Your private JavaScript registry can now publish to the public.
Public packages are now GA. Publish and install the packages you want to share with the ecosystem. Read the full announcement here ↓ vlt.io/blog/public-packages
OpenAI confirmed its agents were behind the GemStuffer incident. Sandboxed during a training run without full internet access, they used the registry as a makeshift web browser to reach the open web. Story by @bobmcmillan with analysis from @socketsecuritywsj.com/tech/ai/cyberattack-…
Today we're launching Surfaces on Traces
A new way to visualize your agent session activity, for everything from skills used, token consumption, security issues and much more.
Available for all your sessions on traces.com.
🏛️ announcing hunk v0.22.0 - now w/ `hunk log`
- TUI for reviewing git/jj history
- quickly jump from commit → diff
- OR multi-select a commit range
- supports mouse + all colour themes
also in this release: multi-line comments, lower memory usage, faster --watch, & more! 🔈
Have you started muting/unfollowing/blocking people you used to follow that are blatantly using AI to write their tweets? I'm wondering if I should curate my feed more but I'm concerned it's too late/everyone is doing it.
This can't be overstated. Funny enough, dual support outpaces esm-only (expected, as maintainers want the broadest interop). We're almost a decade in & esm-only pkgs are only growing at ~2% /yr; at that pace, it'd take another decade to hit ~50%.
refs. github.com/wooorm/npm-esm-vs…
Damn.. @vltpkg is great 👌 Bye NPM SHIT!
Simple setup:
- VLT proxy CF Worker with 2 service tokens
== read-only token for consumer reads
== read-write for convenience
- have a Github CI that publish to VLT with OIDC.
- have npm .wgw .lol as registry for ONLY MINE pkgs
Lovely.
v1.03 just dropped with faster installs at every layer.
158x faster packument generation.
Warm cache that skips the network entirely.
Tarball extraction, parallelized.
github.com/vltpkg/vltpkg/rel…