NFSFU234 Open Source Day: Three Tools, One Scope
October 5, 2026
•4 min read
•64 views
•NFSFU234 Open Source Day

In our one-year WishIT post, we mentioned we were trying something we'd never done before: NFSFU234 Open Source Day, our first, landing August 25. That's today.
We're not asking anyone to take the pitch on faith. The tool's own output, against our own site, is the evidence.
NFORSHIFU234 Dev is the software studio brand under NFORSHIFU LOGICFORGE LTD. Try ShotSweep: shotsweep.nforshifu234dev.com · TourGuide: tourguide.nforshifu234dev.com · FormValidation: formvalidation.nforshifu234dev.com Built by NFORSHIFU234 Dev. Three tools, one scope, out in the open — the way we think open source should work.
Read Also: 365 Days of WishIT: The Engineering Story Behind It → We teased this event at the end of that post. This is the follow-through.Here's what actually shipped, and why we think it's a bigger story than three separate release notes.
What shipped
ShotSweep — new, v1.1.0
A CLI tool that captures screenshots of a site and compares them between runs, so a visual regression gets caught before a user finds it, not after. A build can pass, every test can pass, a page can return HTTP 200 — and still look broken. That's the gap this closes.- Full sitemap capture — point it at a sitemap and it resolves every URL, including sitemap indexes
- Light and dark mode, multiple viewports — captured in the same run
- Authenticated pages — form login, saved sessions, bearer tokens, custom headers, cookies
- --replace-origin — reuse a production sitemap against localhost or staging without maintaining a separate URL list
- Deterministic diffing — pixel comparison between two runs, configurable thresholds, non-zero exit code on a real regression, built to gate CI the same way a failing test would
TourGuide 2.0.2 — major update
- Project-wide configuration —
defineConfig()andlet an app set tour defaults once instead of repeating props on every instance - A full accessibility pass — focus trapping, keyboard navigation, ARIA roles, screen-reader support
- Its first real automated test suite — Vitest coverage for configuration, accessibility, and tooltip positioning
- Several positioning and cleanup fixes — tooltips no longer render on the wrong side near viewport edges, and a target element's styles are now correctly restored after a tour ends
FormValidation 3.0.0 — the largest release in the library's history
- Always-async validation API —
.submit(),.validate(), and.validateInput()now consistently return aPromise - File and image upload validation — type, size, and dimension checks
- Site-wide configuration —
configureForms()andautoInit()validate rules across an entire site's forms from one place instead of form by form - A real Jest test suite and CI-gated releases
The part that matters more than any single feature
FormValidation and TourGuide started as separate, unscoped npm packages, built years apart. As of today, both move to the@nfsfu234 scope, joining ShotSweep, which launched scoped from day one.
For the first time, all three tools live under one namespace instead of three unrelated package names:
That's the actual headline. Three side projects, built at different points over several years, are as of today one ecosystem.
The self-test
Before shipping ShotSweep, we ran it against our own documentation site — 28 routes, light and dark mode, sectioned at 1440×900. Both runs came back with 136 manifest entries and zero capture errors.
We're not asking anyone to take the pitch on faith. The tool's own output, against our own site, is the evidence.
The honest part: we removed a feature
FormValidation used to offer client-side password hashing. As of 3.0.0, it's gone, along with the dependency it needed. We're not framing that as a fix for a bug , it wasn't broken. It just never did what it looked like it did. Hashing a password in the browser before sending it doesn't protect it in transit, and any backend worth using is already handling that correctly on its own side. The feature gave the appearance of security without providing any. It took a 3.0.0-scale release for us to justify pulling it, but it needed to go. That change is a small line in a changelog. We think it's worth calling out on its own, because "we removed something that looked useful but wasn't" is a harder call to make than adding a new flag, and we'd rather be the kind of team that makes it.What this means going forward
All three tools are MIT licensed and open for contribution starting today: Community testing is already a formal part of how we ship WishIT — real usage surfacing real problems, treated as direction rather than a backlog item. The same principle applies here. We'd rather find what's broken through people actually using these tools than assume the release notes cover everything. More open-source work is coming out of NFORSHIFU234 Dev. This was the first NFSFU234 Open Source Day. It won't be the last.NFORSHIFU234 Dev is the software studio brand under NFORSHIFU LOGICFORGE LTD. Try ShotSweep: shotsweep.nforshifu234dev.com · TourGuide: tourguide.nforshifu234dev.com · FormValidation: formvalidation.nforshifu234dev.com Built by NFORSHIFU234 Dev. Three tools, one scope, out in the open — the way we think open source should work.