It was because Astral was VC funded.
https://astral.sh/blog/announcing-astral-the-company-behind-...
Having a private package index gives you a central place where all employees can install from, without having to screen what each person is installing. Also, if I remember right, there are some large AI and ML focused packages that benefit from an index that's tuned to your specific hardware and workflows.
Plus the obvious need for a place to host proprietary internal libraries.
Every company needs its own package repository. You need to be able to control what is running on your environment. Supply-chain risk is very, very real and affects anybody selling software for a living.
This is besides the point that in the real world, not every risk is addressed, at least in part because available resources are diverted to address larger risks.
Most of the companies that spend $$$$ with them can't use public registries for production/production-adjacent workloads due to regulations and, secondarily a desire to mitigate supply chain risk.
Artifactory is a drop-in replacement for every kind of repository they'll need to work with, and it has a nice UI. They also support "pass-through" repositories that mirror the public repositories with the customization options these customers like to have. It also has image/artifact scanning, which cybersecurity teams love to use in their remediation reporting.
It's also relatively easy to spin up and scale. I don't work there, but I had to use Artifactory for a demo I built, and getting it up and running took very little time, even without AI assistance.
Like, nobody really pays for web servers - there are too many good free options. They're far more complex than Artifactory.
I guess it's just that it's a product that only really appeals to private companies?
There are no competing open-source projects because such projects would need to provide more value than Artifactory/Sonatype OSS, which are both already huge projects, just to be considered.
There are also several free registries out there: Quay, Harbor, and Docker's own distribution. They all have paid versions, of course.
Perhaps OpenAI is aiming for a more compelling suit of things for penetrating enterprise (I'm just speculating as I go here).
There seems to be a pervasive believe that the Python tooling and interpreter suck and are slow because the maintainers don’t care, or aren’t capable.
The actual problem is that there isn’t enough money to develop all of these systems properly.
Google says that Astral had 15 team members. Or course, it’s so hard to make these projections. But it wouldn’t shock me if uv and ruff are each individually multi-million dollar pieces of software.
If you’d like to invest a million dollars to improve pip, or work for free for 3 years to do it yourself, I’m not sure if anyone would object.
That bootstrapping process just installs the wheel's contents, no Internet connection required. (Pip does, of course, download pip for you when you run its self-upgrade — since the standard library wheel will usually be out of date).
Also, the survivors are the exception, not the rule.
Either pay for the product, or use stuff that isn't dependent on VC money, this is always how it ends.
Maybe you use non-transitive pure Python dependencies, but it's likely that your tools and dependencies still rely on stuff in Rust or C (e.g.: py-cryptography and Python itself respectively).
As mentioned multiple times, since my experience with Tcl and continuously rewriting stuff in C, I tend to avoid languages that don't come with JIT, or AOT, in the reference tooling.
I tend to work with Java, .NET, node, C++, for application code.
Naturally AI now changes that, still I tend to focus on approaches that are more classical Python with pip, venv, stuff written in C or C++ that is around for years.
At worst, it's just Anaconda II AI Boogaloo. The ecosystems will evolve and overcome, or will die and different ecosystems rise to meet the need going forward.
I anticipate OpenAI will get bored and ignore Astral's tools. Software entropy will do its thing and we will remember an actively developed uv as the good old days until something similar to cargo gets adopted as part of Python's standard distribution.
Consider ffmpeg. You can donate via https://www.ffmpeg.org/spi.html
How much money do they make from donations? I don't know but "In practice we frequently payed for travel and hardware."
Translation: nothing at all.
If such a fundamental project that is a revenue driver for so many companies, including midas-level rich companies like Google, can't even pay decent salaries for core devs from donations, then open source model doesn't work in terms of funding the work even at the smallest possible levels of "pay a reasonable market rate for devs".
You either get people who just work for free or businesses built around free work by providing something in addition to free software (which is hard to pull off, as we've seen with Bun and Astral and Deno and Node).
There are examples of foundations or other similar entities paying developers, like Linux, SQLite, even Zig.
Maybe the difference is some projects rely on core contributors more because external contributions are more restricted in some way.
But sure, the entire open source model doesn't work, lol
I get the point you're making, but the way you introduced it isn't conducive to productive conversation.
The entire context of this subthread is whether or not the model that Astral was using was reasonable or not compared to an open source approach. From your initial comment, you've been touting alternatives, and the comment I responded to was giving specific examples of where you think the model worked. I don't think you've provided much evidence that there was a good alternative here, and when you're taking an opinionated stance, a productive conversation will sometimes involve people pointing out flaws they perceive in your arguments.