Sign in

Darcy Clarke

@darcyclarke.me
1.8K followers 378 following 179 posts

@vlt.sh Founder & Chief End-User Officer Prev: GitHub, npm & Themify Co-Founder

PostsRepliesMedia
Darcy Clarke @darcyclarke.me · 04/08/2026
Excited to share vlt 1.0 along with our hosted registries & ecosystem mirrors now GA! A drop-in npm replacement, built so nothing runs on your machine just because you typed install. → faster delivery → malware blocking at the registry layer → graph-native querying
14416
Darcy Clarke @darcyclarke.me · 02/04/2026
I heard you like fast package managers? What about fast registries? It's been a roller coaster of a month but our team has made some serious headway w/ even more improvements in the works. Gotta keep the registry fast so y'all can nab the next Claude Code leak.
2131
Darcy Clarke @darcyclarke.me · 27/02/2026
For VSR, we're going to continue maintaining that as a lightweight self-hosted option (great for testing/local dev) but we've been primarily focused on our hosted registry/service. Perf & security again are top of mind. Initial benchmarks show significant wins against npm/AWS. More on this soon.
130
Darcy Clarke @darcyclarke.me · 04/02/2026
Yea... this was/is a thing. It was "removed" on the website at some point before I joined. That said, you can still find references in the website to it (since it was only visually removed) & the endpoints / CLI commands still exist & work.
160
Darcy Clarke @darcyclarke.me · 30/01/2026
The @vlt.sh benchmark suite has been updated to include the yarn v6 canaries (still a WIP & improving all the time): benchmarks.vlt.sh
0114
Darcy Clarke @darcyclarke.me · 09/01/2026
Makes sense & +1 for making the lib. That said, I still hope you'll champion the idea that PURLs are superfluous. URLs w/ vanity-protocols were/are sufficient. I remain baffled how this became _"the standard"_ in SBOMs when it doesn't support all pkg spec types in the world's largest pkg ecosystem 🤷🏼‍♂️
120
Darcy Clarke @darcyclarke.me · 13/10/2025
👋🏻 If you're at @jsconf.bsky.social NA this week, come say hi to our team @vlt.sh ⚡📦 @ruyadorno.com, @lukekarrys.com & our Design Engineer (Jason Korol) will be there for both the conf & Node.js Collab Summit 🚀🐢
0134
Darcy Clarke @darcyclarke.me · 10/10/2025
Why are @github.com tokens allowed to have no expiry but @npmjs.bsky.social are about to make every IT team's lives a living hell? This is just more security theatre. Think harder @microsoft.com.
1154
Darcy Clarke @darcyclarke.me · 21/09/2025
I'm very happy we've got one in the @vlt.sh office. Gets a fair bit of use. Most of our designs/drawings all end up looking like toasters for some reason though...
120
Darcy Clarke @darcyclarke.me · 17/09/2025
Yes (via. `npm config set before=... --location=<global|user|project>`) but not the dynamic/relative date (see screenshot). That said, you can always add the `npm config set` command to your .bashrc/.zshrc file so the config updates every time you start a new terminal session (see second screenshot)
230
Darcy Clarke @darcyclarke.me · 04/09/2025
⚡ Point. Click. Discover. 🚀 We're excited to unveil a new Query Builder to @vlt.sh's UI. It's now dead simple to visually navigate complex dependency graph filters without typing a thing. No need to memorize our selector syntax (if you don't want to).
152
Darcy Clarke @darcyclarke.me · 04/09/2025
🔥 Just your yearly reminder that the JS ecosystem could be much worse off... stuck in the *first level* of "Dependency Hell" like many other ecosystems with minimal options/diversity... lucky for us, we get to face much hotter problems 😉
0162
Darcy Clarke @darcyclarke.me · 28/08/2025
Yea - you can test it yourself (see screenshot attached). I believe there's roughly a ~10 token limit per OAuth Authorized App where they'd then start to popping off after that (so just run `gh auth refresh` 10 times & you're good 😉). Again, no UI/UX that lists these tokens from GH (no API either).
010
Darcy Clarke @darcyclarke.me · 23/07/2025
Notably, I think paying a recruiter for non-leadership roles is a waste but LinkedIn is on another level. I've always hated the advertising industry & never thought posting a job would be treated as advertising in disguise. Seems like the "state-of-the-art" in "professional networks"/HR is a swamp.
110
Darcy Clarke @darcyclarke.me · 23/07/2025
I know the adage, "you get what you pay for" but in this case, I've given LinkedIn ALL my information about my career & "professional network" for well over a decade - I'd expect to get something back that wasn't "pay us thousands of dollars more to access that network". I don't need "promotion".
110
Darcy Clarke @darcyclarke.me · 23/07/2025
True story, I posted a job last night & *poof* the budget was gone in ~15min. Results: with a max budget of $100USD (the lowest possible) I got 2 applicants & 10 "viewers"(whatever that means?). That's an INSANE CPI/CPC w/ zero insight on price determination, quality of impressions or demographics.
110
Darcy Clarke @darcyclarke.me · 23/07/2025
Worse, if you choose the "average daily budget" they can & do go over that budget all the time (to the tune of >50% the budget). Again, zero transparency as to what you got for that money & the whole experience is clunky AF with missing table-stakes features (ex. preview) while they charge premiums.
110
Darcy Clarke @darcyclarke.me · 23/07/2025
But get this, they force you to set either a daily "average budget" or a max total for the campaign. Thing is, they don't tell you how they meter/charge that "budget" which is absolutely INSANE. No visibility into what you're getting for your money.
110
Darcy Clarke @darcyclarke.me · 23/07/2025
Posting a job to LinkedIn is a dumpster fire 💩🔥 I don't know how they're still running their opaque pricing racket. Apparently, if you have a "hot" job title (ie. ANY at all right now) then you MUST pay for a "promoted" posting 🤨 Think Uber's surge pricing but drivers are paying & MUST pay to drive.
170
Darcy Clarke @darcyclarke.me · 03/06/2025
Watching @bizza.pizza speak at @github.com HQ like it's early 2020... only took 5+ years & me quitting to finally see the inside of this office 🤦🏻‍♂️ Continue Dev landed a good one
040
Darcy Clarke @darcyclarke.me · 01/04/2025
The vibes these days... #PromptAndPray
020
Darcy Clarke @darcyclarke.me · 11/03/2025
Big feels today
2140
Darcy Clarke @darcyclarke.me · 11/03/2025
We're back in business! Big thanks to @voodootikigod.bsky.social & @openjs.bsky.social for bringing JSConf back to NA ❤️ The whole @vlt.sh team will be there & hopefully many old & new faces. Get an early bird ticket before they are gone! events.linuxfoundation.org/jsconf-north...
051
Darcy Clarke @darcyclarke.me · 28/02/2025
Watching @mhdawson.bsky.social share how the @nodejs.org project works/collaborates & the Next-10 Initiative/WG #nodejs #future
051
Darcy Clarke @darcyclarke.me · 27/02/2025
🔗 Modernizing JS Supply Chain Security: tinyurl.com/modern-2025
010
Darcy Clarke @darcyclarke.me · 27/02/2025
🎤 I had two amazing talks here @ @confooca.bsky.social over the last two days. Big thanks to Yann & the team that run this amazing 🇨🇦 conference here in Montreal. If you want to check out my slide decks they are: 🔄 Securing the JS Ecosystem with Reproducibility: tinyurl.com/reproduce-2025 And...
183
Darcy Clarke @darcyclarke.me · 26/02/2025
🚀 We just launched `$ npx reproduce <pkg>`
3279
Darcy Clarke @darcyclarke.me · 13/02/2025
🔥 Our new Design Engineer Jason Korol wrote up an awesome article on some recent ships related to the @vlt.sh GUI, including: 💾 Saved Queries 🏷️ Labelling 🔁 Interactive Dep Management 🖼️ Improved Metadata #gui #interactive #dashboard #query #interactive #dependencies
163
Darcy Clarke @darcyclarke.me · 31/01/2025
A great talk by @lukekarrys.com on performing lockfile surgery which is getting much easier with @vlt.sh
151