Sign in

Darcy Clarke

@darcyclarke.me
1.8K followers 378 following 178 posts

@vlt.sh Founder & Chief End-User Officer Prev: GitHub, npm & Themify Co-Founder

PostsRepliesMedia
Reposted by Darcy Clarke
Ruy Adorno @ruyadorno.com · 29/09/2026
Thanks @vlt.io for contributing! 🔈 audio on to hear it from @nodeland.dev
0114
Reposted by Darcy Clarke
NodeConf.eu @nodeconf.eu · 8h
Thank you everyone for joining us at #NodeConfEU 2026! 💚 We hope you enjoyed it as much as we did, and we can’t wait to see you again next year! 📅👩‍💻 #TechCommunity #NodeCommunity
0209
Darcy Clarke @darcyclarke.me · 24/09/2026
A new home for your open source... In case you're fed up with that old one
030
Reposted by Darcy Clarke
Ruy Adorno @ruyadorno.com · 15/09/2026
I've been back to improving the vlt CLI for the last month, here's a peek at what we shipped since our major v1.0 release! 🚀 www.vlt.io/blog/vlt-cli...
vlt.io
A month of vlt CLI updates | vlt /vōlt/
Since 1.0, vlt has shipped install-speed wins, security hardening, and quality-of-life CLI fixes.
051
Reposted by Darcy Clarke
NodeConf.eu @nodeconf.eu · 02/09/2026
🚀 Thrilled to announce @vlt.io as a #Silver #Sponsor of #NodeConfEU 2026! Thank you! 💛 Your partnership is helping us create something truly special in the #Node.js #community! 🎟️ nodeconf.eu
1105
Reposted by Darcy Clarke
Kate Holterhoff, PhD @kateholterhoff.com · 12/08/2026
Dependency hell!! Oh no, w @darcyclarke.me at @nodejs.org Interactive at @renderatl.com #NodeJSInteractive
083
Darcy Clarke @darcyclarke.me · 04/08/2026
Excited to share vlt 1.0 along with our hosted registries & ecosystem mirrors now GA! A drop-in npm replacement, built so nothing runs on your machine just because you typed install. → faster delivery → malware blocking at the registry layer → graph-native querying
14416
Reposted by Darcy Clarke
Pooya Parsa @pi0.io · 28/07/2026
⛰️ mountx :: mount JavaScript as a real filesystem! Write ~6 lines of JS, get a real directory any process can read & write: editors, CLIs, AI agents. Rootless on Linux (FUSE) and macOS (NFSv3 with no kernel extensions). ~Pure JS, zero deps. mountx.vercel.app
6314
Reposted by Darcy Clarke
vlt /vōlt/ @vlt.io · 23/07/2026
A familiar story: the build crashes, so you rm -rf node_modules && rm package-lock.json, then reinstall to get your dev env back. But once the lockfile's gone, your ^ ranges take over. npm install can grab the newest in-range version of everything: poison included when there's a supply chain attack
vlt.io
Ship JavaScript? Hang onto your lockfile | vlt /vōlt/
Pinning dependencies in package.json won't save you in a supply-chain attack — a committed lockfile does. Here's why, and how to install so it holds.
153
Reposted by Darcy Clarke
Ruy Adorno @ruyadorno.com · 21/07/2026
Love to see all the pieces coming together! Just ran a `vlt publish --scope=':workspace'` cmd that mass-publishes all my workspaces in a given project to a private registry in my vlt.io account ❤️
vlt.io
Home | vlt /vōlt/
Package registries for teams that move fast
182
Reposted by Darcy Clarke
vlt /vōlt/ @vlt.io · 16/07/2026
There is CSS... but what if I told you there is such a thing as DSS? Dependency Selector Syntax is an expressive DSL written as a homage to CSS. Use it to inspect malicious dependencies in your repo docs.vlt.io/cli/selector...
1103
Reposted by Darcy Clarke
vlt /vōlt/ @vlt.io · 07/07/2026
If you regularly publish to the npm registry, you might be concerned about package size 😁 But have you heard of PACKUMENT size? News flash: how often you publish, how long your manifest is, how many *exports* you have, can also eventually prevent you from publishing!
vlt.io
Why Drizzle ORM couldn't publish new releases on NPM for a month | vlt /vōlt/
Drizzle ORM recently hit a 100 MB limit in the npm registry and couldn't ship new releases for weeks. What is this limit?
183
Reposted by Darcy Clarke
Nicholas C. Zakas @humanwhocodes.com · 29/06/2026
13 years ago today I made the first commit to the ESLint Git repo. It’s hard to believe that this project I cobbled together in my spare time over a couple of weeks is still going strong. I’ve been doing a lot of reflecting over these years and the journey it’s been. A thread.
A birthday cake for ESLint, with candles of 1 and 3 at the top for 13 and the ESLint logo with "Happy birthday" on the side.
3899
Darcy Clarke @darcyclarke.me · 01/06/2026
⚡️ We're looking for a DevRel person at @vlt.sh - based in our Toronto 🇨🇦 HQ. You'll work closely w/ me & should love the idea of owning various aspects of product marketing. You'll be vlt's biggest fan & advocate; molding this unique role in a way that plays to your strengths & ours.
22417
Reposted by Darcy Clarke
Feross @feross.bsky.social · 20/05/2026
Today is a big day for @socket.dev. We raised a $60M Series C at a $1B valuation, led by Thrive Capital. 20,000+ orgs, 1.5M repos protected, 1,000+ supply chain attacks blocked per week. 3/5 FAANG companies are customers. We're just getting started.
118514
Reposted by Darcy Clarke
luke karrys @lukekarrys.com · 12/05/2026
today is a great day to rm -rf your work computer so you can take a little break
4282
Reposted by Darcy Clarke
Socket @socket.dev · 11/05/2026
84 TanStack npm package artifacts were compromised in the ongoing Mini Shai-Hulud supply chain attack, adding suspected CI credential-stealing malware. Socket flagged every malicious version within six minutes of publication. Details: socket.dev/blog/tanstac...
socket.dev
Tanstack npm Packages Compromised in Ongoing Mini Shai-Hulud...
Socket detected 84 compromised TanStack npm packages modified with suspected CI credential-stealing malware.
56735
Reposted by Darcy Clarke
Wes @notwes.bsky.social · 05/05/2026
The hidden gem is that @nodejs.org majors and LTS cycles got WAY easier to understand: 2026 -> v26 2027 -> v27 2028 -> v28 ... Aall of them go LTS for 18 months meaning each major is supported for 2 years. The new graphic tells the best story here: nodejs.org/en/blog/anno...
nodejs release schedule chat. Bars for each major showing 6mo unstable, 6mo current, then 18mo LTS for each major. The best interpretation is that each yearly release is stable and supported for 2 full years.
210825
Darcy Clarke @darcyclarke.me · 29/04/2026
While others race away from Open Source, @vlt.sh is doubling down. 🖤⚡ Today we’re announcing our renewed commitment to @opensourcepledge.com and investing back into the ecosystem. www.vlt.io/blog/doublin...
vlt.io
Doubling Down on Open Source | vlt /vōlt/
We've doubled our open source pledge contribution to $14,000 ($3,500 per full-time engineer)
26511
Reposted by Darcy Clarke
Oliver Medhurst @honk.foo · 23/04/2026
porffor.dev is now served by a Porffor-compiled TS native binary!
A screenshot of porffor.dev:

new! This page is served by a Porffor-compiled TS binary!
[live stats] memory 4.0mb | binary 287kb | requests 210 | uptime 3h 21m
1317623
Darcy Clarke @darcyclarke.me · 05/04/2026
📖 This article by @sarahgooding.bsky.social at @socket.dev highlights a concerning trend (ref. socket.dev/blog/attacke...) 📕 Story time: this kind of supply chain targeting isn't unique. I myself & everyone on our team @vlt.sh have been the targets of consistent, concerted efforts.
socket.dev
Attackers Are Hunting High-Impact Node.js Maintainers in a C...
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
2179
Reposted by Darcy Clarke
luke karrys @lukekarrys.com · 02/04/2026
this is one of my favorite parts of the @vlt.sh CLI. it uses @socket.dev security data to prevent known malware from running lifecycle scripts like postinstall! and it’s powered by queries under the hood so you could make it as granular as you wanted (but we ship with safe defaults)
0167
Reposted by Darcy Clarke
Feross @feross.bsky.social · 02/04/2026
We’re seeing cases where teams can’t explain how they were compromised by the Axios incident because it doesn’t show up in their project's lockfile. The blast radius here is much larger than it looks. Deep dive into the messy reality of modern dependency resolution → socket.dev/blog/hidden-...
socket.dev
The Hidden Blast Radius of the Axios Compromise - Socket
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
01711
Darcy Clarke @darcyclarke.me · 02/04/2026
I heard you like fast package managers? What about fast registries? It's been a roller coaster of a month but our team has made some serious headway w/ even more improvements in the works. Gotta keep the registry fast so y'all can nab the next Claude Code leak.
2131
Darcy Clarke @darcyclarke.me · 01/04/2026
tldr; if you used @vlt.sh as your package manager, then you were protected the minute @socket.dev flagged the malicious packages in the `axios` attack yesterday. The best time to switch your package manager was 48hrs ago, the next best time is right now. More below: blog.vlt.sh/blog/vlt-build
blog.vlt.sh
Introducing Phased Package Installations
When you run vlt install, packages are downloaded and extracted to node_modules, but no lifecycle scripts execute.
1137
Darcy Clarke @darcyclarke.me · 01/04/2026
I'm still waiting on the "Vestro" announcement from @vercel.com today - where it's a slop fork of Astro...
180
Reposted by Darcy Clarke
varlock.dev @varlock.dev · 09/03/2026
🙌
041
Reposted by Darcy Clarke
James Snell @jasnell.me · 03/03/2026
Fixed up some perf issues and benchmark bugs in the new-streams reference impl ... some highlights running comparisons on @nodejs.org @deno.land and @bun.sh ... note each column is just looking at the one runtime, not comparing runtimes against each other ...
2142
Darcy Clarke @darcyclarke.me · 02/03/2026
When does slop become soup? Like... delicious soup
020
Reposted by Darcy Clarke
Kevin Deng @sxzz.dev · 26/02/2026
🚀 Coming in the next version of tsdown: built-in Node.js SEA (Single Executable Applications) support! Now you can bundle your JS apps into a standalone executable with a single command: tsdown --exe
48813
Reposted by Darcy Clarke
Rebane @rebane2001.bsky.social · 24/02/2026
i built an entire x86 CPU emulator in CSS (no javascript) you can write programs in C, compile them to x86 machine code with GCC, and run them inside CSS lyra.horse/x86css/
1322610856
Darcy Clarke @darcyclarke.me · 04/02/2026
Agent skills are the new postinstall scripts... #changemymind
162
Darcy Clarke @darcyclarke.me · 03/02/2026
What do people use to stay up to date with/monitor socials these days? My feed is 🔥 with AI tools & I feel like my meat brain & thumbs can't process the thousands of experiments/insights. Do I just spin up OpenClaw & make it monitor socials w/ daily recaps?
140
Reposted by Darcy Clarke
Evert Pot @evertpot.com · 30/01/2026
Doing some analytics with #NPM and this is the distribution of how many downloads NPM packages typically get.
Pie chart. 3.3M NPM packages. 81% of packages has less than 10 downloads per week. 12% between 10 and 100. 3.2% between 100 and 1000. 1.8% between 1000 and 10K. 1.1% between 10K and 1M and 0.2% over 1M
281
Darcy Clarke @darcyclarke.me · 30/01/2026
The @vlt.sh benchmark suite has been updated to include the yarn v6 canaries (still a WIP & improving all the time): benchmarks.vlt.sh
0114
Reposted by Darcy Clarke
Nicholas C. Zakas @humanwhocodes.com · 29/01/2026
I was recently on the Changelog podcast to talk about npm's security issues, what can be done, and why the npm registry is unique amongst programming language source code registries.
1123
Reposted by Darcy Clarke
Jordan Harband @jordan.har.band · 29/01/2026
nvm.sh users: please upgrade to github.com/nvm-sh/nvm/r... if you're using `wget` on your system, to fix a medium vulnerability (github.com/nvm-sh/nvm/s...).
github.com
Release v0.40.4 · nvm-sh/nvm
Bug Fixes sanitize NVM_AUTH_HEADER in wget path nvm_has_colors: also check if stdout is a terminal nvm_strip_path: avoid gawk-specific RT variable for mawk compatibility nvm_get_default_packages: ...
164
Darcy Clarke @darcyclarke.me · 29/01/2026
Annnnnd it's gone. "Fed Rescinds Software Supply Chain Mandates Making SBOMs Optional". A lot of SecOps folks made a killing off this box checking. Hopefully they banked the money somewhere other than South Park: socket.dev/blog/federal...
media.tenor.com
a man in a suit and tie is sitting at a desk with a computer and the word and written on it
ALT: a man in a suit and tie is sitting at a desk with a computer and the word and written on it
020
Reposted by Darcy Clarke
Software Engineering Daily @softwaredaily.bsky.social · 22/01/2026
Darcy Clarke and Ruy Adorno are longtime npm CLI maintainers and Node.js contributors. They join @joshuakgoldberg.com to discuss vlt, a new package manager and registry designed to improve performance, security, and developer experience. @darcyclarke.me @ruyadorno.com bit.ly/3YNGniF
softwareengineeringdaily.com
Next-Gen JavaScript Package Management with Ruy Adorno and Darcy Clarke - Software Engineering Daily
Package management sits at the foundation of modern software development, quietly powering nearly every software project in the world. Tools like npm and Yarn have long been the core of the JavaScript...
053
Darcy Clarke @darcyclarke.me · 15/01/2026
💙 20yrs since $(this) thing made you fall in love w/ the DOM & CSS selectors. Never forget the amazing work @johnresig.com & team did to make this happen & then ensure the awesomeness got standardized in Web APIs like querySelector() & querySelectorAll(). John, thanks for all the $ 😉
070
Reposted by Darcy Clarke
HalfStack @halfstackconf.bsky.social · 09/01/2026
@lukekarrys.com joins HalfStack Phoenix. A practical story about building for kids, using NFC cards to control music, and turning everyday interactions into something playful and intuitive. 📅 𝐉𝐚𝐧𝐮𝐚𝐫𝐲 𝟑𝟎𝐭𝐡, 𝟐𝟎𝟐𝟔 — 𝐌𝐚𝐣𝐞𝐬𝐭𝐢𝐜 𝐓𝐡𝐞𝐚𝐭𝐞𝐫, 𝐆𝐢𝐥𝐛𝐞𝐫𝐭 🎟️ halfstackconf.com/phoenix #HalfStackphoenix #TechEvents
1105
Reposted by Darcy Clarke
James Sumners @james.sumners.info · 22/12/2025
This just in: JavaScript uses memory.
media.tenor.com
a woman is standing in front of a sign that says news 4
ALT: a woman is standing in front of a sign that says news 4
051
Reposted by Darcy Clarke
Jordan Harband @jordan.har.band · 22/12/2025
I made something new: an eslint plugin to validate your npm ecosystem lockfiles! It supports npm, pnpm, yarn, bun, and vlt, and it's already helped find a supply chain security attack vector inside a fortune 500 tech company. www.npmjs.com/package/esli...
npmjs.com
35411
Darcy Clarke @darcyclarke.me · 16/12/2025
GitHub's product leadership sure knows how to piss off developers these days
1130
Reposted by Darcy Clarke
jviide.iki.fi @jviide.iki.fi · 12/12/2025
To recap, NPM allows 2FA TOTP token reuse within the token’s validity window. I reported this and was told it’s a “known low-risk issue” and that they “don’t consider this to present a significant security risk.” So, let’s look at how this seemingly small issue could be leveraged by a phisher. 1/
32313
Reposted by Darcy Clarke
Andrew Lisowski 💻 @hipstersmoothie.com · 04/12/2025
Looking for a maintainer. Good opportunity if you want to manage a library with a lot of users cc @reinhold.is I know storybook has its own version of this. Maybe they could be merged and managed in tandem?
364
Darcy Clarke @darcyclarke.me · 30/11/2025
Who's going to be in Las Vegas this week for AWS re:Invent? Let's chat packages & supply chain security if you're here!
media.tenor.com
a cartoon of a man standing in front of a stack of cardboard boxes and the words what the
ALT: a cartoon of a man standing in front of a stack of cardboard boxes and the words what the
150
Reposted by Darcy Clarke
Evert Pot @evertpot.com · 26/11/2025
The top licenses published on #npm . Number #2 is interesting because it's not really a well-known one, but it's the default choice when running `npm init`, so it likely represents all the people that just pressed enter without having an opinion. [1/2]
4164
Reposted by Darcy Clarke
Ruy Adorno @ruyadorno.com · 19/11/2025
🚀 Here is @vlt.sh take on running lifecycle scripts on installs, adding another powerful capability to our query language syntax: blog.vlt.sh/blog/vlt-build #javascript #nodejs #packages
blog.vlt.sh
Introducing Phased Package Installations
When you run vlt install, packages are downloaded and extracted to node_modules, but no lifecycle scripts execute.
294
Darcy Clarke @darcyclarke.me · 30/10/2025
Seriously? Y'all had no idea?! HMU if you want to know about the "weaknesses" or "blind spots" with npm/GitHub or your security vendors. arstechnica.com/security/202...
arstechnica.com
NPM flooded with malicious packages downloaded more than 86,000 times
Packages downloaded from NPM can fetch dependancies from untrusted sites.
010