Grilled Cheese

ExploreLog inSign up

vlt /vōlt/

@vlt.io

363 Following850 Followers

JavaScript registries and tooling for teams that move fast.

PostsRepliesMedia
@evertpot.comOct 7, 2026, 11:19 PMReposted by @vlt.io

Fun fact about the NPM replication feed. If you just follow the feed to get updates for ever package, you will miss packages because they retroactively insert changes in the *past* of the feed.

@lukekarrys.comOct 6, 2026, 6:34 PMReposted by @vlt.io

on the ⚡️ @vlt.io ⚡️ registry we serve metadata that is 70% smaller which is one reason (out of many!) that we're able to do clean installs in 20-70% less time when you point to our registry vs npmjs.org. i wrote about how we did it:

@ruyadorno.comSep 29, 2026, 9:44 AMReposted by @vlt.io

Thanks @vlt.io for contributing! 🔈 audio on to hear it from @nodeland.dev

@vlt.ioSep 24, 2026, 3:04 PM

Your private JavaScript registry can now publish to the public.
Public packages are now GA. Publish and install the packages you want to share with the ecosystem.
Read the full announcement here ↓ www.vlt.io/blog/public-...

@vlt.ioAug 28, 2026, 9:40 PM

10 versions of @7nohe/openapi-react-query-codegen was published to npm in an ongoing attack.

They contained provenance.

buff.ly/LHuOYgw

@vlt.ioAug 27, 2026, 11:52 PM

Trick question!

@evertpot.comAug 27, 2026, 12:25 PMReposted by @vlt.io

Are you talking about paths in a tar escaping the base path? A good package manager should prevent this. I know both npm and vlt do.

@vlt.ioAug 27, 2026, 12:21 PM

🤔 Imma bat this to @evertpot.com @ruyadorno.com who might know more

@vlt.ioAug 17, 2026, 12:36 AM

Maintainers shouldn't carry the security & hosting burden alone.
We offer free package hosting for qualified open-source maintainers—high-reliability infrastructure & registry-level security so you can focus on building.
Apply here: www.vlt.io/open-source/...

@vlt.ioAug 17, 2026, 12:36 AM

Deep dependency trees & unmaintained packages create constant operational tax for dev teams. Upgrading nested packages shouldn't mean risking broken lockfiles or malicious lifecycle hooks. When 98% of app stacks run on open source, maintainer infrastructure becomes critical.

1
@vlt.ioAug 17, 2026, 12:36 AM

The 2026 Black Duck OSSRA report dropped some wild data for JS/TS teams: • Open source powers 98% of commercial apps • 64%+ of JS dependencies are transitive (⁠node_modules⁠ depth) • 93% of codebases rely on unmaintained "zombie" packages • Unsafe ⁠preinstall⁠ scripts remain a top vector 🧵

1
@vlt.ioAug 16, 2026, 2:29 PM

This weekend I read over the vlt team's dependency graph code and it blew my mind. Package management and install time safety is a very difficult problem space because all tools resolve dependencies differently.

FFrontend Dogma@frontenddogma.comAug 16, 2026, 8:30 AM

Why npm Dependency Trees Are So Big, by @[email protected]: https://nesbitt.io/2026/07/28/why-npm-dependency-trees-are-so-big.html?ref=frontenddogma.com #npm #dependencies

nesbitt.ioWhy npm Dependency Trees Are So BigTwo versions of lodash walk into a tree
@vlt.ioAug 14, 2026, 10:46 PM

That's a feat to behold - and to stick with - at work!

@vlt.ioAug 14, 2026, 7:13 PM

What you're saying reminds me of the xkcd "15th standard" comic xkcd.com/927/

xkcd.comStandards
1
@vlt.ioAug 14, 2026, 4:01 PM

How do you prove whoever published your dependencies is who they say they are?

Did the maintainer publish this, or did someone compromise the registry?

With agents installing packages you can't read, that gap matters.

How do you verify package integrity?

#supplychainSecurity

@vlt.ioAug 13, 2026, 6:30 PM

Your AI agent just installed 47 packages you didn't read. One might be malicious, but the registry will served it anyway.

When agents control dependencies, the trust chain breaks. Where does security live?

#supplychainSecurity #JavaScript

@vlt.ioAug 13, 2026, 1:36 AM

🧌

@vlt.ioAug 12, 2026, 7:11 PM

Like 1Gigabit... 1 Gigabyte... or...?

2
@vlt.ioAug 12, 2026, 2:01 PM

What if Semantic Versioning solved "is this compatible?" but not "is this safe?" SBOMs, provenance, lifecycle safety—all fragmented across ecosystems. Can we build *on* semver instead replacing it? Check out Darcy Clarke's talk, "Beyond Semver" at Node.js Interactive, Render ATL, Wed 2pm ET.

@vlt.ioAug 11, 2026, 12:25 PM

Seems that's where the industry is moving!

Older posts
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-11 02:37:10 EDT