Crate.io: A new kind of Python package index
crate.io
crate.io
As it is now the front page of PyPi https://pypi.python.org/pypi gives us more information than the front page of Crate.
I like that it's quick, PyPi is a bit slow for me at the moment.
I also like the info page for a specific package (https://crate.io/packages/docopt/#description), it's nice and informative, quite easy to read but I do not like that you have to click the info tab to see the classifiers (which python versions it works with, among other things).
What is the key arguments and features that should make us want to use Crate.io over PyPi?
I mostly interface with PyPi via pip on the commandline.
Is crate supposed to be a drop-in replacement? Can we just make pip work against a different base url? Will you launch your own pip replacement?
How is Crate.io better than the current PyPi? The website does not mention any of this, it barely contains any text.
</ramble>, I've just wrote up a few of the questions I had while checking it out, sorry if it's a bit incoherent :-)
It can be used as a drop in replacement against PyPI using the --index-url option of pip. (pip install --index-url=https://simple.crate.io/)
It has a number of security and speed improvements over PyPI some of which I've contributed back to or pushed for PyPI to get overtime.
But it has a huge ass search field! It's all about the UX, brother; the bigger (and flatter!) the UI, the better the UX, as any UX expert will tell you.
Compare that to PyPi which does exactly what I described, and even during off peak periods, searches can sometimes take up to 20 seconds
The real answer is I have. I'm a PyPI administrator now and have been enacting a lot of these benefits on PyPI itself. Just this weekend I've deployed a CDN in front of all of PyPI so that package downloads have sped up by 1-3 orders of magnitude depending on location.
Previously I had pushed hard for getting a real valid and trusted SSL certificate on PyPI, moving the user provided html/js from packages.python.org to pythonhosted.org in order to prevent CSRF fixation attacks.
Like I said Crate is an experiment. One that has enabled me to push for good changes in PyPI.
CPAN: Comprehensive Perl Archive Network
Rubygems: (self-explanatory)
PyPI: Python Package Index
Crate.io: Crate? Crate.io?
Nothing about the name or any part of the domain really mentions Python, or Python packages or libraries. It's not a bad name, but it doesn't really seem like a name for a large Python package index. What's the exact rationale behind the naming?
Why?
I miss one thing: PGP signature files. I've been checking one of my packages and PyPI is showing the .asc file but crate only shows the sha256 hash.
although i will say i usually just google for a python package and come across a stackexchange that points me to some package, rather than using some index. if you can become some authoritative reference, more power to you.
Happens at
https://crate.io/social-auth/complete/github/?code=123Pypi.python.org/simple is the heart of everything - do we even use a package repository to browse for packages these days - or do we rely on the blue googles?