Sign in

vlt /vōlt/

@vlt.io
844 followers 363 following 125 posts

JavaScript registries and tooling for teams that move fast.

PostsRepliesMedia
Reposted by vlt /vōlt/
Ruy Adorno @ruyadorno.com · 29/09/2026
Thanks @vlt.io for contributing! 🔈 audio on to hear it from @nodeland.dev
0114
vlt /vōlt/ @vlt.io · 24/09/2026
Your private JavaScript registry can now publish to the public. Public packages are now GA. Publish and install the packages you want to share with the ecosystem. Read the full announcement here ↓ www.vlt.io/blog/public-...
vlt.io
Public Packages | vlt /vōlt/
Explore the JavaScript ecosystem without an account, and publish packages from your own registry for anyone to install.
060
vlt /vōlt/ @vlt.io · 28/08/2026
10 versions of @7nohe/openapi-react-query-codegen was published to npm in an ongoing attack. They contained provenance. buff.ly/LHuOYgw
buff.ly
Security: package is currently publishing malicious code · Issue #218 · 7nohe/openapi-react-query-codegen
Between 2026-08-28 20:00 and 20:21 UTC, 8 versions of @7nohe/openapi-react-query-codegen were published to npm containing a remote-code-execution payload. This includes 3.0.4, the current latest ta...
030
vlt /vōlt/ @vlt.io · 28/08/2026
Trick question!
020
Reposted by vlt /vōlt/
Evert Pot @evertpot.com · 27/08/2026
Are you talking about paths in a tar escaping the base path? A good package manager should prevent this. I know both npm and vlt do.
111
vlt /vōlt/ @vlt.io · 27/08/2026
🤔 Imma bat this to @evertpot.com @ruyadorno.com who might know more
020
vlt /vōlt/ @vlt.io · 26/08/2026
vlt 1.0.5 just dropped 🚢 ⚓️ → Dependency-deduping cuts installs with duplicated deps 40% smaller → Warm cache skips the network entirely → Safe by default: tar decompression-bomb caps & path-traversal hardening before anything writes to disk github.com/vltpkg/vltpk...
140
Reposted by vlt /vōlt/
Orta Therox @orta.io · 24/08/2026
I've 1.0.0'd my Danger JS re-write today: Risk If you use Danger in GitHub + GitHub Actions then it should be a simple dependency switch and you'd end up with substantially less moving parts I've been using it daily in Puzzmo for 6 months with no issues npmx.dev/package/risk
A screenshot of the risk nom package page on npmx.dev
3222
vlt /vōlt/ @vlt.io · 25/08/2026
👋🏼
120
vlt /vōlt/ @vlt.io · 25/08/2026
Fascinating...!
000
vlt /vōlt/ @vlt.io · 25/08/2026
npm run dev // exit 1 npm ls view // finds 2 different versions of webpack, 1 major apart // spends 3 hours vacillating between stack overflow and console trying to make It build again Those were the days...
010
vlt /vōlt/ @vlt.io · 24/08/2026
When you need to fix a typo, not an upgrade
010
vlt /vōlt/ @vlt.io · 24/08/2026
Hopefully not all on the same level 😱
110
vlt /vōlt/ @vlt.io · 24/08/2026
Your package.json lists 20 dependencies. Your node_modules has 800. The 780 you didn't add are where supply-chain risk actually lives. How many transitive deps are in your last install?
000
vlt /vōlt/ @vlt.io · 23/08/2026
Every JS dev has run `npm audit fix --force` and watched their build break. Automated security fixes don't understand your dep graph. The fix that 'solves' the CVE creates three new problems. What did `--force` break for you?
130
vlt /vōlt/ @vlt.io · 21/08/2026
Linux users: watch out for these trojan npm packages masquerading as working calendar and streak utils thehackernews.com/2026/08/14-t...
thehackernews.com
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Trojanized npm packages launch RedC2 4.0 on Linux at import time, giving operators shell access, credential theft, and payload execution.
010
vlt /vōlt/ @vlt.io · 21/08/2026
Whether you're building SBOMs, running vulnerability scans, or just trying to keep your supply chain straight, it's the common URL syntax we've needed for cross-ecosystem refs. packageurl.org
packageurl.org
Home | www.packageurl.org
Landing page for www.packageurl.org.
010
vlt /vōlt/ @vlt.io · 21/08/2026
Ever tried matching an npm package to a CVE, only to realize every security tool names dependencies differently? 🙃 Enter PURL (Package URL). It’s an open standard that gives software packages a uniform string identifier—regardless of registry, ecosystem, or language.
200
vlt /vōlt/ @vlt.io · 21/08/2026
How does this guy find the time to do all the things he does?!
020
Reposted by vlt /vōlt/
James Snell @jasnell.me · 21/08/2026
Friends don't let friends let AI name things.
121
vlt /vōlt/ @vlt.io · 20/08/2026
Hello superstar
011
vlt /vōlt/ @vlt.io · 20/08/2026
RSS is... RDF Site Summary? Rich Site Summary? Really Simple Syndication? well, we're on it. www.vlt.io/rss.xml #iykyk
vlt.io
https://www.vlt.io/rss.xml
100
vlt /vōlt/ @vlt.io · 20/08/2026
I think his person (who shall not be named) was trained on the LLM in this case
110
Reposted by vlt /vōlt/
Evert Pot @evertpot.com · 20/08/2026
My cowoker dropped 'load bearing' in a conversation 😭
351
vlt /vōlt/ @vlt.io · 19/08/2026
vlt v1.03 dropped with faster installs at every layer. 158x faster packument generation. A warm cache that skips the network entirely on your second install. Tarball extraction, parallelized. github.com/vltpkg/vltpk...
022
vlt /vōlt/ @vlt.io · 19/08/2026
A developer's dilemma: Your security audit flags a CVE. You have to upgrade to the next version to fix it. If you upgrade, you'll have to refactor your whole app to adapt to breaking changes. If you don't upgrade, the CVE alert persists. Maintaining prod is full of hairy decisions.
000
vlt /vōlt/ @vlt.io · 19/08/2026
What would happen if we hid the stars? 🤔
100
vlt /vōlt/ @vlt.io · 18/08/2026
Sending hug ops
030
vlt /vōlt/ @vlt.io · 17/08/2026
Maintainers shouldn't carry the security & hosting burden alone. We offer free package hosting for qualified open-source maintainers—high-reliability infrastructure & registry-level security so you can focus on building. Apply here: www.vlt.io/open-source/...
000
vlt /vōlt/ @vlt.io · 17/08/2026
Deep dependency trees & unmaintained packages create constant operational tax for dev teams. Upgrading nested packages shouldn't mean risking broken lockfiles or malicious lifecycle hooks. When 98% of app stacks run on open source, maintainer infrastructure becomes critical.
110
vlt /vōlt/ @vlt.io · 17/08/2026
The 2026 Black Duck OSSRA report dropped some wild data for JS/TS teams: • Open source powers 98% of commercial apps • 64%+ of JS dependencies are transitive (⁠node_modules⁠ depth) • 93% of codebases rely on unmaintained "zombie" packages • Unsafe ⁠preinstall⁠ scripts remain a top vector 🧵
100
Reposted by vlt /vōlt/
Artem Zakharchenko @kettanaito.com · 16/08/2026
We made a huge mistake with the Fetch API. We brought it to the server.
1193
vlt /vōlt/ @vlt.io · 16/08/2026
This weekend I read over the vlt team's dependency graph code and it blew my mind. Package management and install time safety is a very difficult problem space because all tools resolve dependencies differently.
000
Reposted by vlt /vōlt/
tierney cyren @bnb.im · 14/08/2026
“coding is largely solved” okay make a new cross platform web browser that supports every web platform spec to 100% compliance
70107580
vlt /vōlt/ @vlt.io · 14/08/2026
That's a feat to behold - and to stick with - at work!
010
Reposted by vlt /vōlt/
Wes @notwes.bsky.social · 14/08/2026
I am a big fan of building *on* existing systems over *replacing* them. I am still processing some of the stuff on semver.xyz, but I am a HUGE fan of the @vlt.io team's *approach* to engineering the future of package management.
semver.xyz
semver.xyz — Semantic Versions
A modern versioning spec: restores build precedence and formally defines sets, ranges and comparators. Test the range grammar in your browser.
163
vlt /vōlt/ @vlt.io · 14/08/2026
What you're saying reminds me of the xkcd "15th standard" comic xkcd.com/927/
xkcd.com
Standards
110
vlt /vōlt/ @vlt.io · 14/08/2026
How do you prove whoever published your dependencies is who they say they are? Did the maintainer publish this, or did someone compromise the registry? With agents installing packages you can't read, that gap matters. How do you verify package integrity? #supplychainSecurity
000
vlt /vōlt/ @vlt.io · 13/08/2026
Your AI agent just installed 47 packages you didn't read. One might be malicious, but the registry will served it anyway. When agents control dependencies, the trust chain breaks. Where does security live? #supplychainSecurity #JavaScript
020
Reposted by vlt /vōlt/
Kate Holterhoff, PhD @kateholterhoff.com · 12/08/2026
Dependency hell!! Oh no, w @darcyclarke.me at @nodejs.org Interactive at @renderatl.com #NodeJSInteractive
083
Reposted by vlt /vōlt/
Kevin Deng @sxzz.dev · 13/08/2026
Changesets is using tsdown
091
vlt /vōlt/ @vlt.io · 13/08/2026
🧌
010
vlt /vōlt/ @vlt.io · 12/08/2026
Like 1Gigabit... 1 Gigabyte... or...?
210
Reposted by vlt /vōlt/
Jake Bailey @jakebailey.dev · 12/08/2026
TypeScript, now downloaded... 1G a month?
TypeSCript

CI | passing
npm package | 7.0.2
downloads | 1G/month
9526
vlt /vōlt/ @vlt.io · 12/08/2026
What if Semantic Versioning solved "is this compatible?" but not "is this safe?" SBOMs, provenance, lifecycle safety—all fragmented across ecosystems. Can we build *on* semver instead replacing it? Check out Darcy Clarke's talk, "Beyond Semver" at Node.js Interactive, Render ATL, Wed 2pm ET.
030
Reposted by vlt /vōlt/
Catalin Cimpanu @campuscodi.risky.biz · 11/08/2026
ShinyHunters claims Metabase hacking spree
066
vlt /vōlt/ @vlt.io · 11/08/2026
Seems that's where the industry is moving!
010
vlt /vōlt/ @vlt.io · 11/08/2026
My SS26 glowup 💈
010
vlt /vōlt/ @vlt.io · 11/08/2026
Came here to say it's much easier to pull bluesky than x metrics
040
vlt /vōlt/ @vlt.io · 10/08/2026
hi!
120