Why does NPM need to be funded as a commercial entity at all? What other open source library has a private company running its package manager? This one still boggles my mind.
- the Java/Kotlin/Scala ecosystem is based around maven central, which is run by Sonatype, Inc.
- Go modules are hosted by Google. Previously, most libraries were hosted on Github
- Rust's crate index is on Github
- The Docker/Moby registry is run by Docker, Inc. (though that might be a stretch for "package manager" :))Note that the crates.io index is just a single git repo that holds JSON metadata about each crate: https://github.com/rust-lang/crates.io-index . The actual code found on crates.io is hosted on S3. The index is an important part of the system, but there's nothing tying it to Github specifically.
Some libraries aren't hosted on Maven Central actually, so it's not uncommon to see instructions for adding extra resolvers to your build config.
The Java ecosystem isn't as dependent on Maven Central as the JavaScript ecosystem is on npmjs.com
If MC goes away as it exists today, the Java Ecosystem will take a huge hit as almost every open source project would stop building in CICD environments from the get-go.
Not sure how APT works in the linux community can really work for anyone else, but definitely worth a shot for sure.
Not many non-commercial entities can afford that.
- Microsoft is a leading sponsor of open source?
- In fact, .NET is open source now and runs on Linux?
- Microsoft bought Github, then NPM... and the community is celebrating both of those things??
- The guy from the apprentice is what?
I don't think you could honestly say the community celebrated both of those things.
Ruby Gems, PHP composer, PIP, etc. would all like a word with you....
The fact that there's a bunch of critical infra run on a precarious volunteer shoestring is not a good thing.
I don’t know, so I have to ask, what’s the metric here?
As at Oct. 2018, the top 12 npm packages [1] were already doing more than 0.5 billion downloads a month. Granted, popularity has waned for a few of those top packages due to deprecation or new language features, for instance.
EDIT:
NPM’s announcement about the acquisition [2] provides up-to-date numbers:
“Today, npm serves over 1.3 million packages to roughly 12 million developers, who download these things 75 billion times a month ...”
1: https://news.ycombinator.com/item?id=18343604
2: http://blog.npmjs.org/post/612764866888007680/next-phase-mon...
The acquisition can be a good outcome for the current situation without it being the ideal state of things.
Would yo prefer npm infrastructure to be maintained and developed by the lowest-paid programmers they could hire?
Linux repos take the alternative approach to try to get as many mirrors as possible so it can remain free.
Microsoft did not buy npm to help it become free. Believe. They bought it because they rekon they can make buck out of it.
That buck comes from somewhere.
Nodejs going to the Linux foundation was good news.
Microsoft buying Npm is bad news.
It probably isn't going to 20x VC money, but it sounds like it would be profitable to run as a business.
"2fa" sounds bad. That is clearly marketing bs for linking your npm account to a MS account with more personal info attached.
Ease of publishing will be the first thing to go.
Then the fun will disappear with MS as owner, like when Oracle bought Java.
Happy to be a rustacean.
And they will ask you, under the guise of 2fa, to confirm thier suspicions.
And $7 a month gets plently of new upgrade options offered.
All talk of mirrors gets brushed under the carpet.
Microsoft pwn all nodejs code except core and those savvy enough to spot this coming and distribute via debian repos.
I'm not sure that's an improvement in any way whatsoever.
MS? Not even a chance. What percent do you think of their business is actually government, beyond buying licenses just like nearly every other corporation on the planet.
what does that mean? That Microsoft works for the NSA or something?
Why I think this: private or volunteer models are unsustainable in the long run owing to funding uncertainties or conflicts of interest between stakeholders. Utilities that support the bulk of our technical infrastructure should be secured by public interests. Governments can keep things free.
Common objections:
- "Governments are inefficient". Depends on the area. The government tends to be inefficient in handling areas with direct consumer benefit, but less so in dealing with consortiums or private entities. Since private entities are the primary mainstream users of packages, I don't think government will be too slow on this front.
- "Governments will be malicious". This I don't doubt, but the solution for that is building better trust mechanisms rather than keeping a practical solution at bay, and for software at least such trust mechanisms are tenable e.g. see the CNCF's Falcon project.
That would work for Npm. Npm has enough problems that its worth running your own mirror for business continuity.
Microsoft are likely to make breaking changes immediatly.
And risk-averse businesses do already.
And we're yet to hear of any negative impact of their Github acquisition (afaik - correct me if wrong).
Those are great until they're not. It's why it's called "bait and switch".
> And we're yet to hear of any negative impact of their Github acquisition (afaik - correct me if wrong).
ANY?! Heh, do a quick search just on HN and you'll find it pretty quickly.
https://news.ycombinator.com/item?id=17221640
https://news.ycombinator.com/item?id=17221656
> I'm legitimately curious as my use of GitHub hasn't led me to notice any change
Nor I. That's not that point.
For the record, I think Microsoft has done wonderfully for the dev community in the last 10 years. I don't see any reason that they are going to "f it up", but big businesses get desperate when environments change and profits get impacted (look no further than what Oracle is doing). Microsoft is not immune to that.
Next you'll call them Micro$oft. Come on now.
If it does micro$oft will just buy the world out from under them.
These are well-documented facts that have been widely reported on in the mass media. You can find links to specific articles on my blog in the recent article about Microsoft and GitHub, if you wish to learn specifics.
The kids are in there right now, as I write to you.
Whether or not Microsoft's provisioning of services to the government is "legal" or not is not particularly relevant to the thread, but it is interesting that you bring it up, presumably as a defense of their behavior.
Again: This is not a partisan thing. At all. Your attempt to reduce it to such is inaccurate (and, tbqf, off-topic for the thread about Microsoft-the-corporation, as well as off-topic for HN).
I'm a naturalized immigrant. I've been in far worse places than America. I suggest you visit CBP and ICE. Talk to the agents. Visit the border. See the shelters. View the damage done by criminals who prey on these people and find out how much the agents do to help them while risking their lives fighting cartels and traffickers.
Like I said, America is far softer with borders than other nations. Crossing illegally brings enforcement and penalties. I'm not sure why this is so controversial, or why protest against govt organizations is done by proxy of software companies.
What you are talking about is Right-wing politics, even if they are extremely far to the left of your -and the majority of peoples political view -in the USA. Both parties in the US are on the right. This isn't Reddit where the state of US politics is the default norm when it differs from most of planet earth. Though HN is quickly getting there.
ICE are the goons operating everywhere (i. e. not tied to the border) rounding up "suspected illegal immigrants".
Because it isn't exactly hard to find illegal immigrants, and their charter allows them to control people without objective cause, ICE gets to arbitrarily decide whom to harass.
It's the real-life version of the perennial fear of civil libertarians that too many criminal laws will just lead to any one of us being arrested whenever it happens to be convenient for whoever is currently in power.
It isn't going to end illegal immigration, nor curtail it to any significant degree. It just serves to keep a large segment of the people who see every day in a constant state of fear, unable to (for example) seek protection from crime or exploitation for fear of being deported.
As for the rest of your comment, this is the far-left extremist position that I cited in my first post. There's no good faith discussion to be had here.
No, it's the enforcement arm for immigration and customs, the former of which is people who are living in the US despite not being US citizens. Enforcement of people (and goods) crossing the border is the Border Patrol and it's parent organization Customs and Border Protection.
There's not much controversy over the people who cross illegally but stay temporarily and close to the border. Those are just traffickers and cartels.
https://www.aclu.org/issues/immigrants-rights/ice-and-border...
Also detainment centers are not cages but fenced areas with free movement inside where people receive food, shelter, healthcare, entertainment, schooling and legal services paid for by US taxpayers while their cases are processed. Detainees are free to deport themselves at any time. This is more accommodating than pretty much every other developed nation.
The fact that it is open source and popular is not sufficient on its own. It had to be forked (vscodium) to show basic respect for the user’s privacy and system resources.
This is such an extreme & pretentious viewpoint. Microsoft knowing that I have VS Code installed & getting a report when it crashes is not in mine, or really any normal developer's threat landscape.
> This is not a fork. This is a repository of scripts to automatically build Microsoft's `vscode` repository into freely-licensed binaries with a community-driven default configuration.
So it "furthers my intended point".
It’s builds released by Microsoft that have all of their specific stuff added in.
Assume the best all you like. Microsoft are spying on you and can lock you out of their ecosystem for any reason. When that ecosystem includes critical public infrastructure, there is a problem.
The only "sane" response to this is to smile at the MS employees who tell you how much they love Open Source and to use absolutely any other platform.
I understand the concern about MS business practices, but I don't think it applies to environment where transactions (as in, importing someone's package or submitting a pull request to it) don't involve any contracts or money.
For some examples: RMS being a douchebag has nothing to do with the usefulness of gdb, nor can that circumstance affect the utility in any imaginable scenario.
Microsoft setting censorship policies (aka ToS) on a website they own and control directly affects the utility of npm/yarn/clients. Their website, their rules.
https://sneak.berlin/20200307/the-case-against-microsoft-and...
VS Code has had to fork to remove the unethical spyware portions within it placed there by Microsoft:
I realize this is just pure anecdata and not a legitimately researched observation, but I don't know a single dev in real life who either switched away from Github or VSCode due to those concerns, despite having a wide variety of dev friends from all kinds of backgrounds, including big tech devs, non-tech company devs, fully remote devs, self-taught devs, small startup devs, outside of the US devs, freelancer devs, etc.
"When we [Microsoft] build Visual Studio Code, we do exactly this. We clone the vscode repository, we lay down a customized product.json that has Microsoft specific functionality (telemetry, gallery, logo, etc.), and then produce a build that we release under our license."
"When you clone and build from the vscode repo, none of these endpoints are configured in the default product.json. Therefore, you generate a "clean" build, without the Microsoft customizations, which is by default licensed under the MIT license"
When a certain build configuration enables major spyware features, and that is the build configuration for the released version by the first party, and another build configuration (that is not released by the first party) disables those major spyware features, the distinction between a fork/patch and a "different build configuration" becomes semantically meaningless.
It's a fork, regardless of how they care to present it. The result of the build configuration is embedded in the release. Consider it a "binary fork" if you don't like considering json "source code".
Microsoft and their allies make the world a lot worse for a lot of people. They’re the number one distributor of spyware in the world!
npm i some-package username/repo#branchName
npm install username/repo#semver:^1.2.3
The big problem is that lots of Node.js modules don't push their tags, so there are issues on lots of repos begging maintainers to push their Git tags so that we don't have to use the npm registry.JavaScript is an interpreted language -- as long as you're only downloading source code from the registry there's really no reason to use a registry instead of the plain old Git repository.
With NPM acquired by GitHub, I can imagine them "filling in some steps" by leveraging the fairly new Actions feature, so that repos can provide built artifacts, the same ones as published on NPM. The deeper integration will be an interesting development to watch.
But, you know, we've had decades of companies whose 'business model' is just their exit strategy...
That's generally not a good place to be.
'small business' is only the equilibrium in sectors that can't increase aggregate output by growing or capital investment like say, the restaurant industry.