Sign in

Darcy Clarke

@darcyclarke.me
1.8K followers 378 following 178 posts

@vlt.sh Founder & Chief End-User Officer Prev: GitHub, npm & Themify Co-Founder

PostsRepliesMedia
Reposted by Darcy Clarke
Ruy Adorno @ruyadorno.com · 29/09/2026
Thanks @vlt.io for contributing! 🔈 audio on to hear it from @nodeland.dev
1114
Reposted by Darcy Clarke
NodeConf.eu @nodeconf.eu · 30/09/2026
Thank you everyone for joining us at #NodeConfEU 2026! 💚 We hope you enjoyed it as much as we did, and we can’t wait to see you again next year! 📅👩‍💻 #TechCommunity #NodeCommunity
03112
Darcy Clarke @darcyclarke.me · 24/09/2026
A new home for your open source... In case you're fed up with that old one
030
Reposted by Darcy Clarke
Ruy Adorno @ruyadorno.com · 15/09/2026
I've been back to improving the vlt CLI for the last month, here's a peek at what we shipped since our major v1.0 release! 🚀 www.vlt.io/blog/vlt-cli...
vlt.io
A month of vlt CLI updates | vlt /vōlt/
Since 1.0, vlt has shipped install-speed wins, security hardening, and quality-of-life CLI fixes.
051
Reposted by Darcy Clarke
NodeConf.eu @nodeconf.eu · 02/09/2026
🚀 Thrilled to announce @vlt.io as a #Silver #Sponsor of #NodeConfEU 2026! Thank you! 💛 Your partnership is helping us create something truly special in the #Node.js #community! 🎟️ nodeconf.eu
1105
Darcy Clarke @darcyclarke.me · 19/08/2026
Want to grab coffee/hang? Can shoot you our office details depending on where you're going to be/how much time you'll have.
130
Reposted by Darcy Clarke
Kate Holterhoff, PhD @kateholterhoff.com · 12/08/2026
Dependency hell!! Oh no, w @darcyclarke.me at @nodejs.org Interactive at @renderatl.com #NodeJSInteractive
083
Darcy Clarke @darcyclarke.me · 04/08/2026
With a generous free tier - reserve your namespace, point your installs at it, and tell us what breaks. vlt.io/blog/1-0
vlt.io
vlt 1.0 & Hosted Package Registries | vlt /vōlt/
Stable client release and general availability of hosted registries & ecosystem mirrors.
060
Darcy Clarke @darcyclarke.me · 04/08/2026
We have flagged 275k+ malicious package versions. More than 25% of them are still downloadable from the public npm registry today. We block at index time, not weeks after the fact.
140
Darcy Clarke @darcyclarke.me · 04/08/2026
The registries and mirrors are GA and npm-API compatible - npm, pnpm, yarn, bun and deno all work, for both installing and publishing. Edge-served, clean installs up to 38% faster, unlimited private packages.
150
Darcy Clarke @darcyclarke.me · 04/08/2026
Querying is graph-native: 60+ pseudo selectors, ~30 of them security-focused (:malware, :cve, :vuln, :unmaintained, :license). Combine :host(local) with a version range and you can find every project on your machine still pinned to an old React.
130
Darcy Clarke @darcyclarke.me · 04/08/2026
Installs are phased. vlt install downloads. vlt build runs lifecycle scripts, selectively. Known malware is blocked by default, before it can execute. Nothing runs just because you installed it.
140
Darcy Clarke @darcyclarke.me · 04/08/2026
The client is a drop-in replacement for npm: init, install, build, run, exec, query, pack, publish, view, update, deprecate. Your whole lifecycle, no npm fallback required.
130
Darcy Clarke @darcyclarke.me · 04/08/2026
Excited to share vlt 1.0 along with our hosted registries & ecosystem mirrors now GA! A drop-in npm replacement, built so nothing runs on your machine just because you typed install. → faster delivery → malware blocking at the registry layer → graph-native querying
14416
Reposted by Darcy Clarke
Pooya Parsa @pi0.io · 28/07/2026
⛰️ mountx :: mount JavaScript as a real filesystem! Write ~6 lines of JS, get a real directory any process can read & write: editors, CLIs, AI agents. Rootless on Linux (FUSE) and macOS (NFSv3 with no kernel extensions). ~Pure JS, zero deps. mountx.vercel.app
6314
Reposted by Darcy Clarke
vlt /vōlt/ @vlt.io · 23/07/2026
A familiar story: the build crashes, so you rm -rf node_modules && rm package-lock.json, then reinstall to get your dev env back. But once the lockfile's gone, your ^ ranges take over. npm install can grab the newest in-range version of everything: poison included when there's a supply chain attack
vlt.io
Ship JavaScript? Hang onto your lockfile | vlt /vōlt/
Pinning dependencies in package.json won't save you in a supply-chain attack — a committed lockfile does. Here's why, and how to install so it holds.
153
Reposted by Darcy Clarke
Ruy Adorno @ruyadorno.com · 21/07/2026
Love to see all the pieces coming together! Just ran a `vlt publish --scope=':workspace'` cmd that mass-publishes all my workspaces in a given project to a private registry in my vlt.io account ❤️
vlt.io
Home | vlt /vōlt/
Package registries for teams that move fast
182
Reposted by Darcy Clarke
vlt /vōlt/ @vlt.io · 16/07/2026
There is CSS... but what if I told you there is such a thing as DSS? Dependency Selector Syntax is an expressive DSL written as a homage to CSS. Use it to inspect malicious dependencies in your repo docs.vlt.io/cli/selector...
1103
Reposted by Darcy Clarke
vlt /vōlt/ @vlt.io · 07/07/2026
If you regularly publish to the npm registry, you might be concerned about package size 😁 But have you heard of PACKUMENT size? News flash: how often you publish, how long your manifest is, how many *exports* you have, can also eventually prevent you from publishing!
vlt.io
Why Drizzle ORM couldn't publish new releases on NPM for a month | vlt /vōlt/
Drizzle ORM recently hit a 100 MB limit in the npm registry and couldn't ship new releases for weeks. What is this limit?
183
Reposted by Darcy Clarke
Nicholas C. Zakas @humanwhocodes.com · 29/06/2026
13 years ago today I made the first commit to the ESLint Git repo. It’s hard to believe that this project I cobbled together in my spare time over a couple of weeks is still going strong. I’ve been doing a lot of reflecting over these years and the journey it’s been. A thread.
A birthday cake for ESLint, with candles of 1 and 3 at the top for 13 and the ESLint logo with "Happy birthday" on the side.
3899
Darcy Clarke @darcyclarke.me · 01/06/2026
If this sounds like you, you should apply on our site: www.vlt.io/careers/deve...
vlt.io
Developer Relations Engineer | Careers | vlt /vōlt/
As a Developer Relations Engineer, you will serve as the bridge between vlt and the global JavaScript community. This role combines technical expertise, community engagement, and developer-focused mar...
010
Darcy Clarke @darcyclarke.me · 01/06/2026
⚡️ We're looking for a DevRel person at @vlt.sh - based in our Toronto 🇨🇦 HQ. You'll work closely w/ me & should love the idea of owning various aspects of product marketing. You'll be vlt's biggest fan & advocate; molding this unique role in a way that plays to your strengths & ours.
22417
Reposted by Darcy Clarke
Feross @feross.bsky.social · 20/05/2026
Today is a big day for @socket.dev. We raised a $60M Series C at a $1B valuation, led by Thrive Capital. 20,000+ orgs, 1.5M repos protected, 1,000+ supply chain attacks blocked per week. 3/5 FAANG companies are customers. We're just getting started.
118514
Reposted by Darcy Clarke
luke karrys @lukekarrys.com · 12/05/2026
today is a great day to rm -rf your work computer so you can take a little break
4282
Darcy Clarke @darcyclarke.me · 13/05/2026
I'm watching you
030
Reposted by Darcy Clarke
Socket @socket.dev · 11/05/2026
84 TanStack npm package artifacts were compromised in the ongoing Mini Shai-Hulud supply chain attack, adding suspected CI credential-stealing malware. Socket flagged every malicious version within six minutes of publication. Details: socket.dev/blog/tanstac...
socket.dev
Tanstack npm Packages Compromised in Ongoing Mini Shai-Hulud...
Socket detected 84 compromised TanStack npm packages modified with suspected CI credential-stealing malware.
56735
Reposted by Darcy Clarke
Wes @notwes.bsky.social · 05/05/2026
The hidden gem is that @nodejs.org majors and LTS cycles got WAY easier to understand: 2026 -> v26 2027 -> v27 2028 -> v28 ... Aall of them go LTS for 18 months meaning each major is supported for 2 years. The new graphic tells the best story here: nodejs.org/en/blog/anno...
nodejs release schedule chat. Bars for each major showing 6mo unstable, 6mo current, then 18mo LTS for each major. The best interpretation is that each yearly release is stable and supported for 2 full years.
210826
Darcy Clarke @darcyclarke.me · 02/05/2026
If `node` distributed itself on npm like bun & deno then you could imagine leveraging dist-tags for this exact purpose (although the `-1` thing is a bit messy/unconventional).
150
Darcy Clarke @darcyclarke.me · 02/05/2026
`"support".replace("spec")` 🙇‍♂️
000
Darcy Clarke @darcyclarke.me · 02/05/2026
Either way, this may be in the weeds/minutia given that the last change to nuxt's `engines.node` was actually a broadening of support (ref. github.com/nuxt/nuxt/co...) but "we may bump a dep that is incompatible with an eol node version in a patch" is concerning/wonder why a major couldn't be cut(?)
github.com
chore: update `installed-check` and `engines.node` · nuxt/nuxt@a05c4b1
200
Darcy Clarke @darcyclarke.me · 02/05/2026
Notably, this is all feedback under the guise that there should never be an implicit expectation on you to support any future work (your software is distributed "as-is"). Moreso, I'm concerned that the practice of narrowing a definition like `engines.node` is effectively a SemVer breaking change.
100
Darcy Clarke @darcyclarke.me · 02/05/2026
Because of that unique/peer relationship - which extends outside your dep - I believe narrowing the scope of that spec in a minor/patch inadvertently lands breaking changes at consumer's feet. I'd hope you'd consider cutting a major version when dropping versions in that spec.
100
Darcy Clarke @darcyclarke.me · 02/05/2026
Unfortunately, for too long the ecosystem has thought of `node` as this implicit peer dep that will always exist. Specifying `engines.node` effectively codifies this peer dep relationship (historically unmanaged) & tools (like package managers) are going to warn/error when there's conflicts.
110
Darcy Clarke @darcyclarke.me · 02/05/2026
`engines` definitions are meant to "specify the version of <engine> that your stuff works on". You really shouldn't distribute a definition if you don't support it. That said, if you're trying to gate the engine requirements of your transitive deps from consumers then you should probably own that.
210
Darcy Clarke @darcyclarke.me · 30/04/2026
media.tenor.com
a close up of a man 's face with the words more on the bottom right
ALT: a close up of a man 's face with the words more on the bottom right
110
Darcy Clarke @darcyclarke.me · 29/04/2026
Your calendar...
010
Darcy Clarke @darcyclarke.me · 29/04/2026
While others race away from Open Source, @vlt.sh is doubling down. 🖤⚡ Today we’re announcing our renewed commitment to @opensourcepledge.com and investing back into the ecosystem. www.vlt.io/blog/doublin...
vlt.io
Doubling Down on Open Source | vlt /vōlt/
We've doubled our open source pledge contribution to $14,000 ($3,500 per full-time engineer)
26511
Reposted by Darcy Clarke
Oliver Medhurst @honk.foo · 23/04/2026
porffor.dev is now served by a Porffor-compiled TS native binary!
A screenshot of porffor.dev:

new! This page is served by a Porffor-compiled TS binary!
[live stats] memory 4.0mb | binary 287kb | requests 210 | uptime 3h 21m
1317623
Darcy Clarke @darcyclarke.me · 05/04/2026
I tip my hat to everyone out there that is doing the thankless, unpaid work to ensure their environments & software stays safe/secure. At @vlt.sh we're giving back (ex. @opensourcepledge.com) & building a package manager that attacks the last mile problem with a zero trust approach.
082
Darcy Clarke @darcyclarke.me · 05/04/2026
The next attack may not require much social engineering at all, just a big enough check. Again, let that sink in.
140
Darcy Clarke @darcyclarke.me · 05/04/2026
Aligning incentives is important. At some point, the random guy in Nebraska, maintaining a critical piece of software, gets burnt out from the thankless social contract. This should be a very scary situation for everyone. People's ethics erode as resentment rises.
160
Darcy Clarke @darcyclarke.me · 05/04/2026
In modern warfare the software supply chain is one of the most critical targets/vectors for exploitation. Surprisingly, I haven't heard of a single OSS maintainer who has had any expense paid for them by their nation state.
160
Darcy Clarke @darcyclarke.me · 05/04/2026
I remember talking w/ @notwes.bsky.social & @jordan.har.band at some point about the OSS ecosystem being the target of state actors & a comment was made to the effect of: "it's not like the government gives us laptops or pays for our yubikeys...". Let that sink in for a moment...
170
Darcy Clarke @darcyclarke.me · 05/04/2026
We license software to be consumed "as-is" for a reason. The total cost of ownership should be on the consumer. Unfortunately, there's an implied social contract that maintainers keep software safe/secure at no cost to the consumer. This needs to change.
140
Darcy Clarke @darcyclarke.me · 05/04/2026
This isn't anything new. I've been targeted ever since my time at @npmjs.bsky.social @github.com where a compromise of mine - or anyone on my teams - would have been devastating to the ecosystem. What often goes unrecognized is just how professional open source maintainers are.
150
Darcy Clarke @darcyclarke.me · 05/04/2026
📖 This article by @sarahgooding.bsky.social at @socket.dev highlights a concerning trend (ref. socket.dev/blog/attacke...) 📕 Story time: this kind of supply chain targeting isn't unique. I myself & everyone on our team @vlt.sh have been the targets of consistent, concerted efforts.
socket.dev
Attackers Are Hunting High-Impact Node.js Maintainers in a C...
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
2179
Reposted by Darcy Clarke
luke karrys @lukekarrys.com · 02/04/2026
this is one of my favorite parts of the @vlt.sh CLI. it uses @socket.dev security data to prevent known malware from running lifecycle scripts like postinstall! and it’s powered by queries under the hood so you could make it as granular as you wanted (but we ship with safe defaults)
0167
Reposted by Darcy Clarke
Feross @feross.bsky.social · 02/04/2026
We’re seeing cases where teams can’t explain how they were compromised by the Axios incident because it doesn’t show up in their project's lockfile. The blast radius here is much larger than it looks. Deep dive into the messy reality of modern dependency resolution → socket.dev/blog/hidden-...
socket.dev
The Hidden Blast Radius of the Axios Compromise - Socket
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
01711
Darcy Clarke @darcyclarke.me · 02/04/2026
"consistency" & "speed" or sort of nebulous without more context. I'm going to assume the former is in regards to availability/reliability(?) & the latter is about delivery(?) - although I could be wrong/feel free to correct me.
000
Darcy Clarke @darcyclarke.me · 02/04/2026
benchmarks.vlt.sh#/registries/...
benchmarks.vlt.sh
vlt benchmarks
010