline squiggles and hover tooltips with rule IDs, and integrates with the VS Code Problems panel.
- Typical validation of a real-world CTV tag takes under 100 microseconds (library); WASM overhead in the editor is imperceptible.
Connected Companies & Entities
3 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
VS Code Extensions Enable Supply-Chain Attacks
A malicious VS Code extension (specstudio.code-wakatime-activity-tracker) was found dropping a Zig-compiled binary onto developer machines as part of a campaign researchers call "GlassWorm." The binary persisted as a background process, harvested sensitive files (e.g., .env, SSH keys, ~/.aws/credentials, .git/config) and exfiltrated them to a command-and-control server, with the capability to receive instructions to modify source code. The article explains that VS Code extensions run with full user permissions (no sandbox) and outlines a 30-minute audit workflow—listing checks, disabling auto-updates, and file-watch scripts—to reduce risk. The author audited 47 extensions, removing 16 and flagging 11 for inspection, and calls for permission scoping, sandboxing, and code signing for extensions.
Developer Builds Autonomous Tailwind Linter to Clean AI CSS
Rashad Husanli published a DEV post (May 18, 2026) describing why he built aura-lint, a zero-dependency autonomous Tailwind linter that finds and auto-fixes messy AI-generated CSS. The tool includes an autonomous --fix mode that converts hardcoded pixel classes into standard Tailwind spacing using a division-by-4 formula, a configurable auralint.json for theme detection and hex-to-Tailwind mappings, and a plugin architecture to add project-specific rules. Husanli positions aura-lint as a local gatekeeper to avoid repeatedly sending cleanup prompts to LLMs and to keep UI code aligned with a project's design system. The project is published on GitHub (modoldern/aura-lint) and is presented as extensible and open-source-friendly.
ESLint Plugin to Catch AI Coding Mistakes
The author analyzed roughly 500 AI-generated coding mistakes and created eslint-plugin-llm-core, an ESLint plugin with 20 rules designed to catch recurring errors produced by LLM coding assistants. The plugin targets patterns such as async/await misuse (e.g., async callbacks to array methods that return Promise arrays), empty catch blocks, missing null checks, magic numbers, deep nesting, inconsistent error handling and other LLM-prone anti-patterns. Rules are educationally worded to teach correct patterns and complement typescript-eslint rather than replace it. The project is published on GitHub (pertrai1/eslint-plugin-llm-core) and npm (eslint-plugin-llm-core), with zero-config recommended rules and an install example (npm install -D eslint-plugin-llm-core). The author plans auto-fixes, broader logging-library detection, and ongoing research to validate impact on AI-generated code quality.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
