I'm proud and excited to be supporting @darcy, @izs, and @ruyadorno as they build @vltpkg.
Their goal is a worthy one: massively improve the packaging ecosystem for developers everywhere.
🚀🚀🚀
Feross
@feross
Search for a command to run...
Podcast interviews, conference talks, and video coverage about vlt and the JavaScript ecosystem.
Articles, blog posts, and industry analysis covering vlt.
Announcing Bun and vlt Support in Socket
vlt is now available in builds via zero configuration
vlt Launches Real-Time Dependency Analysis Powered by Socket
vlt Launches "reproduce": A New Tool Challenging the Limits of Provenance
Node v22.11.0 (LTS)、Nuxt 3.14、vlt Package Manager
Our Seed Investment in vlt: The Future of JavaScript Packages
Solving the Challenges of the JS Ecosystem
vlt: The Future of JavaScript Package Management
vlt: A New Dawn for Package Management
vlt: The Next-Gen Package Manager by npm Veterans
npm Author Launches New JavaScript Package Manager
JSR Open Governance Board
A Paradigm Shift in JavaScript: Introducing vlt and VSR
Coverage of manifest confusion and npm security research by Darcy Clarke and the broader security community.
Patch Release GitLab 17.1.2 (CVE-2024-6595)
Manifest Confusion in npm Packages Identified by Novel Tool
800 npm Registry Packages at Risk of Manifest Confusion
Over 800 npm Packages Found with Discrepancies
npm Manifest Confusion Six Months Later
Manifest Confusion: A Major Bug in npm
npm Manifest Confusion: What Is It and Should You Worry?
Manifest Confusion: Don't Believe What You See
Node.js Users Beware: Manifest Confusion Attack
Addressing the npm Manifest Confusion Vulnerability
Manifest Confusion
npm's Manifest Confusion
npm Manifest Confusion: A Malware Hiding Weakness
npm Ecosystem Vulnerable to Manifest Confusion Attack
Manifest Confusion: A New Threat to npm Trust
Manifest Confusion
npm Ecosystem at Risk from Manifest Confusion Attacks
JavaScript Registry npm Vulnerable to Manifest Confusion
CVE-2024-6595
Featured in industry newsletters reaching thousands of JavaScript developers.
ECMAScript News (June 2025)
ECMAScript News (March 2025)
JavaScript Weekly #713
Node Weekly #557
Bytes.dev #371
JavaScript Weekly #680
What developers are saying about vlt across social media.
I'm proud and excited to be supporting @darcy, @izs, and @ruyadorno as they build @vltpkg.
Their goal is a worthy one: massively improve the packaging ecosystem for developers everywhere.
🚀🚀🚀
Feross
@feross
beyond stoked on what @darcy / @vltpkg team is cooking for the future of JavaScript packages
🫶✨🥺
Marc Laventure
@MarcLaventure
📦 At #NodeConfEU, @vltpkg debuted their new #JavaScript package manager and serverless registry, innovating in a space where npm has stagnated. Today on the Socket blog: Find out what the team has been creating for the past 6 months. 📩
Socket
@SocketSecurity
Can't wait for vlt to fix all our problems!!!! 🔥🔥🔥❤️❤️🙏🏾🙏🏾
Amal Hussein
@nomadtechie
Congrats @darcy @izs @ruyadorno and @lukekarrys on this launch!
'vlt gui' is SUPER COOL. Will come with more positive feedback when I kick the tires of the registry.
sMyle (🦋 @myles.dev)
@MylesBorins
How do you feel about npm? Not the client (npm vs. pnpm vs. yarn etc.), but the full product—package hosting, upload/download, team permissions, etc.?
I just had a call with @darcy about @vltpkg and honestly, I'm super stoked about it because it's what I hoped npm would become.
Tejas Kumar
@tejask
The JS ecosystem isn't known for its safety/security but this one is pretty wild. 👇
npm doesn't validate/compare a package's tarball and manifest.
You basically can't trust any info on npm relying on manifest metadata. 😥
Kudos to @darcy for uncovering!
Stefan Judis
@stefanjudis
Will npm be used mainly to install vlt like IE was used to install Chrome 🤔🙈
Jabran Rafique
@jabranr
Holy crap! Vlt — the new JavaScript package manager — just announced Isaac Schlueter is on the team.
Isaac is the creator of npm.
So now we have the guy who made Node working on JSR, and the guy who made npm working on vlt.
exciting times
Wes Bos
@wesbos
A new wave of innovation and investments in JS is coming.
Have you checked out @vltpkg yet?
Link in thread for the full interview.
Modern Web
@moderndotweb
I ❤️ @vltpkg's query syntax. I've found it helpful with "vlt view" (there's something similar with "npm query"). It's the better "list" option of package managers and is a pathway to actually get accurate results 🎉
jddalton.bsky.social
@jdalton
Exciting news for JavaScript developers!
Isaac Schlueter, the creator of npm, has brought back the original npm team to launch vlt. This new company is all about making JavaScript package management better.
vlt is introducing a new package manager and a serverless registry.
Amit Mirgal
@amit_mirgal
🙇♂️ Thank you @vlt.sh @ruyadorno.com et al. for giving the community a cohesive toolkit for working with packages. I wish I had some of these when I was building Paka ❤️!
Jason Kuhrt
@kuhrt.me