Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • So this is advertising as a secure npm?
  • The entire page doesn't even mention javascript :/
  • thanks for the feedback. we will update the announcement post. we at least try to make that clear on the main landing page https://www.vlt.io/home
  • Without identity federation via oidc it’s basically not really a replacement for verdaccio
    by merb
  • This is coming imminently but appreciate the feedback & will push to get this landed here quickly. That said, our client does support OIDC publishing if your registry does so hopefully you'll still find value there as it's a major step up from legacy npm clients.
  • Over a year I joined the waitlist and almost forgot that I did. Today the registry is open to deliver on its promises—secure the supply chain.
  • Founder here - thanks for the vote of confidence! We've got a lot more in store.
  • This will benefit the entire ecosystem. Well done.
  • Appreciate the kind words! We're excited to keep supporting this ecosystem.
  • Can anyone from vlt explain the inconsistencies in their performance over time graph? When I compare it w/ the npm baseline, it looks like it fluctuates between being ~4s faster typically but then there are periods where the performance is worse.

    I appreciate the transparency that the company has showing their performance, the early August degradation has me wondering what’s going on.

    by d_sc
  • I believe most, if not all of those, were due to some variation of adding some new feature/capability to the system and then making things faster again.
  • I am not sure exactly what this service is or why it is desirable. Pitch me in five seconds or less?
  • 5s: save time & money

    10s: vlt helps engineering teams build JavaScript software faster, reduce supply chain risk, and lower infrastructure costs (via. API perf / payload optimizations).

    20s: If you've used npm for years & are just narrowly escaping the various malware attacks or are on the hook for running up CI/agent bills at work because cold installs are X percent of the time compared to your actual builds/runtime, then you should check us out.

    22s: Also, <insert jFrog grumble>.