Reposted by vlt /vōlt/Ruy Adorno @ruyadorno.com · 29/09/2026Thanks @vlt.io for contributing! 🔈 audio on to hear it from @nodeland.dev 0114
vlt /vōlt/ @vlt.io · 24/09/2026Your private JavaScript registry can now publish to the public. Public packages are now GA. Publish and install the packages you want to share with the ecosystem. Read the full announcement here ↓ www.vlt.io/blog/public-...vlt.ioPublic Packages | vlt /vōlt/Explore the JavaScript ecosystem without an account, and publish packages from your own registry for anyone to install. 060
vlt /vōlt/ @vlt.io · 28/08/202610 versions of @7nohe/openapi-react-query-codegen was published to npm in an ongoing attack. They contained provenance. buff.ly/LHuOYgwbuff.lySecurity: package is currently publishing malicious code · Issue #218 · 7nohe/openapi-react-query-codegenBetween 2026-08-28 20:00 and 20:21 UTC, 8 versions of @7nohe/openapi-react-query-codegen were published to npm containing a remote-code-execution payload. This includes 3.0.4, the current latest ta... 030
Reposted by vlt /vōlt/Evert Pot @evertpot.com · 27/08/2026Are you talking about paths in a tar escaping the base path? A good package manager should prevent this. I know both npm and vlt do. 111
vlt /vōlt/ @vlt.io · 27/08/2026🤔 Imma bat this to @evertpot.com @ruyadorno.com who might know more 020
vlt /vōlt/ @vlt.io · 26/08/2026vlt 1.0.5 just dropped 🚢 ⚓️ → Dependency-deduping cuts installs with duplicated deps 40% smaller → Warm cache skips the network entirely → Safe by default: tar decompression-bomb caps & path-traversal hardening before anything writes to disk github.com/vltpkg/vltpk... 140
Reposted by vlt /vōlt/Orta Therox @orta.io · 24/08/2026I've 1.0.0'd my Danger JS re-write today: Risk If you use Danger in GitHub + GitHub Actions then it should be a simple dependency switch and you'd end up with substantially less moving parts I've been using it daily in Puzzmo for 6 months with no issues npmx.dev/package/risk 3222
vlt /vōlt/ @vlt.io · 25/08/2026npm run dev // exit 1 npm ls view // finds 2 different versions of webpack, 1 major apart // spends 3 hours vacillating between stack overflow and console trying to make It build again Those were the days... 010
vlt /vōlt/ @vlt.io · 24/08/2026Your package.json lists 20 dependencies. Your node_modules has 800. The 780 you didn't add are where supply-chain risk actually lives. How many transitive deps are in your last install? 000
vlt /vōlt/ @vlt.io · 23/08/2026Every JS dev has run `npm audit fix --force` and watched their build break. Automated security fixes don't understand your dep graph. The fix that 'solves' the CVE creates three new problems. What did `--force` break for you? 130
vlt /vōlt/ @vlt.io · 21/08/2026Linux users: watch out for these trojan npm packages masquerading as working calendar and streak utils thehackernews.com/2026/08/14-t...thehackernews.com14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Trojanized npm packages launch RedC2 4.0 on Linux at import time, giving operators shell access, credential theft, and payload execution. 010
vlt /vōlt/ @vlt.io · 21/08/2026Whether you're building SBOMs, running vulnerability scans, or just trying to keep your supply chain straight, it's the common URL syntax we've needed for cross-ecosystem refs. packageurl.orgpackageurl.orgHome | www.packageurl.orgLanding page for www.packageurl.org. 010
vlt /vōlt/ @vlt.io · 21/08/2026Ever tried matching an npm package to a CVE, only to realize every security tool names dependencies differently? 🙃 Enter PURL (Package URL). It’s an open standard that gives software packages a uniform string identifier—regardless of registry, ecosystem, or language. 200
Reposted by vlt /vōlt/James Snell @jasnell.me · 21/08/2026Friends don't let friends let AI name things. 121
vlt /vōlt/ @vlt.io · 20/08/2026RSS is... RDF Site Summary? Rich Site Summary? Really Simple Syndication? well, we're on it. www.vlt.io/rss.xml #iykykvlt.iohttps://www.vlt.io/rss.xml 100
vlt /vōlt/ @vlt.io · 20/08/2026I think his person (who shall not be named) was trained on the LLM in this case 110
Reposted by vlt /vōlt/Evert Pot @evertpot.com · 20/08/2026My cowoker dropped 'load bearing' in a conversation 😭 351
vlt /vōlt/ @vlt.io · 19/08/2026vlt v1.03 dropped with faster installs at every layer. 158x faster packument generation. A warm cache that skips the network entirely on your second install. Tarball extraction, parallelized. github.com/vltpkg/vltpk... 022
vlt /vōlt/ @vlt.io · 19/08/2026A developer's dilemma: Your security audit flags a CVE. You have to upgrade to the next version to fix it. If you upgrade, you'll have to refactor your whole app to adapt to breaking changes. If you don't upgrade, the CVE alert persists. Maintaining prod is full of hairy decisions. 000
vlt /vōlt/ @vlt.io · 17/08/2026Maintainers shouldn't carry the security & hosting burden alone. We offer free package hosting for qualified open-source maintainers—high-reliability infrastructure & registry-level security so you can focus on building. Apply here: www.vlt.io/open-source/... 000
vlt /vōlt/ @vlt.io · 17/08/2026Deep dependency trees & unmaintained packages create constant operational tax for dev teams. Upgrading nested packages shouldn't mean risking broken lockfiles or malicious lifecycle hooks. When 98% of app stacks run on open source, maintainer infrastructure becomes critical. 110
vlt /vōlt/ @vlt.io · 17/08/2026The 2026 Black Duck OSSRA report dropped some wild data for JS/TS teams: • Open source powers 98% of commercial apps • 64%+ of JS dependencies are transitive (node_modules depth) • 93% of codebases rely on unmaintained "zombie" packages • Unsafe preinstall scripts remain a top vector 🧵 100
Reposted by vlt /vōlt/Artem Zakharchenko @kettanaito.com · 16/08/2026We made a huge mistake with the Fetch API. We brought it to the server. 1193
vlt /vōlt/ @vlt.io · 16/08/2026This weekend I read over the vlt team's dependency graph code and it blew my mind. Package management and install time safety is a very difficult problem space because all tools resolve dependencies differently. 000
Reposted by vlt /vōlt/tierney cyren @bnb.im · 14/08/2026“coding is largely solved” okay make a new cross platform web browser that supports every web platform spec to 100% compliance 70107580
Reposted by vlt /vōlt/Wes @notwes.bsky.social · 14/08/2026I am a big fan of building *on* existing systems over *replacing* them. I am still processing some of the stuff on semver.xyz, but I am a HUGE fan of the @vlt.io team's *approach* to engineering the future of package management.semver.xyzsemver.xyz — Semantic VersionsA modern versioning spec: restores build precedence and formally defines sets, ranges and comparators. Test the range grammar in your browser. 163
vlt /vōlt/ @vlt.io · 14/08/2026What you're saying reminds me of the xkcd "15th standard" comic xkcd.com/927/xkcd.comStandards 110
vlt /vōlt/ @vlt.io · 14/08/2026How do you prove whoever published your dependencies is who they say they are? Did the maintainer publish this, or did someone compromise the registry? With agents installing packages you can't read, that gap matters. How do you verify package integrity? #supplychainSecurity 000
vlt /vōlt/ @vlt.io · 13/08/2026Your AI agent just installed 47 packages you didn't read. One might be malicious, but the registry will served it anyway. When agents control dependencies, the trust chain breaks. Where does security live? #supplychainSecurity #JavaScript 020
Reposted by vlt /vōlt/Kate Holterhoff, PhD @kateholterhoff.com · 12/08/2026Dependency hell!! Oh no, w @darcyclarke.me at @nodejs.org Interactive at @renderatl.com #NodeJSInteractive 083
Reposted by vlt /vōlt/Jake Bailey @jakebailey.dev · 12/08/2026TypeScript, now downloaded... 1G a month? 9526
vlt /vōlt/ @vlt.io · 12/08/2026What if Semantic Versioning solved "is this compatible?" but not "is this safe?" SBOMs, provenance, lifecycle safety—all fragmented across ecosystems. Can we build *on* semver instead replacing it? Check out Darcy Clarke's talk, "Beyond Semver" at Node.js Interactive, Render ATL, Wed 2pm ET. 030
Reposted by vlt /vōlt/Catalin Cimpanu @campuscodi.risky.biz · 11/08/2026ShinyHunters claims Metabase hacking spree 066