Sign in

vlt /vōlt/

@vlt.io
846 followers 363 following 125 posts

JavaScript registries and tooling for teams that move fast.

PostsRepliesMedia
vlt /vōlt/ @vlt.io · 26/08/2026
vlt 1.0.5 just dropped 🚢 ⚓️ → Dependency-deduping cuts installs with duplicated deps 40% smaller → Warm cache skips the network entirely → Safe by default: tar decompression-bomb caps & path-traversal hardening before anything writes to disk github.com/vltpkg/vltpk...
140
vlt /vōlt/ @vlt.io · 25/08/2026
👋🏼
120
vlt /vōlt/ @vlt.io · 24/08/2026
When you need to fix a typo, not an upgrade
010
vlt /vōlt/ @vlt.io · 21/08/2026
Ever tried matching an npm package to a CVE, only to realize every security tool names dependencies differently? 🙃 Enter PURL (Package URL). It’s an open standard that gives software packages a uniform string identifier—regardless of registry, ecosystem, or language.
200
vlt /vōlt/ @vlt.io · 19/08/2026
vlt v1.03 dropped with faster installs at every layer. 158x faster packument generation. A warm cache that skips the network entirely on your second install. Tarball extraction, parallelized. github.com/vltpkg/vltpk...
022
vlt /vōlt/ @vlt.io · 12/08/2026
What if Semantic Versioning solved "is this compatible?" but not "is this safe?" SBOMs, provenance, lifecycle safety—all fragmented across ecosystems. Can we build *on* semver instead replacing it? Check out Darcy Clarke's talk, "Beyond Semver" at Node.js Interactive, Render ATL, Wed 2pm ET.
030
vlt /vōlt/ @vlt.io · 07/08/2026
Guesss who's featured in Node Weekly? nodeweekly.com/issues/636
010
vlt /vōlt/ @vlt.io · 06/08/2026
benchmarks.vlt.io
bar graphs showing average times for install of next, vue, svelte, astro
000
vlt /vōlt/ @vlt.io · 05/08/2026
You can't improve what you don't measure. And measure, we do. 😉 A clean install runs up to 38% faster than npm, no change to your tooling required.
110
vlt /vōlt/ @vlt.io · 05/08/2026
It's been a day
slack feed of boxes showing packages getting published
0100
vlt /vōlt/ @vlt.io · 16/07/2026
There is CSS... but what if I told you there is such a thing as DSS? Dependency Selector Syntax is an expressive DSL written as a homage to CSS. Use it to inspect malicious dependencies in your repo docs.vlt.io/cli/selector...
1103
vlt /vōlt/ @vlt.io · 22/04/2025
In partnership with @socket.dev we're bringing Socket Package Alerts to your local dependencies when using the vlt client. Introducing Package Insight Selectors, a powerful addition to our Dependency Selector Syntax that helps you understand and secure your node_modules folder. #js #nodejs #vlt
164