Npm Raises $2.6M Seed Round
blog.npmjs.org
blog.npmjs.org
Back in July he must've seen this coming because he switched the npm license from MIT to the more restrictive Artistic 2.0: https://github.com/npm/npm/commit/c32391b1efd70a861cebc77e0c...
He's already taken away the download numbers on npmjs.org, so maybe he intends to sell the "analytics" back to the community.
The guy calls himself a Supreme Emporer on his LinkedIn.
As of five days ago ( http://blog.npmjs.org/post/75707294465/new-npm-registry-arch... ) we are hosting the registry ourselves; it was previously hosted by Nodejitsu (who still operate a downstream mirror).
As for the download counts, per Twitter ( https://twitter.com/npmjs/status/422823647619710976 ), we removed the download counts because our original solution for those counts (keeping them in CouchDB) wasn't scaling. I am literally, as we speak, working on the replacement system to restore download counts.
And Isaac's LinkedIn title is a joke. I hope that's obvious.
i understand someone has to pay for the servers and development time, but would it be possible to give a hint for the types of things you plan to charge for? Even just a rough sketch of "we will offer private repositories" or "we will offer support." I appreciate the "reassurances" that nothing will change today for me, but the ambiguity prevents my latent paranoia from going away.
You can still use the nodejitsu registry for free if you'd like[1]. They arent likely to need as much scaling anymore, but there's still a big cost to running those servers. I don't think there was any foul play when it comes to the scalenpm money as I'm fairly sure they were not aware of the intent for Npm, Inc to take over default hosting.
tl;dr the money did not go to the same people, and the people who crowd funded thought they'd still be hosting npm going forward at the time.
[1] http://blog.nodejitsu.com/simple-hosted-private-npm-and-regi...
The cynicism in this thread is so bizarre to me. No one is being evil. There's no secret foul play. Everyone go write modules and share them and be happy.
Say what?
The Nodejitsu replica is a downstream replica, not a failover. Very different. 100% of `registry.npmjs.org` traffic goes to npm, Inc infrastructure.
> The cynicism in this thread is so bizarre to me.
Welcome to Hacker News. I see it's your first time here. :)
> Everyone go write modules and share them and be happy
Couldn't agree more.
I did tell Charlie in November about my intent to take over the registry in Q1 of 2014, if it proved economically feasible. The raise helped accomplish that, for sure, but so did a massive restructuring that means it requires much less resources.
All that said, I love them both dearly.
We don't know what they were valued at.
>Many companies have been literally begging for me to figure out a way to take their money and add some features to npm. None of this impacts what any of you are currently doing, and in fact, it helps you, because it requires building additional high-availability systems that are robust enough for the next 10x increase we face.
>Like I said, all that is currently free will remain free, and all that is currently flaky will improve. There'll be some new stuff you can pay for if you want to use it, but if you're happy with the current status quo, you can just take it easy and maybe eventually get a job where you use npm for work stuff also :) - Isaac Schlueter
You can run Nagios/RHEL for free, but support/custom built/easy drop and go is where you get into serious money.
- paid private repositories on npm or a parallel system (think github)
- paid internal npm servers with support (think github enterprise)
- statistics that used to be available, like download counts (think imgur pro)
Right now npm is at the core of every project using node.js, and businesses have more complex needs than open source projects. One such need would be having a private registry. You don't want to have your production build chain depending on packages that could be replaced by the author at any point in time. The current wisdom if you want protection from that is to run your own npm server, but why do that when you can just have the guys that do this exclusively do it for you?
This makes sense because there are business needs that don't overlap much with the open source world that they can sell, the same way GitHub does. GitHub was successful because they got the programming world using them for their open source projects, and after dominating over that market, those programmers took the service and recommended it to their employers, because that was the tool everyone was using.
Npm falls in the same business area, where the programming community is already using them, and businesses have other needs from them, that they currently cannot provide.
It would be nice for npm to put up a monetization blog post to clear up the confusion.
I would say that this marks the beginning of the end for npm as anything viable for front-end code repositories and probably for anything related to node.
I propose an open-source alternative for front-end JavaScript libraries and dependency management.
Anyone calling for npm modules and browserify to rule the day for front-end JS should question their opinions on the matter.
What would be nice is decentralization — because these registries are so similar to link shorteners I am wondering what a peer to peer registry system would look like a la DNS...
And now izs starts a new company npm inc. that will, well, who knows. But he's former Joyent who power npm, so will running npm transfer to npm inc.? But how does Nodejitsu or the 300K that they raised with their campaign fit into this picture?
I wrote the original version of the npm registry in a day or two on top of CouchDB. I built it quickly and didn't think much about scale.
Isaacs continued to improve and maintain that code. At one point he even wrote up an open standard for generic js package registries for CommonJS but they didn't seem to care (they were too busy arguing about promises).
At the time I wrote the initial code I was employed at CouchOne and we had a small CouchDB hosting platform operated by Jason Smith which is where we ran the registry free of charge. Later on, after CouchOne was aquired by Membase and became Couchbase, it decided to break off the hosting company and give/sell it to Jason Smith, which became IrisCouch.
IrisCouch continued to run the registry for free for several years. They had no venture funding and limited resources but they provided this service for our community anyway. They announced a product for enterprise (hosted) NPM but as far as I know it wasn't really marketed or sold. Last year IrisCouch was acquired by Nodejitsu.
Nodejitsu continued to host the registry for free. Some time last year the infrastructure hit a breaking point, mostly around CouchDB. Remember, I wrote this in a weekend when less than a hundred node packages existed. Many of the semantics from me and Isaacs' initial "prototype" persisted until just a few weeks ago. For instance, this single database held all the package binaries, for every version of a package, attached to the document for that package.
Once the registry started to have serious stability issues a few things happened. Isaacs started to work on ways to improve the reliability by changing how the registry worked and Nodejitsu sought community support for keeping the current registry up. At some point Isaacs also decided it would be best if he worked on NPM full time and built NPM Inc.
In the early days we weren't thinking about 58K modules, that was just crazy, we were just figuring out the simplest way to store a couple packages the node community was writing. Since founding this company Isaacs has already managed to re-write the way the registry works to fit the kind of load we have now.
Nodejitsu is now free of the financial burden that was dragging them down as well and Isaacs' new infrastructure can keep the registry up more cheaply than the previous system and more reliably.
1. Why are people happy about this? They did a crowd funding round taking common people's money, gave them squat, then took Investor money and gave them a share. (Would make me mad if I was part of the crowd)
2. What is the business model? In what world does PIP or any other package manager have a revenue stream? Ads? Spyware? There are no good models for this.
3. Does anyone else think that having a company title of Supreme Emporer is a sign that this is not a founder focused on community?
I'd say we bounce and use something else, but I did that a long time ago, so I can only suggest everybody else make like an external node. (a leaf ;-) )
Maybe they could make npm reliable for Windows with that money too.
Did they just hand over the keys to the node community to someone else?
It's amazing how things have changed in 10 years.
CPAN.
Perl.
A real community of programmers, system admins, enthusiasts.
All of the CPAN mirrors are paid for by somebody. Nothing's free; money is in the equation at some point.
Of course, that's a different model than VC funding. However, you're intimating that NPM isn't "real" with your last statement. The project has run for several years now. This isn't some project that came out of the chute with funding (such as Meteor).
Similar model is GitHub: long-running project/organization, took VC after a few years. In the time since they took the VC, have they become corrupted? Are they not a real community?
Let's be honest here, 92% of commits were made by izs, npm is izs and izs is npm. The two are inseparable. Without izs, any real development of npm would slow to a crawl, until someone else familiar with the codebase takes ownership.
I know izs personally and he is a stand up guy and a lot of the negative comments about him selling out in this thread are completely unjustified, especially without knowing more details about the rights he has relative to the contract he has with npm, inc. as its CEO.
If push comes to shove and izs disagrees with the direction the VCs push company after later rounds of funding where izs and the other founders lose control, does he still have the right to split off from the company and continue supporting npm the open source project independent of npm, inc., including taking it in a direction contrary to the goals of npm, inc.? If the answer is no, then there is risk that the community has plenty of time to mitigate if we really care about keeping npm as a public good. The risk is that we lose the most valuable person to this project because he can't work on it anymore.
That being said, the license information on the npm github repo shows that the most valuable assets are owned by izs and not this new company. He owns the trademarks "npm", "the npm registry" and the copyright on the npm codebase. npm, inc. does not own these things. I assume that he, the individual, licenses rights to the npm name to npm, inc. With all this in mind, does he have a non-compete clause that would prevent him from supporting npm if, for whatever reason, he splits off from npm, inc. If there are no legal restrictions on his rights to contribute/maintain, I'd say the risks are much lower than we thing.
At the end of the day, if people in the community really feel strongly about all this, the best thing they can does is start building equity around a different trademarks other than "npm" and the "the npm registry". Those are the two most important assets and given that the codebase is licensed as Artistic License v2, the name of any fork in the future would have to change its name even if the trademarks were unprotectable.
If all this bothers you, do the work to build a community fork of npm with a different name (and give ownership of the trademarks to the community), maintain feature parity and compatibility with npm and maintain registry mirrors for this community version. Add to this community fork a dual publish feature that simultaneously publishes modules to npm, inc. controlled registry servers and community maintained ones. This is the best insurance policy the community can have.
Either put your time where your mouth is and start working on a community fork that lives peacefully in parallel or quit whining and especially quit criticizing izs. izs has contributed an incredible amount of time to the needs of the community and has more than earned the goodwill and benefit of the doubt. If npm, inc. one day starts doing something truly anti-community, that is the time to cry foul, not now.
npm can refer to any number of things. It can refer to the client, the server, the hosting provider, the public package registry, and now npm Inc. They all sound like the same thing but they're all actually different.
Contrast this to Github. Github is a service that provides hosting, a public registry, and tools for git. Nobody complains about Github controlling git, because they're obviously separate things. Most people don't know that npm the registry is different from npm the software and that you can even host your own server.
I think they'll mostly be a consulting company for enterprise solutions to companies with hundreds of node.js projects going on that need a complex package management solution that npm inc. can provide.
I could take a giggly pot-shot at web development in general by proposing that they want to monetize node.js via a browser-base service to live one's entire developer life, but I'm in serious agreement with others' concerns that there's something ultimately harmful in VC money getting confused, panicky, and deciding to GSM (Google Mobile Services) the licensing of new code or come up with some ridiculous contributor licensing agreement like what I'm hearing about Ubuntu.
Take heed, FOSS communities don't negotiate except on an endless table that runs from one side of the universe to the other.
This npm inc. is one of the dumbest startup ideas that I have ever come across. Kudos to the founders for managing to hack the VCs, but VCs that dumb ain't gonna be around for long.
I don't understand how they intend to monetize this, but whatever.
There is always funding for everything that lives. Even if you're hosting something for "free" yourself, your job is the funding.
1. super easy publishing 2. A package for practically everything you can think of and if not, see #1 3. Most of the market share for its particular language so that you can be reasonably sure a particular module maintainer has an up to date package