@vltpkgi
iAccount based inCanada
About this account
- Account based in
- Canada
- Connected via
- Canada Android App
Account-level information from X, not a live location or the device used for a specific post.
JavaScript package registries & tooling for teams that move fast.
Joined March 2023
- Tweets263
- Following257
- Followers1.5K
- Likes587
Your private JavaScript registry can now publish to the public.
Public packages are now GA. Publish and install the packages you want to share with the ecosystem. Read the full announcement here ↓ vlt.io/blog/public-packages
vlt /vōlt/ retweeted
Some more data for CI cold installs after switching to vlt's registry from npm.
35% faster at p90!
Switched to @vltpkg registry from npm and saw some nice improvements in cold installs and package metadata size
vlt /vōlt/ retweeted
🚀 Thrilled to announce @vltpkg as a #Silver #Sponsor of #NodeConfEU 2026!
Thank you! 💛
Your partnership is helping us create something truly special in the #Node.js #community!
🎟️ nodeconf.eu
vlt /vōlt/ retweeted
vlx hunkdiff # <3 – at Toronto, Ontario
vlt /vōlt/ retweeted
This can't be overstated. Funny enough, dual support outpaces esm-only (expected, as maintainers want the broadest interop). We're almost a decade in & esm-only pkgs are only growing at ~2% /yr; at that pace, it'd take another decade to hit ~50%.
refs. github.com/wooorm/npm-esm-vs… – at Mississauga, Ontario
10 versions of @7nohe/openapi-react-query-codegen was published to npm in an ongoing attack.
They contained provenance.
github.com/7nohe/openapi-rea…
vlt 1.0.5 is here 🚀
Faster installs when package.json declares duplicated depedencies: up to 40% smaller.
Safer installation and package publishing by default: tar decompression caps & path-traversal hardening enforced. github.com/vltpkg/vltpkg/rel…
vlt /vōlt/ retweeted
Crazyy...someone measured Claude's vocabulary across 47,464 GitHub pull requests.
A word cluster that didn't exist in 2025 is now 45% of human-authored PRs.
The top word is "load-bearing"
Replying to @LukeberryPi
You should be testing your UI
vlt /vōlt/ retweeted
Works perfectly on page 1.
Page 1000 takes 30 seconds.
Page 10000 crashes the server.
Pagination is supposed to make it faster.
It's making it slower.
Why? 🤔
vlt /vōlt/ retweeted
"Everything you've ever installed and built runs through infrastructure me and my team built [over the years in npm]"
what a fucking banger.
vlt.io/
vlt /vōlt/ retweeted
Developers:
Why doesn’t JSON allow trailing commas?
It looks harmless.
But this is invalid JSON.
Why?
vlt /vōlt/ retweeted
Damn.. @vltpkg is great 👌 Bye NPM SHIT!
Simple setup:
- VLT proxy CF Worker with 2 service tokens
== read-only token for consumer reads
== read-write for convenience
- have a Github CI that publish to VLT with OIDC.
- have npm .wgw .lol as registry for ONLY MINE pkgs
Lovely.
"Everything you've ever installed and built runs through infrastructure me and my team built [over the years in npm]"
what a fucking banger.
vlt.io/
Linux users: watch out for these trojan npm packages masquerading as working calendar and streak utils
thehackernews.com/2026/08/14…
vlt /vōlt/ retweeted
Replying to @ClaudeDevs
have you found the smoking gun to make the output less load-bearing?
Cross-ecosystem package tracking is a nightmare when every tool formats dependencies differently. 🧵
Enter PURL (Package URL)—the open standard bringing sanity to software supply chains.
Add ?qualifiers for OS/arch details and #subpath for specific subfolders inside a package, and you have an unambiguous, deterministic identifier for any software artifact.