Hippy: React Native Alternative by Tencent
github.com
github.com
EDIT: I've read through more of the source and compared it to React Native. Like Jarred mentioned[2] it probably started out as a fork of React Native.
0: https://github.com/Tencent/Hippy/blob/master/ios/sdk/base/Hi...
1: https://github.com/facebook/react-native/blob/master/React/B...
I can't see a reason not to mention this unless you're trying to fool someone.
> Hippy-Vue and Hippy-Vue-Router is using the part of codes write by Evan You with MIT license.<MIT license>
My best guess is that Evan is this person [1][2]. So that still doesn't seem to fit the proper MIT license agreements if you're right, and it looks like you are.
[0] https://github.com/Tencent/Hippy/blob/master/LICENSE
How do you work with different platforms? How does the performance compare to React Native? Can we see examples? What APIs exist to access native functionalities? How complete is the Flex implementation?
Code-wise, the most interesting things I've seen:
- They expose wrappers for native recycling list views[0]. React Native does this in JavaScript through VirtualizedList, however some have experienced performance issues with it[1]
- They wrote their own flexbox layout library[2] (likely based on Yoga)
- It works with both Vue[3] and React
- Hippy supports web as a build target out of the box[4] (react-native-web is a 3rd party library)
- Touch events work on the `<View />` component directly, instead of needing to wrap `<View />`'s in the `<Touchable />` components[5]
- It uses a closed-source fork of libv8 on Android called X5[6].
The API & coding style is quite similar to React Native, but the implementation seems different. I'm guessing this started as an internal fork of React Native and turned into a large refactor, but that's just a guess
[0]: https://github.com/Tencent/Hippy/blob/master/ios/sdk/compone...
[1]: https://github.com/facebook/react-native/issues/13413
[2]: https://github.com/Tencent/Hippy/tree/master/layout
[3]: https://github.com/Tencent/Hippy/tree/master/packages/hippy-...
[4]: https://github.com/Tencent/Hippy/tree/master/packages/hippy-...
[5]: https://github.com/Tencent/Hippy/tree/master/packages/hippy-...
[6]: https://github.com/Tencent/Hippy/issues/9#issuecomment-56822...
this makes my spidey senses tingle. What might be hidden there?
I would be very curious to know why and if there are plans to replace with open source.
Having used a lot of these apps I wonder if this is indeed what they use to deliver near native experience with web technologies..
In a time of geopolitical "tech wars" open source culture could easily become collateral damage.
Certain tools come with telemetry that is used to track the users. On top of this, by making open source these corporations are seen as good for the community by naive engineers.
You can find here on HN articles that talk about how Google is using Chrome to bend the web to its will, how Visual Studio Code tracks its users and how Facebook uses its Android SDK to track smartphones. JetBrains declared they made Kotlin with the intent of gaining an edge on competition for Java IDEs (no spying intent declared or reported, but I want to highlight that even for a $300 million company technological domain is proving effective).
Tencent is merely doing what other corporations have been doing for decades.
As I understand it Tencent has worked closely with the Chinese government to enable its social media properties like WeChat to feed data into Sesame Credit on a massive scale. This is a project that they support and enable, and I believe in the early days they were also one of the companies that helped to develop it, regardless of who currently operates it on paper.
- It uses a closed-source fork of libv8 on Android called X5[6].
We already know that tencent engages in bad stuff on behalf of the Chinese government (Sesame Credit as a concrete example) so they shouldn’t be presumed innocent right out of the box.
What’s wrong with existing cross platform frameworks? You have to wonder what their agenda is for creating this.
Sesame Credit is not a Tencent project. If you're going to get facts wrong, at least don't repeat them more than once. https://news.ycombinator.com/item?id=21879422
> You have to wonder what their agenda is for creating this.
Career advancement for everyone on the list of contributors.
In the meantime I’m pretty sure they fully cooperate with the Chinese government in supplying data to the Sesame Credit system through their social media properties like WeChat. Something that more ethical competitors like WhatsApp have refused to do.
- It uses a closed-source fork of libv8 on Android called X5[6].
Of course every package used in any code that contains sensitive data should be audited along with its dependant, but I see no reason to be more afraid of this particular package than anything people happily install from npm.
They have international agreements with a number of countries for surveillance.
This means that unless an app is completely hosted, in all parts from source code to production, in a privacy-friendly country, on servers provided by a privacy-friendly company and the app is made by a company in similar conditions, the US and EU have all they need.
Chinese companies absolutely do not have this track record. Chinese companies are essentially an extension of the heavy hand of the Chinese Communist Party.
I just hope the various cryptominers that get shoehorned in to umpteenth child dependencies fight against each other...
If everything was like the NPM meme where you install a package to check if something is true, then your LOC for that module with be quite limited.
However a single dependency is often big itself, and the 50 dependencies it has are also quite big. The LOC in the dep-dep is not the same as if it was written by hand in the dep.
So if you wrote your dep by hand you may use, say, 500,000 LOC - but with the tree of dependencies not being a 1:1 to what you use, you have to audit more like 2Mil LOC. Perhaps an audit could be aided by some sort of tree-shaking scenario, where all non-used code is removed, leaving you with the real 500,000 LOC that needs review.. Would be interesting.
I've been having this same problem with Rust lately. Frankly, I think it's true for any package platform you use.
Right, people act like node_modules is extremely special. They open the folder and say "Look at all of the files, what a mess!" as if other languages don't have this. Just in most other languages it's more hidden from you.
Since the project hasn't acknowledged the forking, they already have given good reason to be suspicious.
Huh? I'm replying to someone inquiring why someone else didn't review a fork. Aka, the GP was focused on the Fork aspect of Hippy, and the Parent asked about React, as if React was a fork.
I think you misunderstood the comment chain. I was not even talking about security issues or how that affects forking. I was merely replying to another discussion about forking, and how React is viewed in that "forking light".
Vagueness and confusion all around, haha.
Also, your comment breaks the site guideline against insinuating astroturfing, shillage, etc., without evidence. I replied to you about that here: https://news.ycombinator.com/item?id=21879877. Please don't do it again.