Ship JavaScript? Hang onto your lockfile

vlt /vōlt/

  • PricingDocs (opens in new window)Benchmarks (opens in new window)
Sign UpLog In
A hero image depicting ascii characters arranged in an organic wave-like pattern

JavaScript package registries
for teams that move fast

Publish scoped and private packages, manage organizations and access, and give every developer and CI environment a consistent source for public and private JavaScript dependencies.

Start Publishing
Schedule a Call

A better registry

vlt is built around the JavaScript dependency graph from the ground up, making package delivery faster, safer, and easier to understand and control.

Start publishingBook a demo

JavaScript packages are not idempotent artifacts; they form enormous, dynamic dependency graphs that affect every install, build, and deployment. Most registries are glorified S3 buckets designed to store files statically - not leveraging any understanding of dependent relationships or linking critical associative metadata.

Move fast
without changing your tools

Book a demoLearn more

vlt serves npm-compatible packages through infrastructure purpose-built for JavaScript package distribution. Fine-tuned caching, smaller payloads, and faster CI—all while remaining fully compatible with the tools your team already uses.

76% Smaller
packuments delivered

Less bandwidth and smaller caches.

vlt
~228 MB
npm
~952 MB

Top 10k packages averaged (gzip)

73% Faster
package installs

Cuts CI compute time with every install.

vlt
1.3s
npm
4.8s

Astro project installation

Benchmark
38% Faster
registry performance

Faster installs without changing tools.

vlt
12.0s
npm
19.4s

Astro project installation

Benchmark

Installing registry packages

70% faster installing packages compared to traditional tools from the npm registry

Executing scripts

70% faster installing packages compared to traditional tools from the npm registry

Cataloging dependencies

Organize your dependencies, and catalog them to keep your codebase simple

npm registry

$npminstallnext

⠋ resolving dependencies…

added 42 packages in 3.1s

vlt registry

$vltinstallnext

resolving dependencies ✓ >extracting files ✓

23 cache hits

75 requests

Done in 1.1s

$

How much could you save?

Estimate your monthly CI savings. Adjust your install volume to see how vlt compares to npm on GitHub Actions 4-core runners.

Installs / mo
100K
25k100k1.0M10M100M

How does vlt compare?

vltLowest~$1.6K
npm~$5.8K

Savings breakdown

ItemQuantityCost
CI compute saved~368 hrs / mo$353 /mo
Annualized× 12 mo$4.2K
Estimated savings / yrBased on npm-vs-vlt install times on GitHub Actions 4-core runner pricing.
~$4.2K

Stop unsafe packages
before they reach your builds

Book a demoLearn more

Every request for a public package passes through a security layer that blocks known malware and high risk software. Using vlt’s client reduces install-time risk further with safer package-manager defaults and configurable policies at the point of consumption.

Registry protection

$vltimalware

resolving dependencies ✗

Error: [404] - Package not found in registry

$

Malicious packages get blocked automatically, backed by continuous advisory and malware scanning across a safe npm mirror.

Safer installation

$vltinext

resolving dependencies ✓ > extracting files ✓

📦 1 packages have install scripts

🔎 Run `vlt query :scripts` to list them

🔨 Run `vlt build` to run all required scripts

$

Lifecycle scripts are restricted or disabled by default, risky behaviors require explicit approval, and hardening is secure-by-default rather than opt-in.

Organizational policy

$vltquery:scripts

project

└─┬ next@16.2.11

└── sharp@0.34.5

$

Query the dependency graph with DSL, then turn those queries into enforceable CI rules that block dependencies based on package properties, relationships, or security metadata.

Understand
every dependency

Book a demoLearn more

Explore your project’s fully resolved dependency graph (no theoretical SBOMs here). Trace why a dependency exists, inspect how specifications resolve, identify affected transitive packages, and query the graph with a powerful selector syntax designed specifically for JavaScript dependencies.

$vltconfigsetregistry=https://registry.vlt.io/acme/npm/

Config updated

$vltlogin

Logged in successfully

$vltinstall

$

Explore

Browse private packages and upstream mirrored npm packages

Setup instructions

$vltquery[name^=cookie]

project

└─┬ express@5.2.1

├── cookie@0.7.2

└── cookie-signature@1.2.2

$

Trace

See why and how dependencies were resolved

Learn more

$vltquery:fs

project

├─┬ express@5.2.1

│ ├── etag@1.8.1

│ ├─┬ send@1.2.1

│ │ └── etag@1.8.1

│ └─┬ serve-static@2.2.1

│ └── send@1.2.1

$

Query

Identify packages using Dependency Selector Syntax

Query documentation

✓ :malware - 0 results

✓ :vulnerable - 0 results

✓ *:license(copyleft) - 0 results

✓ :deprecated - 0 results

✗ :root > * - 28 results

Failed: 1 of 5 queries did not

meet expectations

$

Control

Convert those queries into policies and graph transformations

Policies

Private registries
built for JavaScript teams

Start publishingLearn more

Publish scoped and private packages, manage organizations and access, and give every developer and CI environment a consistent source for their public and private software.

Invite team members

Create an account, and invite members to your organization to start collaborating

Join many organizations

Join multiple organization with a single account, and collaborate across many teams

Explore trusted packages

Explore and install trusted packages from the secure npm mirror

Publish private packages

Publish packages with to your organization’s registry and start installing trusted packages

Latest News

July 23security

Ship JavaScript? Hang onto your lockfile

Desaturated, grainy close-up of colored pushpins on a map with dramatic backlight and long shadows

Pinning dependencies in package.json won't save you in a supply-chain attack — a committed lockfile does. Here's why, and how to install so it holds.

Jen Chan

July 08open source

Beyond disabling postinstalls: how npm install will change in npm 12

npm 12 breaking changes banner

As part of its planned 12th release, the npm CLI drops automatically running lifecycle scripts on installs as part of multiple planned breaking changes

Ruy Adorno Staff Software Engineer

June 23registry

Why Drizzle ORM couldn't publish new releases on NPM for a month

Package publish version banner

Drizzle ORM recently hit a 100 MB limit in the npm registry and couldn't ship new releases for weeks. What is this limit?

Evert Pot Staff Software Engineer

Ready to build
something extraordinary?

Start PublishingSchedule a Call
Open Source
  • Package Manager
  • Serverless Registry
  • Policies
  • Reproduce
  • Packages & Ecosystem
Platform
  • Registry
  • Security
  • Observability
  • Packages
  • Projects
Resources
  • Blog
  • Press
  • Brand Kit
  • Benchmarks
  • Documentation
Company
  • About
  • Careers
  • Status
  • Contact
© 2026 vlt technology inc, All rights reserved
  • Terms
  • Privacy
  • Security