Content Quality: Well-organized News piece using the standard Overview / What We Know / What We Don't Know / Context structure. 647 words, within the 400-1200 News range. Prose is clear and appropriately technical for a developer-tooling launch story. The 'What We Don't Know' section appropriately flags that the 38%-faster and malware-flagging figures are company-reported and unverified by third parties.
Source Verification: All 5 sources fetched successfully (HTTP 200, no suspicious_patterns) and personally read from the gzipped snapshots in sources/2026-09/vlt-reaches-10-launching-hosted-package-registries-as-a-security-first-npm-replacement/: (1) source-0.html.gz (vlt.io/blog/1-0) - read in full via text extraction; confirms the platform positioning quote, phased-install (vlt install/vlt build) split, the 60+/~30 selector counts and full selector list including :host(local) and the example query, Catalogs, OIDC trusted publishing (GitHub Actions automatic, GitLab/CircleCI with supplied token), the malware-feed/OSV ingestion quote, the 275k-flagged/25%-still-available figures, and the 38%-faster claim - all verbatim as quoted in the article. (2) source-1.html.gz (InfoQ) - read in full; confirms the drop-in-replacement framing, the install/build split, the selector count and Socket integration, the 275k/quarter-installable figures, and the 38%-faster claim, but two quotes attributed to InfoQ are NOT verbatim (see concerns). (3) source-2.html.gz (Hacker News thread) - read in full; confirms 55 points / 20 comments, and confirms the founder-attributed quote ('vlt helps engineering teams build JavaScript software faster, reduce supply chain risk, and lower infrastructure costs (via. API perf / payload optimizations)') is a verbatim comment by user clarke78, who later self-identifies in the same thread with 'Founder here - thanks for the vote of confidence!' — supporting the article's 'commenter identifying as the company's founder' framing. (4) source-3.html.gz (GitHub repo) - read in full; confirms BSD-2-Clause-Patent license designation. (5) source-4.html.gz (raw LICENSE file) - read in full; confirms 'Copyright (c) vlt technology, Inc.' verbatim. Two of five sources (vlt.io, news.ycombinator.com) are not on config/source_allowlist.txt; both were manually verified as legitimate primary sources (the company's own product announcement and the linked public discussion thread) and every claim attributed to them checks out against the snapshot text.
Factual Accuracy: Every specific number, quote, and attribution in the 'What We Know' section traces to a cited, personally-read source snapshot, with two exceptions: two quotes attributed to InfoQ paraphrase rather than reproduce InfoQ's exact wording (see concerns). The substance of both claims is accurate; only the exact wording inside the quote marks differs from the source.
Overall Assessment: Substantively solid, well-sourced launch story with no fabricated facts and no issues in the headline, summary, or lead. Two subordinate quotes attributed to InfoQ paraphrase rather than reproduce the source verbatim, and two sources sit outside the curated allowlist despite being verified legitimate primary sources. Both issues are minor, recoverable, and can be honestly disclosed in a single corrections record without gutting the article's substance — APPROVE_WITH_CORRECTIONS.