Honestly it's great that npm 5 seemingly caught up with the speed of yarn but that only addresses one of many reasons I'm happy to have made the switch. Npm has been broken in exciting ways for years (and often in the same way for years -- see the infamous race condition in their tar implementation that broke npm publish at random).
I mean, I consider myself a relatively novice programmer, so perhaps I'm underestimating the challenge involved, but I'm absolutely baffled that we ended up with 'the standard Node package manager' not being able to produce consistent results when setting things up in different environments. I mean, I've used Gemfile.lock for what feels like ages.
There was no CLI argument parser, so Isaac wrote his own. There was no cross-platform tar bundler, so Isaac wrote his own. Not to mention that there just weren't any best practices in Node or JS for any of what NPM was trying to do yet.
Yarn has the classic second mover advantage. The yarn devs learned from NPM's mistakes (there were more people involved than you see in the commit logs -- they even talked to some NPM people during development) and built on the vast ecosystem that exists now.
I don't like npm Inc and I think there's a serious conflict of interest in having NPM bundled in the Node Foundation's official releases (people using the NPM client is in npm Inc's best interests, whereas Yarn isn't controlled by a single commercial entity). But blaming NPM's problems entirely on developer incompetence is unfair.
That was the last straw for me and NPM is now banned in favor of yarn.
It's an odd project with a lot of super strange peer dependencies, many of them in beta or as pre-releases, so I'm sure it's nothing that happens all the time (the joys of using React Native and Relay where everything is at an imaginary release state). But still glad npm 5 made it work consistently.
In exchange, you get a new cache directory layout with directories named after autogenerated hashes, and "npm cache list" isn't supported yet :(
But I'm not complaining; npm has certainly made progress, though it's still relatively slow.
I gave an example of using Yarn's offline mirror option in one of my "Practical Redux" tutorial blog posts: http://blog.isquaredsoftware.com/2017/07/practical-redux-par... .
This has been broken for almost 2 years now.
https://github.com/npm/npm/issues/10343
It's unacceptable that the NPM team is moving so fast without looking back considering so many projects depend on it.
One of the bugs currently open references NPM deleting your dependencies.
Another bug had NPM delete itself just by running `NPM install`.
I didn't notice anything, but I'm using yarn everywhere, so...
Yarn takes 12 seconds to install all of our node_modules, npm@5 (latest) takes over 12 minutes.
This made it completely and utterly untenable for our CI system, so we switched to yarn and shaved 12 minutes off our CI builds. It's been fantastic.
Old results from about a month ago:
https://twitter.com/bertjwregeer/status/887450964420055043
npm 5.3.0: added 1991 packages in 538.289s
yarn v0.27.5: Done in 58.42s.its strange that the lockfile was supposed to fix problems with un-repeatable installs, but I had several issues fixed by simply deleting the lock file and re-installing.
rm -rf node_modules && rm package-lock.json && npm installMy concern with the lock file is that it doesn't seem to be consistent across platforms (OSX and Windows) because of optional dependencies. I have a project with those (freaking fsevents) and every time I do npm install I it changes the lock file back and forth.