Sign in

vlt.io

@vlt.io
0 followers 0 following 0 posts
PostsRepliesMedia
vlt /vōlt/ @vlt.io · 24/09/2026
Your private JavaScript registry can now publish to the public. Public packages are now GA. Publish and install the packages you want to share with the ecosystem. Read the full announcement here ↓ www.vlt.io/blog/public-...
vlt.io
Public Packages | vlt /vōlt/
Explore the JavaScript ecosystem without an account, and publish packages from your own registry for anyone to install.
060
vlt /vōlt/ @vlt.io · 28/08/2026
10 versions of @7nohe/openapi-react-query-codegen was published to npm in an ongoing attack. They contained provenance. buff.ly/LHuOYgw
buff.ly
Security: package is currently publishing malicious code · Issue #218 · 7nohe/openapi-react-query-codegen
Between 2026-08-28 20:00 and 20:21 UTC, 8 versions of @7nohe/openapi-react-query-codegen were published to npm containing a remote-code-execution payload. This includes 3.0.4, the current latest ta...
030
Reposted by vlt /vōlt/
Evert Pot @evertpot.com · 27/08/2026
Are you talking about paths in a tar escaping the base path? A good package manager should prevent this. I know both npm and vlt do.
111
vlt /vōlt/ @vlt.io · 26/08/2026
vlt 1.0.5 just dropped 🚢 ⚓️ → Dependency-deduping cuts installs with duplicated deps 40% smaller → Warm cache skips the network entirely → Safe by default: tar decompression-bomb caps & path-traversal hardening before anything writes to disk github.com/vltpkg/vltpk...
140
Reposted by vlt /vōlt/
Orta Therox @orta.io · 24/08/2026
I've 1.0.0'd my Danger JS re-write today: Risk If you use Danger in GitHub + GitHub Actions then it should be a simple dependency switch and you'd end up with substantially less moving parts I've been using it daily in Puzzmo for 6 months with no issues npmx.dev/package/risk
A screenshot of the risk nom package page on npmx.dev
3222
vlt /vōlt/ @vlt.io · 24/08/2026
When you need to fix a typo, not an upgrade
010
vlt /vōlt/ @vlt.io · 24/08/2026
Your package.json lists 20 dependencies. Your node_modules has 800. The 780 you didn't add are where supply-chain risk actually lives. How many transitive deps are in your last install?
000
vlt /vōlt/ @vlt.io · 23/08/2026
Every JS dev has run `npm audit fix --force` and watched their build break. Automated security fixes don't understand your dep graph. The fix that 'solves' the CVE creates three new problems. What did `--force` break for you?
130
vlt /vōlt/ @vlt.io · 21/08/2026
Linux users: watch out for these trojan npm packages masquerading as working calendar and streak utils thehackernews.com/2026/08/14-t...
thehackernews.com
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Trojanized npm packages launch RedC2 4.0 on Linux at import time, giving operators shell access, credential theft, and payload execution.
010
vlt /vōlt/ @vlt.io · 21/08/2026
Ever tried matching an npm package to a CVE, only to realize every security tool names dependencies differently? 🙃 Enter PURL (Package URL). It’s an open standard that gives software packages a uniform string identifier—regardless of registry, ecosystem, or language.
200
Reposted by vlt /vōlt/
James Snell @jasnell.me · 21/08/2026
Friends don't let friends let AI name things.
121
vlt /vōlt/ @vlt.io · 20/08/2026
RSS is... RDF Site Summary? Rich Site Summary? Really Simple Syndication? well, we're on it. www.vlt.io/rss.xml #iykyk
vlt.io
https://www.vlt.io/rss.xml
100
Reposted by vlt /vōlt/
Evert Pot @evertpot.com · 20/08/2026
My cowoker dropped 'load bearing' in a conversation 😭
351
vlt /vōlt/ @vlt.io · 19/08/2026
vlt v1.03 dropped with faster installs at every layer. 158x faster packument generation. A warm cache that skips the network entirely on your second install. Tarball extraction, parallelized. github.com/vltpkg/vltpk...
022
vlt /vōlt/ @vlt.io · 19/08/2026
A developer's dilemma: Your security audit flags a CVE. You have to upgrade to the next version to fix it. If you upgrade, you'll have to refactor your whole app to adapt to breaking changes. If you don't upgrade, the CVE alert persists. Maintaining prod is full of hairy decisions.
000
vlt /vōlt/ @vlt.io · 17/08/2026
The 2026 Black Duck OSSRA report dropped some wild data for JS/TS teams: • Open source powers 98% of commercial apps • 64%+ of JS dependencies are transitive (⁠node_modules⁠ depth) • 93% of codebases rely on unmaintained "zombie" packages • Unsafe ⁠preinstall⁠ scripts remain a top vector 🧵
100
Reposted by vlt /vōlt/
Artem Zakharchenko @kettanaito.com · 16/08/2026
We made a huge mistake with the Fetch API. We brought it to the server.
1193
vlt /vōlt/ @vlt.io · 16/08/2026
This weekend I read over the vlt team's dependency graph code and it blew my mind. Package management and install time safety is a very difficult problem space because all tools resolve dependencies differently.
000
Reposted by vlt /vōlt/
tierney cyren @bnb.im · 14/08/2026
“coding is largely solved” okay make a new cross platform web browser that supports every web platform spec to 100% compliance
70107580
Reposted by vlt /vōlt/
Wes @notwes.bsky.social · 14/08/2026
I am a big fan of building *on* existing systems over *replacing* them. I am still processing some of the stuff on semver.xyz, but I am a HUGE fan of the @vlt.io team's *approach* to engineering the future of package management.
semver.xyz
semver.xyz — Semantic Versions
A modern versioning spec: restores build precedence and formally defines sets, ranges and comparators. Test the range grammar in your browser.
163
vlt /vōlt/ @vlt.io · 14/08/2026
How do you prove whoever published your dependencies is who they say they are? Did the maintainer publish this, or did someone compromise the registry? With agents installing packages you can't read, that gap matters. How do you verify package integrity? #supplychainSecurity
000
vlt /vōlt/ @vlt.io · 13/08/2026
Your AI agent just installed 47 packages you didn't read. One might be malicious, but the registry will served it anyway. When agents control dependencies, the trust chain breaks. Where does security live? #supplychainSecurity #JavaScript
020
Reposted by vlt /vōlt/
Kate Holterhoff, PhD @kateholterhoff.com · 12/08/2026
Dependency hell!! Oh no, w @darcyclarke.me at @nodejs.org Interactive at @renderatl.com #NodeJSInteractive
083
Reposted by vlt /vōlt/
Kevin Deng @sxzz.dev · 13/08/2026
Changesets is using tsdown
091
Reposted by vlt /vōlt/
Jake Bailey @jakebailey.dev · 12/08/2026
TypeScript, now downloaded... 1G a month?
TypeSCript

CI | passing
npm package | 7.0.2
downloads | 1G/month
9526
vlt /vōlt/ @vlt.io · 12/08/2026
What if Semantic Versioning solved "is this compatible?" but not "is this safe?" SBOMs, provenance, lifecycle safety—all fragmented across ecosystems. Can we build *on* semver instead replacing it? Check out Darcy Clarke's talk, "Beyond Semver" at Node.js Interactive, Render ATL, Wed 2pm ET.
030
Reposted by vlt /vōlt/
Catalin Cimpanu @campuscodi.risky.biz · 11/08/2026
ShinyHunters claims Metabase hacking spree
066
vlt /vōlt/ @vlt.io · 11/08/2026
Came here to say it's much easier to pull bluesky than x metrics
040
Reposted by vlt /vōlt/
NullVoxPopuli @nullvoxpopuli.com · 09/08/2026
Who's got frontend frameworks? Trying to collect some stats on update efficiency (rather than rendering new dom en-masse (which js-framework-benchmark heavily favors <3))
4173
vlt /vōlt/ @vlt.io · 08/08/2026
Everyday is a day for JavaScript
010
Reposted by vlt /vōlt/
html energy @htmlenergy.bsky.social · 07/08/2026
HTML Day 2026 is tomorrow ❇️ 2026.html.energy Start your text editors !
2026.html.energy
HTML Day 2026
HTML Day is on August 8th, 2026!
12818
Reposted by vlt /vōlt/
Frontend Dogma @frontenddogma.com · 08/08/2026
vlt 1.0 and Hosted Package Registries, by @darcyclarke.me (@vlt.io): www.vlt.io/blog/1-0?ref=frontenddog… #releasenotes
vlt.io
vlt 1.0 & Hosted Package Registries | vlt /vōlt/
Stable client release and general availability of hosted JavaScript registries & ecosystem mirrors.
122
vlt /vōlt/ @vlt.io · 08/08/2026
You've got an SBOM. Your team trusts it. But what's actually shipping in your node_modules? Most teams can't answer that. An SBOM is a snapshot. Your actual graph—what resolved, what got yanked, what changed at publish time—is invisible. That invisibility is the gap.
200
vlt /vōlt/ @vlt.io · 07/08/2026
Guesss who's featured in Node Weekly? nodeweekly.com/issues/636
010
vlt /vōlt/ @vlt.io · 07/08/2026
What if I told you the metadata file for a package — the part that decides what installs — is often 97% bloat? Drizzle's is 61 MB on npm. 1.7 MB on vlt's registry. Same package. Different infrastructure. www.vlt.io/blog/packume...
191
vlt /vōlt/ @vlt.io · 06/08/2026
You can't improve what you don't measure. And measure, we do. 😉 A clean install runs up to 38% faster than npm, no change to your tooling required.
131
Reposted by vlt /vōlt/
Ruy Adorno @ruyadorno.com · 05/08/2026
We just released the first version of the vlt.io platform! 🚀 This is just the beginning, as we start to tackle the challenge of securing the JavaScript packages ecosystem and making it faster. Make sure to sign up and follow us at @vlt.io 😊 #javascript #nodejs #package
vlt.io
Home | vlt /vōlt/
Package registries for teams that move fast
0141
vlt /vōlt/ @vlt.io · 05/08/2026
You can't improve what you don't measure. And measure, we do. 😉 A clean install runs up to 38% faster than npm, no change to your tooling required.
110
vlt /vōlt/ @vlt.io · 05/08/2026
It's been a day
slack feed of boxes showing packages getting published
0100
Reposted by vlt /vōlt/
luke karrys @lukekarrys.com · 05/08/2026
this ride @vlt.io \ / \ / 🤝 powered by @nodejs.org and apple sauce
a blurry selfie of me on an indoor bike. there’s a windowsill with 2 empty apple sauce pouches. and i’m wearing a nodejs shirt
091
Reposted by vlt /vōlt/
luke karrys @lukekarrys.com · 04/08/2026
🎉 it's launch day at @vlt.io! 🎉 - use our new drop-in npm replacement to protect yourself from malware and increase performance - create private registries to share packages with your team - oh and the vlt CLI is now v1! read more in our announcement post:
vlt.io
vlt 1.0 & Hosted Package Registries | vlt /vōlt/
Stable client release and general availability of hosted registries & ecosystem mirrors.
0232
Reposted by vlt /vōlt/
Darcy Clarke @darcyclarke.me · 04/08/2026
Excited to share vlt 1.0 along with our hosted registries & ecosystem mirrors now GA! A drop-in npm replacement, built so nothing runs on your machine just because you typed install. → faster delivery → malware blocking at the registry layer → graph-native querying
14416
vlt /vōlt/ @vlt.io · 04/08/2026
⚠️ JS supply chain attack ongoing: The GitHub account of the maintainer behind keyv was compromised recently - Shai Halud style. www.aikido.dev/blog/keyv-an...
aikido.dev
Keyv and friends compromised in npm supply chain attack
Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer's GitHub account
182
vlt /vōlt/ @vlt.io · 04/08/2026
There is a tiny human developer behind this screen trying to talk shop with other developers 🍃
000
Reposted by vlt /vōlt/
NodeConf.eu @nodeconf.eu · 04/08/2026
🥁 𝐒𝐩𝐞𝐚𝐤𝐞𝐫 𝐀𝐧𝐧𝐨𝐮𝐧𝐜𝐞𝐦𝐞𝐧𝐭🎙️ Thrilled to have @akiro.se on the #NodeConf EU 2026 stage! She'll tell us the story of "𝐂𝐲𝐛𝐞𝐫 𝐑𝐞𝐬𝐢𝐥𝐢𝐞𝐧𝐜𝐞 𝐟𝐨𝐫 𝐀𝐩𝐩𝐥𝐢𝐜𝐚𝐭𝐢𝐨𝐧 𝐃𝐞𝐯𝐞𝐥𝐨𝐩𝐞𝐫𝐬." 🎟️Don't miss it out; secure your #tickets! nodeconf.eu #Node.js #TechConference #techcommunity #JS
084
vlt /vōlt/ @vlt.io · 03/08/2026
For the longest time, package namespaces on npm were first-come, first-serve. Typosquats, slopsquats & worms are all downstream of that design. www.vlt.io/blog/slopsqu...
vlt.io
Typosquatting was a spellcheck issue. Slopsquatting is a trust issue. | vlt /vōlt/
Consuming JavaScript packages safely just got more complicated.
042
Reposted by vlt /vōlt/
Lars @webpro.nl · 03/08/2026
🐚→🌳 unbash v4.0.6 is out unbash will change the game: more modern and complete syntax support + great performance Cuts whole dependency trees and expensive wasm loaders 🪓 Today, fixed a bunch of edge cases and improved docs + comparisons. Stay tuned.. → github.com/webpro-nl/un...
082
vlt /vōlt/ @vlt.io · 02/08/2026
Dependency Cultures - Richard Feldman www.youtube.com/watch?v=E82l...
youtube.com
Dependency Cultures - Richard Feldman | SSW 2026
YouTube video by Software Should Work
010
vlt /vōlt/ @vlt.io · 01/08/2026
If you're the type of dev that prides themselves on using plain ol' fetch, an even lower level HTTP wrapper to consider when writing a lib or using node on a server is undici www.npmjs.com/package/undici
npmjs.com
000
Reposted by vlt /vōlt/
James @43081j.com · 31/07/2026
new @e18e.dev blog post about when to publish source maps to npm 📦 source maps are often the reason behind bloated install sizes, but sometimes necessary. here we try to explain some of the balance, do/don't
e18e.dev
Source maps or not?
Source maps are great for debugging, but should we be shipping them in production?
45515