Advertisement · 728 × 90

Posts by vlt /vōlt/

Preview
Attackers Are Hunting High-Impact Node.js Maintainers in a C... Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

📖 This article by @sarahgooding.bsky.social at @socket.dev highlights a concerning trend (ref. socket.dev/blog/attacke...)

📕 Story time: this kind of supply chain targeting isn't unique. I myself & everyone on our team @vlt.sh have been the targets of consistent, concerted efforts.

1 week ago 17 9 1 0

tldr; if you used @vlt.sh as your package manager, then you were protected the minute @socket.dev flagged the malicious packages in the `axios` attack yesterday. The best time to switch your package manager was 48hrs ago, the next best time is right now.

More below: blog.vlt.sh/blog/vlt-build

1 week ago 12 7 0 2
Graph showing daily new packages being uploaded to NPM for the last 12 months and showing a lot of growth since the start of 2026.

Graph showing daily new packages being uploaded to NPM for the last 12 months and showing a lot of growth since the start of 2026.

Yesterday we saw the most _new_ NPM packages being released in the last 12 months, at 2804 packages.

Pretty steady upward trajectory here, unlike we've ever seen. This graph is spiky because it's daily data and weekends are lower.

1 month ago 9 3 0 0
Post image

The @vlt.sh benchmark suite has been updated to include the yarn v6 canaries (still a WIP & improving all the time): benchmarks.vlt.sh

2 months ago 12 4 0 0

🧑‍💻 Come "Cowork with Friends" tomorrow in Downtown Mesa!

We'll be at Pair Cupworks from 8:30am-12pm.

@vlt.sh will be sponsoring beverages and raffling off 1 free ticket to @halfstackconf.bsky.social Phoenix!

Join the group or just show up! coworkwithfriends.com/group/downto...

2 months ago 5 1 0 0
Preview
Next-Gen JavaScript Package Management with Ruy Adorno and Darcy Clarke - Software Engineering Daily Package management sits at the foundation of modern software development, quietly powering nearly every software project in the world. Tools like npm and Yarn have long been the core of the JavaScript...

Darcy Clarke and Ruy Adorno are longtime npm CLI maintainers and Node.js contributors. They join @joshuakgoldberg.com to discuss vlt, a new package manager and registry designed to improve performance, security, and developer experience.

@darcyclarke.me
@ruyadorno.com

bit.ly/3YNGniF

2 months ago 5 3 0 0
Post image Post image

@lukekarrys.com joins HalfStack Phoenix.

A practical story about building for kids, using NFC cards to control music, and turning everyday interactions into something playful and intuitive.

📅 𝐉𝐚𝐧𝐮𝐚𝐫𝐲 𝟑𝟎𝐭𝐡, 𝟐𝟎𝟐𝟔 — 𝐌𝐚𝐣𝐞𝐬𝐭𝐢𝐜 𝐓𝐡𝐞𝐚𝐭𝐞𝐫, 𝐆𝐢𝐥𝐛𝐞𝐫𝐭

🎟️ halfstackconf.com/phoenix

#HalfStackphoenix #TechEvents

3 months ago 10 5 1 0
Advertisement

Today, we published a security release for @nodejs.org that fixes a critical bug affecting virtually every production Node.js app.

If you use React Server Components, Next.js, or ANY APM tool (Datadog, New Relic, OpenTelemetry), your app could be vulnerable to DoS attacks.

👇

2 months ago 80 21 2 4
Post image

The top licenses published on #npm .

Number #2 is interesting because it's not really a well-known one, but it's the default choice when running `npm init`, so it likely represents all the people that just pressed enter without having an opinion. [1/2]

4 months ago 16 4 4 0
Preview
Introducing Phased Package Installations When you run vlt install, packages are downloaded and extracted to node_modules, but no lifecycle scripts execute.

🚀 Here is @vlt.sh take on running lifecycle scripts on installs, adding another powerful capability to our query language syntax: blog.vlt.sh/blog/vlt-build

#javascript #nodejs #packages

4 months ago 9 4 2 0
The Registry is Dead, Long Live the Registry! - Darcy Clarke, vlt
The Registry is Dead, Long Live the Registry! - Darcy Clarke, vlt YouTube video by OpenJS Foundation

If you think npm's architecture is good, go watch @darcyclarke.me's talk. The dependency graph is complex and @vlt.sh is reinventing it in a smart and unique way. www.youtube.com/watch?v=o8nG...

5 months ago 8 4 0 0
Post image

Huge thanks to the @vlt.sh team for building something new and refreshing in the world of package managers and taunting me with LEGO to try it out.

Join me and check them out: www.vlt.sh

5 months ago 16 5 0 0
Post image

Thanks @vlt.sh! This is awesome!

5 months ago 8 1 0 0
Preview
Query Across Projects with the host selector The host selector is a pseudo-selector that switches your current graph context to load dependencies from different project sources

Seeing the recent supply-chain attacks made me prioritize this item from our backlog as I wanted a quick way to know if any of my local projects have been affected.

Meet the new vlt client `:host()` Query selector:

blog.vlt.sh/blog/host-co...

#javascript #nodejs #packages

6 months ago 8 5 0 0
Advertisement
Video

⚡ Point. Click. Discover.

🚀 We're excited to unveil a new Query Builder to @vlt.sh's UI. It's now dead simple to visually navigate complex dependency graph filters without typing a thing. No need to memorize our selector syntax (if you don't want to).

7 months ago 5 2 1 0
Preview
Query Powered vlt Commands Run scripts across your dependency graph using powerful query selectors and the --scope config.

🚀 Dependency Selector Syntax can now be used across @vlt.sh commands like run, exec, and pkg!

This enables precise filtering when running scripts, executing commands, or getting package info. You have access to the whole graph!

Read more about how it works and some example use cases:

7 months ago 5 4 0 0
Preview
vlt is now available in builds via zero configuration - Vercel The package manager vlt is now available as a zero-config option, auto detected based on the presence of a lockfile in your build.

🚀 @vercel.com now supports vlt in builds with zero config: vercel.com/changelog/vl... @vlt.sh

8 months ago 9 2 0 0
Preview
Taking Control with Graph Modifiers Managing dependencies in complex JavaScript projects just got easier. vlt now offers Graph Modifiers, a new way to take precise control of your dependency graph.

🚀 Excited to announce another major addition to the @vlt.sh client: Graph Modifiers!

Graph Modifiers enable fine-grain customization of your install using our powerful Dependency Selector Syntax ⚡️

Read more about it here: blog.vlt.sh/blog/introdu... #javascript #nodejs #packages

8 months ago 8 5 1 0
Preview
Community Sync Agenda - Week of Jul 27 (2025-07-28) · Issue #1056 · vltpkg/vltpkg Community Sync Agenda - Week of Jul 27 (2025-07-28) Meeting Date: Thursday, July 31, 2025 at 2:00 PM EST Stream Link: https://riverside.fm/studio/vlt-community YouTube: https://www.youtube.com/@vlt...

💬 @vlt.sh is starting Weekly Community Sync calls today (in ~5min actually); here's the deets:

📝 Agenda: github.com/vltpkg/vltpk...
🎙️ Join: recording.vlt.sh
🔴 Watch...
On Riverside: recording.vlt.sh
On YouTube: www.youtube.com/@vltpkg/live

Excited to build together!

8 months ago 8 2 2 0
Preview
Centralized Dependency Management Made Simple We are excited to share catalog support - a powerful new feature for centralized dependency management that reduces duplication and simplifies version orchestration across your projects.

🚀 We just shipped catalog support to @vlt.sh! If you go grab the latest version you can now install & manage dependencies with pnpm-like catalog definitions (ex. `vlt i typescript@catalog:dev`).

You can read more here: blog.vlt.sh/blog/catalog...

8 months ago 10 3 0 0
Preview
We're looking for a Senior Backend Engineer to join our team at vlt technology inc.. | Darcy Clarke We're looking for a Senior Backend Engineer to join our team at vlt technology inc.. based here in Toronto at our HQ. If you love JavaScript & open source this may be right up your alley. Please share...

We're looking for a Senior Backend Engineer to join our team at @vlt.sh based here in Toronto 🇨🇦 at our HQ. If you love JavaScript & open source this may be right up your alley. Please share if you know anyone who would be a great fit.

www.linkedin.com/posts/darcyc...

#javascript #nodejs #packages

8 months ago 11 9 0 1
Video

JSR now supports @vlt.sh 🎉

10 months ago 22 4 0 0
Advertisement

For the record the secret logo is @vlt.sh! Now I will never forget your logo! 😂

11 months ago 10 2 0 0
Packages

🙇‍♂️ Thank you @vlt.sh @ruyadorno.com et al. for giving the community a cohesive toolkit for working with packages docs.vlt.sh/packages. I wish I had some of these when I was building Paka with @schickling.dev ❤️!

11 months ago 5 1 1 0
Preview
Package Insights Selectors Powered by Socket Unlock deep, actionable insights into your dependencies with vlts new security-first selectors — powered by metadata from Socket.

Learn more about it: blog.vlt.sh/blog/insight...

11 months ago 5 0 1 0
Video

In partnership with @socket.dev we're bringing Socket Package Alerts to your local dependencies when using the vlt client.

Introducing Package Insight Selectors, a powerful addition to our Dependency Selector Syntax that helps you understand and secure your node_modules folder.

#js #nodejs #vlt

11 months ago 6 4 1 0
Preview
Package Insights Selectors Powered by Socket Unlock deep, actionable insights into your dependencies with vlts new security-first selectors — powered by metadata from Socket.

vlt client: query package data for security information (provided by Socket)
@ruyadorno.com @vlt.sh
blog.vlt.sh/blog/insight...

#ECMAScript #JavaScript

11 months ago 5 3 0 0
Video

We're excited to announce the new Insights Selectors to the @vlt.sh's Dependency Selector Syntax.

This new information allows you to query packages based on a variety of security-focused metadata powered by @socket.dev! ⚡️

11 months ago 11 3 1 1
Post image

🚀 We just launched `$ npx reproduce <pkg>`

1 year ago 27 9 3 2
Advertisement
bart simpson standing in front of a smoky the bear machine with the text:

YOU PRESSED "YOU," REFERRING TO ME. THAT IS INCORRECT. THE CORRECT ANSWER IS YOU.

bart simpson standing in front of a smoky the bear machine with the text: YOU PRESSED "YOU," REFERRING TO ME. THAT IS INCORRECT. THE CORRECT ANSWER IS YOU.

whenever i try to use `--ours` vs `--theirs` in git:

1 year ago 56 10 7 1