NPM Is Joining GitHub
github.blog
github.blog
Microsoft doesn’t do everything right but the GitHub acquisition has honestly gone better than I ever expected. Rather than forcing GitHub to adopt Microsoft centric policies, Microsoft has adopted more GitHub stuff, especially from a product POV. GitHub still runs as a separate company (different logins and health care and hiring systems) with its own policies and point of view.
The reality is npm was in a bad place and in a land of not good options, this strikes me as the best possibility. I’d rather have GitHub control this and be able to give the resources to npm than a company like Oracle or Amazon or even Google or Facebook to own it. In a perfect world, some independent entity could fund npm out of gratitude but at the same time, consider how poorly npm as a company was run for YEARS and the general lack of direction.
So yeah, I’m cautiously optimistic this won’t be fucked up by GitHub — but I understand the concern.
As for those worried about Microsoft embracing, extending, and extinguishing. Lol. Even if that was the goal (and I truly don’t think that’s the ethos at all any more), Microsoft is laughably incompetent at achieving that sort of strategy. Google and Amazon have the EEE under lock right now (Facebook too — let’s be glad Zuck didn’t buy this after we saw what happened to yarn), but Microsoft can’t even put coherent dev strategy outside of .NET on Azure.
That's what we said about the Skype acquisition too.
"It's different this time, it will run independently, for once Microsoft won't interfere and destroy the acquired company".
3 years later (I was there), 50% of Skype original management and developers left. All the major new projects of Skype turn out to be integration with the endless already existing Microsoft products: integration with Link, integration with microsoft ID, integration with Microsoft UI, etc...
5 years later, Skype is dead... but everyone left already.
Good job Microsoft.
Seriously, go use products like Google Hangouts, Slack or Microsoft Teams (Microsofts's surprisingly better clone of Slack) and then tell me that Skype was ruined by integrating with Microsoft's other product base. The closest argument you might be able to make is that Skype could have developed new features or updated its UI and stayed competitive, but that wouldn't give them the competitive edge that it's competitors nearly all had in terms of being backed by major tech companies. Additionally, the major revenue source was Business tier use, which Microsoft dramatically improved by integrating it with their other cloud-based business suite applications.
Microsoft didn't kill Skype, if anything they extended its life expectancy and value in markets that actually paid to use it. It's dead/dying now because better tools have been developed and marketed to replace it. That's just standard product life cycle.
You have to understand that the technology underlying Skype at the time was very brittle and poorly designed.
Google almost bought Skype before Microsoft did and backed out after they got a look at the code.
When Microsoft acquired it Skype was routing its traffic over port 80 for example.
“On 10 May 2011, Microsoft Corporation acquired Skype Communications, S. à r.l for US$8.5 billion”
I think Microsoft has changed significantly in the last decade.
I’m quietly hopeful the npm acquisition will go well for us (although I still hold some serious grudges about Microsoft’s past behaviour).
What happened with yarn? As a very casual user of it, it seems to work well and have pushed npm to innovate a bit when it was stagnating. But I haven’t followed it lately. Were there technical issues or political drama?
.NET Core was a great move and it's all coming together nicely now, and even creating innovations like Blazor.
> Microsoft can’t even put coherent dev strategy outside of .NET on Azure
I missed something, what happened to Yarn?
This seems to be pretty fair about the whole thing: https://shift.infinite.red/yarn-1-vs-yarn-2-vs-npm-a69ccf022...
[0] https://github.com/atom-archive/xray
[1] They never officially announced it, but they almost certainly de-staffed it to the point where it's barely on life support: https://imgur.com/a/jQBHsUk
[2] https://www.reddit.com/r/AMA/comments/8pc8mf/im_nat_friedman...
Update:
What a surprise, the VSCode fanboys are coming in droves to downvote and say nothing more than how Atom was going to die anyways.
Sure, maybe it was, but that's not the point. The point is Microsoft _actively pulled development resources away from Atom after explicitly claiming they wouldn't_.
I get that a lot of people like VSCode better than Atom, but _please_ put things into perspective for a moment and consider if you'd make the same comment if the same thing happened to _your pet project that happened to be #2 in popularity but then got axed after being acquired by the company who owned the #1 after claiming they wouldn't do exactly that_.
Whatever your opinion might be on Atom vs VSCode, can we not at least agree that this kind of behavior is something we should hold acquiring companies accountable for? It might not make any difference to their bottom line at the end of the day, but the least we should do is hold them to the fire in the court of public opinion.
If commit activity graphs are really a meaningful measure, look at VSCode's:
https://github.com/microsoft/vscode/graphs/commit-activity
The number of commits per, uh, date unit (the graph is not super clear on that axis, honestly) across the entire length of VSCode's activity graph rarely drops as low as the highest number of commits per date unit for Atom.
I'd have preferred to see both survive and do well, but that really hasn't been the way the text editor space seems to have worked. Editors that are conceptually awfully similar to one another tend to have one dominant player: TextMate (at least for Macs), then Sublime Text, then Atom, then very quickly Code. Given that Code and Atom are probably the closest of any two in that list, this just isn't that surprising.
Atom still had a healthy number of active contributors (presumably most of them were from GitHub) making improvements to the product on a daily basis to make it a perfectly viable tool for the people who chose to use it (and despite the much smaller developer base they continued to innovate with projects like xray and tree-sitter)... That is until the Microsoft acquisition happened.
Before anyone jumps in with the causation vs correlation argument, I think any reasonable person looking at the evidence would agree that the timing is convenient enough to make it highly unlikely to have been a coincidence, especially considering that most of those contributions were from employees at GitHub who were _getting paid to work on Atom_, so the only reasonable explanation for the contributions to stop abruptly within a month is that they _stopped getting paid to work on Atom_.
To add insult to injury they even had the audacity to claim they wouldn't do exactly what they did. That is the crux of my issue with how they handled this acquisition.
I was an user of Atom and later switched to VSCode. It took me few months of weighting all the options before I made the switch. That's how much I love Microsoft -- Very little.
Don't know if they got it fixed, but there was a design flaw in Atom: Bug inside some Atom plugin (`linter-ui-default` is one of it if my memory is correct) can reset the entire Atom into it's default setting, and it happens randomly (See link 1, 2 and 3).
This problem pisses me off so much and so many times. The last time it happened, I accidentally deleted my backup configuration `config.cson` when trying to recover the setting. Yes, it is technically my fault, but no, really, it is not. So, after seeing all my life flashed before my eyes, I decided to stop living ... with Atom, I had enough.
VSCode is generally a better editor when compare to Atom. I mean, VSCode has it own issues, sure. But for me, so far those issues are mild and usually got fixed quickly.
1: https://github.com/atom/atom/issues/14922 2: https://github.com/atom/atom/issues/14909 3: https://discuss.atom.io/t/atom-keeps-losing-settings/61617 (This one was in 2018 while the other two was in 2017)
It's possible that one of the linter providers had that issue, and since Linter providers are only called by the linter package, they wouldn't exhibit the issue on their own. It's not uncommon to have issues that seem like it's the linter's fault since all of the providers do nothing and seem harmless unless invoked by the linter package.
I would've helped to debug this, had somebody pinged me on any of the issues. Oh well :)
Lack of delivery killed Atom, not Microsoft.
I don't think so. When VS Code came out my reaction was "Wow! It's like a 1.0 version of Atom!" I.e. an electron (or similar) based editor that works, whereas atom always seemed like a beta release. I tried to use atom a bit but it came with little out of the box and the plugin ecosystem was a complete mess. I filed an issue asking if obsolete/dead plugins could be somehow removed from the plugin repository, but nothing came of it.
Atom wasn't killed, it died on its own.
What need does Atom fill that VSCode doesn't?
what is EEE?
> "Embrace, extend, and extinguish" (EEE), also known as "embrace, extend, and exterminate",is a phrase that the U.S. Department of Justice found was used internally by Microsoft to describe its strategy for entering product categories involving widely used standards, extending those standards with proprietary capabilities, and then using those differences in order to strongly disadvantage its competitors.
https://en.wikipedia.org/wiki/Embrace,_extend,_and_extinguis...
https://en.wikipedia.org/wiki/Embrace,_extend,_and_extinguis...
The initial capabilities look similar and circle really needs a competitor with how flaky their service has recently been.
If they did choose to EEE, this makes it more likely, not less.
Why does NPM need to be funded as a commercial entity at all? What other open source library has a private company running its package manager? This one still boggles my mind.
- the Java/Kotlin/Scala ecosystem is based around maven central, which is run by Sonatype, Inc.
- Go modules are hosted by Google. Previously, most libraries were hosted on Github
- Rust's crate index is on Github
- The Docker/Moby registry is run by Docker, Inc. (though that might be a stretch for "package manager" :))Note that the crates.io index is just a single git repo that holds JSON metadata about each crate: https://github.com/rust-lang/crates.io-index . The actual code found on crates.io is hosted on S3. The index is an important part of the system, but there's nothing tying it to Github specifically.
Some libraries aren't hosted on Maven Central actually, so it's not uncommon to see instructions for adding extra resolvers to your build config.
The Java ecosystem isn't as dependent on Maven Central as the JavaScript ecosystem is on npmjs.com
Not many non-commercial entities can afford that.
- Microsoft is a leading sponsor of open source?
- In fact, .NET is open source now and runs on Linux?
- Microsoft bought Github, then NPM... and the community is celebrating both of those things??
- The guy from the apprentice is what?
I don't think you could honestly say the community celebrated both of those things.
Ruby Gems, PHP composer, PIP, etc. would all like a word with you....
It probably isn't going to 20x VC money, but it sounds like it would be profitable to run as a business.
I'm not sure that's an improvement in any way whatsoever.
Why I think this: private or volunteer models are unsustainable in the long run owing to funding uncertainties or conflicts of interest between stakeholders. Utilities that support the bulk of our technical infrastructure should be secured by public interests. Governments can keep things free.
Common objections:
- "Governments are inefficient". Depends on the area. The government tends to be inefficient in handling areas with direct consumer benefit, but less so in dealing with consortiums or private entities. Since private entities are the primary mainstream users of packages, I don't think government will be too slow on this front.
- "Governments will be malicious". This I don't doubt, but the solution for that is building better trust mechanisms rather than keeping a practical solution at bay, and for software at least such trust mechanisms are tenable e.g. see the CNCF's Falcon project.
And we're yet to hear of any negative impact of their Github acquisition (afaik - correct me if wrong).
I understand the concern about MS business practices, but I don't think it applies to environment where transactions (as in, importing someone's package or submitting a pull request to it) don't involve any contracts or money.
For some examples: RMS being a douchebag has nothing to do with the usefulness of gdb, nor can that circumstance affect the utility in any imaginable scenario.
Microsoft setting censorship policies (aka ToS) on a website they own and control directly affects the utility of npm/yarn/clients. Their website, their rules.
npm i some-package username/repo#branchName
npm install username/repo#semver:^1.2.3
The big problem is that lots of Node.js modules don't push their tags, so there are issues on lots of repos begging maintainers to push their Git tags so that we don't have to use the npm registry.JavaScript is an interpreted language -- as long as you're only downloading source code from the registry there's really no reason to use a registry instead of the plain old Git repository.
But, you know, we've had decades of companies whose 'business model' is just their exit strategy...
That's generally not a good place to be.
'small business' is only the equilibrium in sectors that can't increase aggregate output by growing or capital investment like say, the restaurant industry.
Regarding "trace a change from a GitHub pull request to the npm package version that fixed it" will there be an API to add a source in case the change was made outside of GitHub? Although I recognize that the vast majority of changes to npm packages happen on GitHub.
But I could have this not right?
It has been confusing for a variety of reasons.
And I think there are mixed reviews with how well it's going overall, especially the RubyTogether part.
We think Git(Lab|Hub) will become the two most popular solutions and we look forward to this competition https://about.gitlab.com/handbook/leadership/biggest-risks/#...
I think the companies that should be nervous are ones that have only one stage or ones that have multiple stages but as a suite of applications instead of a single application https://about.gitlab.com/handbook/product/single-application... There are a lot of these https://about.gitlab.com/devops-tools/
I wish Gitlab would get over this passive-aggressive negging of GitHub.
I would squirm seeing something like that among any two competing companies. But it takes a strange configuration of overcompensating an inferiority complex to use it for the specific case of one company starting out as an explicit clone of another, to then lord any small feature the original company may have followed over them.
This isn't the first time. I've seen it dozens of times, and I don't even specifically care about these two companies.
GitHub is now very much focused on the end to end life cycle now that they have "GitHub One".
And Microsoft doesn't even have to maintain the main runtime, Google does. What a clever strategy!
They lost a decade of battles for the web, but it seems they just found a way to get back in the fight.
Now at the IE 6 times, that meant monopoly, and it was terrible news.
But today, it means more competition between the giants, which is very good for us.
The problem is that it was left to stagnate after Microsoft won.
Someone at MS knows strategic and tactics. When MS and Windows bootstrap themselves into the cloud, they will have some software to land on.
[2] example import in Deno:
import { serve } from "https://deno.land/std@v0.36.0/http/server.ts";
Previous HN about Deno: https://news.ycombinator.com/item?id=22102656Who is backing the project in this point?
I wonder to what extent they've had influence over their own success at all though. Basically they had to hope that JS stayed popular (it did), that Node stayed relevant (it did) and that the entire JS ecosystem would move over to NPM (it did, but I'd say rather despite NPM than because of it) (I mean, otherwise Yarn wouldn't even exist, right?).
So basically their bet was:
- Turn NPM into a startup
- Keep the lights on
I bet I'm missing all kinds of key behind-the-scenes stuff, but still, I don't know many startups that manange to successfully exit by "just" keeping the lights on. In a weird cringey way, it's motivating.
"I have a set of goals that I wrote down back then, and have shared openly with the team.
...
3. Get a big enough exit that I can quit my job and see what comes out of me a second time. 4. Share the rewards equitably with the people who got npm to where it is.
...
On (3), well, I’m still working a jobby job, but I always knew that was a long shot, and “make npm a better package manager” is a job I enjoy. And as for (4), I’m proud of the deals that we’ve been able to negotiate for the team.
It’s not a kajillion billion dollar 10x startup cinderella story, and we’ve taken our hits, but in the end we’ve done right by our community, team, and careers, and I’m extremely proud of what we’ve achieved."
Keeping the lights on long enough makes this kind of exit more likely. Paul Graham has a good article about this: http://www.paulgraham.com/die.html
NPM did better than "just" keeping the lights on, though. They even held Yarn at bay by adopting its best features very quickly.
I would expect that there was at least a mention, considering the reason that most modules in npm are still in ES5 is exactly because of the monopolistic practices that Microsoft followed back in the day which makes Internet Explorer still relevant.
Not negative, not positive comment. Just surprising there was no mention. And I do think Microsoft is doing a great job recently with Open Source in general.
[1] https://blog.npmjs.org/post/612764866888007680/next-phase-mo...
Just like a cancer! Oh wait...
Maybe Microsoft's reputation is exactly the reason why it was left out of this announcement.
Sometimes a brand is so tarnished that the owner tries to hide it from the people who hate it. (For example, Comcast → Xfinity. I expect Monsanto to go the same way and become Bayer.)
The same also goes for Charter → Spectrum.
When the company that commercialized heroin and was complicit in the holocaust is a better brand you really got a PR problem.
Microsoft doesn't want to be Microsoft anymore; it wants to be Oracle and IBM and primarily make money off of business consulting and the cloud.
I think Windows will eventually become a presentation and slowly-phased-out compatibility layer on top of Linux, similar to the way macOS became Unix, but even less different than its underlying OS.
However, it should be noted that I'm not very good at predicting things.
WSL1 was a proprietary reimplementation of the Linux system call ABI as an NT subsystem. WSL2 is actual Linux running in a VM. That seems to be moving in exactly the opposite direction.
A decentralized web or a non-for-profit like Wikipedia is a much better model for these infrastructure projects.
Discoverability and pull requests are two big benefits that GitHub has offered. Could we create decentralized open source solutions to provide those benefits? Are there other benefits that we’d need to provide to have viable alternatives to centralization?
Pagure supports submitting pull requests with Git repos on any server (regardless of whether it's running Pagure or not) with its remote pull requests feature. Issues, docs, and pull request metadata are all stored as git repos using JSON files as data, making it easy and portable to other Pagure instances and easy to convert for any other system.
As far as I know, Pagure is now the only Git forge software packaged in all major Linux distributions (Fedora+EPEL[1], openSUSE[2], Mageia[3], Debian[4], Ubuntu[5], Arch Linux AUR[6]).
It'd be nice to see people interested in this helping to build a future supporting portable, decentralized development.
[1]: https://src.fedoraproject.org/rpms/pagure
[2]: https://build.opensuse.org/package/show/openSUSE:Factory/pag...
[3]: http://madb.mageia.org/package/show/name/pagure/release/caul...
[4]: https://packages.debian.org/sid/pagure
Why would there be a mention of Microsoft? That many modules in npm are ES5 is completely irrelevant for npm's purpose.
And Microsoft changed, how exactly?
And why are you advertising for them?
https://news.microsoft.com/2018/06/04/microsoft-to-acquire-g...
Could you tell me more about that?
This is independent of what Microsoft's doing with .NET Core. I'm excited about the work that they're doing, but this isn't going to stop us from making sure that npm is outstanding.
"Joining" is an interesting term here... but I suppose it won because it sounds more like something friendly humans would do. "NPM Is Breaking Bread and Sharing with Github as Special Friends."
Meanwhile, I almost have my team switched to yarn.
I'd wager most people who use yarn even installed it via the npm CLI.
Didn't GitHub set up their own npm registry recently? Shots have been fired in this regard. Which, now that I type that out, makes me kinda wonder how amicable this purchase was...
It'd be such a shame if something bad were to happen to your lovely repository...
Switching to berry has been a huge PITA over here, but I don't want to give up workspaces
I check yarn about every three months, or when I find a new, infuriating bug with the npm CLI (so, every couple of months on average). I think npm install suffers greatly from not having a formal spec. It has been bugfixed by so many different individuals now that it has reached a truly astounding level of schizophrenia.
If yarn didn't exist, I would have started trying to break down the install problem into many independent concerns that can be reasoned about individually and tried to solicit help in making a full installer out of it. If I'd known I'd still be trying to make yarn workspaces work for us 18 months later I probably would have.
Node modules in general have some bad patterns of delegation that are utterly antagonistic to self-documentation, and both yarn and npm seem to suffer from this as well. I think in the next week or so I'm going to have to set up a small test case that exhibits the yarn bug I'm seeing, or any of the half a dozen interlocking (emphasis on 'lock') npm bugs that now have me painted into a very tiny corner.
I had still been following 1.x
Looking at https://yarnpkg.com/advanced/migration : T-T
We have so many little modules from different teams, or even borderline abandonware, that it would take ages to make these changes, and 'yarn node'?? Just... no. How is that ever gonna work consistently with node_modules/.bin?
At this point my choices are, start contributing to yarn and npm development, or get my ass in gear on learning Elixir and Rust. I have been wondering for maybe 18 months if I might be 'done with Node'. I think I've had it backward this whole time. Node may in fact be done with me.
How separate from MS has GitHub been in day-to-day operations?
This is as good as Google acquiring Youtube because Youtube needs an insane amount bandwidth and it was a perfect fit for Google's infrastructure and ad platform.
It's just sad to see Google not playing the Developers game well.
The existing npm ownership model is markedly less clear and has led to several problems, including the transfer of package publishing rights to bad actors without anyone being aware. On the whole, npm accounts and orgs were always just an unnecessary abstraction that obscured the actual provenance of software, of which GitHub is the de facto source.
The worst option has been Elm's system where the whole package system requires you to not only use GitHub, but when GitHub in down (which isn't uncommon unfortunately) packages that weren't cached locally were inaccessible with no mirroring options.
Hopefully we can integrate repository information to packages meta data such that you could be aware of a change of ownership even for a globally namespaced package.
That said, and just in case their notoriously warlike legal team manages to fumble this somehow, I'd like to take the opportunity to remind every other frontender that Verdaccio (https://verdaccio.org/) exists, is easy to implement, and relatively low maintenance.
TypeScript and VS Code have been an invaluable contribution to the community. I'm a daily user of both and so thankful for the talent, ingenuity and effort that have gone into them.
How Microsoft have managed the acquisition of GitHub, giving them autonomy and infrastructure support - so far, it's been all around positive.
Now with NPM under their wings, the centralization does worry me somewhat. I hope there are conscientious decision-makers who will guide the project for the good of community and ecosystem.
You can blame AWS/GCP for letting GitHub & npm be acquired, how many years were they on the open market?
Most of the $$$ in OSS is being funneled towards rent-seeking major cloud providers that are hosting OSS software, whom should all have blank checks with the money they've reaped so far, but seems only Microsoft has the strategic savvy to focus on acquiring the obvious targets for increasing dev mindshare. I don't fault them for their M&A's, it's just good business.
Smart, have no idea where AWS or GCP's control team are at when these strategic plays are going down.
Stuff like this is what irritates me. Even small vps providers have this.
- They want to sell Azure Services
- Most (if not all) NPM packages already live on github
- NPM has a business revolving around package management, including private npm instances and increasingly around node/package security
- This being primarily a business that will sell to has-money businesses (e.g., medium to large businesses, Fortune 500 corporations etc)
So, given all of the above, it makes sense to have a vertical selling into one of the fastest growing package management ecosystems where you can be the "full stack" provider of developer/enterprise tools.
I don't think its anything beyond this, personally. I expect to see a lot of pushes to integrate with Azure Pipelines, cloud deployment etc. centered around this.
I wonder if they'll buy Passenger[0] next, its a popular (in my experience) to deploy nodejs applications.
Critical open source entities are bought by private company. I understand the need for money and sustainability these entities need, but it's really a shame that the open source community doesn't "own" themselves.
Most people don’t know, in these open source acquisitions by for profits there’s money involved and “founders” get an exit. Not always clear To the public who those are or what they took home from a mostly volunteer effort.
> GitHub, the developer repository owned by Microsoft, made a little deal of its own this morning when it bought JavaScript packaging vendor npm for an undisclosed amount.
https://techcrunch.com/2020/03/16/github-nabs-javascript-pac...
Future "5-10 years down the road" me knows this will suck, ending up where all concentrated monopolies end up...
If developers love Github, they love the cloud. Microsoft is betting big on the cloud, they lost the Mobile war but they definitely want to be the developer and cloud darlings.
https://news.ycombinator.com/item?id=21031266
I also predicted a few more controversial things but if you think it terms of ecosystem and cloud market strategy, then it makes perfect sense.
What I'd not hope : MS changes strategy with change of people etc and npm and GitHub rot.
This is already happening with Windows and SQL server licensing. This will happen sooner or later.
https://en.m.wikipedia.org/wiki/Deno_(software)
Built by the node team to replace node.
However even a non-.NET web-developer now could be using quite a bit of Microsoft owned tech; VSCode GitHub npm Azure
I don't fully understand the way it's governed from this article.
It'd be wonderful, as a package consumer, to have visibility into some security metrics for a given package. This would be useful both at initial install time, and when the package is upgraded. Something like:
1) who are the latest commits GPG signed by?
2) is the package publisher using 2FA?
3) what is the security profile of all dependent packages?
4) are there any new authors (directly or via dependencies) since the last version (with links to the author and their contributions).
These might help avoid prior situations where popular packages get injected with malware by new maintainers.
Sometimes I wonder what the business world (and the internet) would be like if mergers and acquisitions weren't allowed. Like, if businesses had to be sustainable or they'd just die, rather than capturing a whole market while eating VC money, maybe we'd all be better off? All of the really embarrassing stuff coming out of SV would just go away? Just Pinboards and Sourcehuts and Mastodons ruling the web?
I'm capitalistically illiterate, so somebody please tell me why this thought is stupid.
If we did that, it would be a crazy waste of resources. The alternative is to let another company buy the stuff... and if a company buys the failed company's tech, equipment, and hires their staff... that is basically the same as buying the company.
Why is there a for-profit corporation behind every open source project these days?
https://news.ycombinator.com/item?id=19838122
Somebody replied "Microsoft won't acquire npm for sure."
The product Github is probably most interested in is NPM as a repository for packages, not its CLI.
I'll be switching from Github to other providers for my own projects, and use a different editor soon (using vscode now).
Their strategy from my perspective is to ensure Linux does not become a competitor for their desktop OS.
1: it never had Linux support.