Install, publish, and query with vlt
Most registries treat your packages as files to store. vlt treats them as a dependency graph to understand.
Set up your agent
Every page on this site is also available as Markdown, and /llms.txt indexes them all. Paste this prompt into your agent to point it at the docs:
Help me use vlt in this project. Start by reading https://docs.vlt.sh/llms.txt, which lists every page of the vlt docs. Any page is available as Markdown by adding .md to its URL (for example https://docs.vlt.sh/client/auth.md), and https://docs.vlt.sh/llms-full.txt has the whole site in one file.
1. Install the vlt CLI with `curl -fsSL https://install.vlt.sh | bash` (it requires Node.js 22.22 or later), then run `vlt install`.
2. To use vlt.io registries, run `vlt setup`. It authenticates and configures the account's registry aliases in one step.
3. To answer questions about dependencies, write Dependency Selector Syntax queries and run them with `vlt query '<selector>'`. The syntax is documented at https://docs.vlt.sh/client/selectors.md. If you support Agent Skills, the dss-query skill at https://github.com/vltpkg/vltpkg/tree/main/src/query/skills/dss-query covers it.
Only use commands and flags that appear in the docs.llms.txt
An index of every page on this site, for agents to read before anything else.
Markdown pages
Add .md to any page's URL for a plain Markdown copy, or read the whole site in one file.
DSS query skill
An agent skill that composes and explains vlt query selectors, including Socket-powered security audits.
Guides
Walkthroughs for the things teams set out to do first.
- Set up your private registry
Create an account and point your package manager at it.
- Publish from CI
Install and publish from CI with a service token.
- Control who can publish
Give members roles and scope access to packages.
- Migrate from npm, yarn, or pnpm
Move your config, commands, and lockfile over.
- Catch malware in your dependencies
Find risky packages with Socket-powered selectors.
- Run a monorepo with workspaces
Define workspaces and run commands across them.
- Test only what changed
The workspace you touched, plus everything that depends on it.
- Query your dependency graph
Select packages with CSS-like queries.
Host your packages
Using Packages
Pull public and private packages through your account's registries with the package manager you already use.
Publishing
The registry speaks the npm registry protocol, so publish with vlt, npm, pnpm, yarn, bun, deno, or from CI.
Members & Access
Manage who can reach your registries, packages, tokens, and settings through account membership and roles.
Authentication & Tokens
Every registry request is authenticated with a bearer token that belongs to your account.
Dashboard
See your account overview and recent publishes, and manage registries from one place.
Manage your dependencies
Security & Malware Detection
Identify and assess security risks in your dependencies through vlt's integration with Socket.
Dependency Selector Syntax
Filter and select packages in your dependency graph with CSS-selector-like queries.
Workspaces
Define multiple workspaces in a single monorepo project and work across them with the vlt client.
Catalogs
Define dependency versions centrally and share them across your projects and workspaces.
Affected Dependencies
Find the workspace you touched plus everything that depends on it before you test, build, or publish.
Graph Modifiers
Alter and refine how the dependency graph is traversed and evaluated, with granular control.
Migrating to vlt
Switch from npm, yarn, or pnpm with step-by-step guides for configuration and commands.