luke karrys
@lukekarrys.com
biking in the desert • coding at @vlt.sh • contributing to the open source JS ecosystem • here to help 👋🏼 🕸️ lukekarrys.com 💾 github.com/lukekarrys 📷 photos.lukelov.es
big day at work. time to unwind with **checks notes** 2 apple sauce pouches and an hour of z2? that can’t be right
"it's a patch release because it was a bug that we forgot to include that feature previously"
🎉 it's launch day at @vlt.io! 🎉 - use our new drop-in npm replacement to protect yourself from malware and increase performance - create private registries to share packages with your team - oh and the vlt CLI is now v1! read more in our announcement post:
vlt 1.0 & Hosted Package Registries | vlt /vōlt/
Stable client release and general availability of hosted registries & ecosystem mirrors.
vlt.io
Excited to share vlt 1.0 along with our hosted registries & ecosystem mirrors now GA! A drop-in npm replacement, built so nothing runs on your machine just because you typed install. → faster delivery → malware blocking at the registry layer → graph-native querying
reeeeeally seems like hoerner should’ve challenged that call in the 6th. only defensible thing i can think of is that it was 3-0. would love to know the leverage index in that situation still. anyone know?
me breaking 15 minutes of dead silence in the gym sauna: so whaddya guys think about the 2025 atlantic article about the decline of casual nudity
i turned “bring my own reusable silicone bag of chia seeds on vacation” years old this year
fajita chicken, sautéed peppers, and cilantro lime rice (not pictured) for dinner. got an “amazing” from both 5yo and 8yo at the same meal. my life’s crowning achievement
my brain is broken that i was listening to a vinyl record and when the next track started i went "is this on shuffle?"
npm is now scanning packages for malware at publish time before they become available for consumption
npm publish-time malware scanning and dual-use metadata - GitHub Changelog
As part of our ongoing supply-chain security work, npm is introducing automatic scanning of packages at publish time. This changelog covers what publishers can expect and a new metadata requirement…
github.blog
without giving out to much PII we got my kids middle names from a pop star, a YA novel, and a train
Karaoke still runs on technology from the '80s. 🛼 What if we rebuilt it with Web Audio, AI, open-source models, and modern web APIs? Watch @monteslu.com give one of the most delightfully nerdy talks from CascadiaJS 2026. youtu.be/wk2Fj2H5eoI
As I head into the onsite phase with a bunch of cool companies, figured I’d put out one last call… ⚡️Would you like someone to make your frontend-heavy app faster or otherwise build/improve/take care of your frontend architecture or infrastructure? That person could be me! DM me! 🔥
my sister is an incredible artist and therapist. she made me a ceramic mask that hangs in my living room that is one of my prized possessions. she was accepted into an artist residency in italy and has a kickstarter to raise money for her to go. one of the tiers is your very own one-of-a kind masks!
Julia's Italian Art Residency
Please support my participation in the two-week interdisciplinary artist residency Baroque Blue Art & Nature Residency in Italy!
kickstarter.com
Something perfect happened in sports this morning, and I wrote about it
The Apotheosis
Two minutes and 42 seconds is not a big time gap in grand tour racing. Not in the first week of the race. Certainly not when Jonas…
medium.com
If you regularly publish to the npm registry, you might be concerned about package size 😁 But have you heard of PACKUMENT size? News flash: how often you publish, how long your manifest is, how many *exports* you have, can also eventually prevent you from publishing!
Why Drizzle ORM couldn't publish new releases on NPM for a month | vlt /vōlt/
Drizzle ORM recently hit a 100 MB limit in the npm registry and couldn't ship new releases for weeks. What is this limit?
vlt.io
You shouldn’t trust Trusted Publishing https://blog.yossarian.net/2026/07/07/You-shouldnt-trust-trusted-publishing #python #security #oss
8yo wanted to try a difficult hiking trail "just to see what its like". i said we could turn around whenever we wanted. luckily i brought 3L of water and plenty of snacks because we made it to the top!
Why Drizzle ORM couldn't publish new versions to NPM for a month: www.vlt.io/blog/packume...
Why Drizzle ORM couldn't publish new releases on NPM for a month | vlt /vōlt/
Drizzle ORM recently hit a 100 MB limit in the npm registry and couldn't ship new releases for weeks. What is this limit?
vlt.io
Very early sneak peek to pnpr - the pnpm registry: pnpm.io/pnpr/
Introduction | pnpm
pnpr is a pnpm-compatible npm registry server, written in Rust. It speaks the
pnpm.io
its been awhile since i hauled something with my cargo bike that made my family shake their head. i should remedy that
santa’s s̶l̶e̶i̶g̶h̶ cargo bike
I was curious what the NPM package with the most releases was, and turns out it's 'electron-remote-control' with 37,328 versions. https://www.npmjs.com/package/electron-remote-control
electron-remote-control
An advanced but easy-to-use remote desktop application with cross-platform support. Latest version: 1.4.4346, last published: a year ago. Start using electron-remote-control in your project by running `npm i electron-remote-control`. There are no other projects in the npm registry using electron-remote-control.
npmjs.com
Say hello to 🐣 fledgling - a new tool to create new npm packages and setup/sync trusted publishing (OIDC) settings. Works great for one offs, but even better in a monorepo! just `npx fledgling`