Live data from Hacker News

NPM Is Joining GitHub

github.blog

191–200 of 588 posts

Re: NPM Is Joining GitHub

#191
post #180

Earlier quoted context omitted.

Tbf Microsoft have won back a lot of good faith with developers due to projects like VS Code and TypeScript, even for those of us who remember their past. And we're yet to hear of any negative impact of their Github acquisition (afaik - correct me if wrong).

VS Code is also spyware; I am not sure that this argument furthers your intended point. The fact that it is open source and popular is not sufficient on its own. It had to be forked (vscodium) to show basic respect for the user’s privacy and system resources.

It's true insofar as VS Code is widely loved by web developers.

So it "furthers my intended point".

Re: NPM Is Joining GitHub

#192
post #187

I'm surprised there's not a single mention of "Microsoft" in this or the npm announcement [1], given the old-evil-history of Microsoft and the new-nice Microsoft we have today. I would expect that there was at least a mention, considering the reason that most modules in npm are still in ES5 is exactly because of the monopolistic practices that Microsoft followed back in the day which makes Internet Explorer still rel…

Microsoft wants to host as much information as possible so it can collect data on developers and users. It is very hard to avoid giving data to Microsoft. GitHub, NPM, LinkedIn, Office 365, Teams, the lock-in is still alive. A decentralized web or a non-for-profit like Wikipedia is a much better model for these infrastructure projects.

[deleted]

Re: NPM Is Joining GitHub

#193

How much did Microsoft pay? What did the founders take away? Most people don’t know, in these open source acquisitions by for profits there’s money involved and “founders” get an exit. Not always clear To the public who those are or what they took home from a mostly volunteer effort.

I too was curious about how much the acquisition cost. According to TechCrunch:

> GitHub, the developer repository owned by Microsoft, made a little deal of its own this morning when it bought JavaScript packaging vendor npm for an undisclosed amount.

https://techcrunch.com/2020/03/16/github-nabs-javascript-pac...

Re: NPM Is Joining GitHub

#194

Earlier quoted context omitted.

I wonder why your (entirely reasonable) comment got down-voted so much. This is exactly the risk why people prefer a distributed and decentralized internet over one where all open source is stored in one central Microsoft subsidiary (e.g. GitHub).

The central repository is entirely optional when using npm the cli tool; many companies use a proxy repository (such as artifactory) to host their internal packages and cache public ones already. Anyone can already run their own, or install from remote git urls (not just github) as well. If the new organization undermines the community, the community can easily move. NPM the company has had a significant number of mi…

Not that many companies had proxies when leftpad was taken down.

Re: NPM Is Joining GitHub

#195
post #21

Earlier quoted context omitted.

I am glad that the npm team will finally have some adult supervision. Meanwhile, I almost have my team switched to yarn.

yarn v1+ or yarn v2/berry? Switching to berry has been a huge PITA over here, but I don't want to give up workspaces

Our 'workspace' is so ornate that yarn couldn't handle it. 1.21+ almost looks right, but something very bad is still going on with mocha deduping, such that tests are failing with really bizarre error messages.

I check yarn about every three months, or when I find a new, infuriating bug with the npm CLI (so, every couple of months on average). I think npm install suffers greatly from not having a formal spec. It has been bugfixed by so many different individuals now that it has reached a truly astounding level of schizophrenia.

If yarn didn't exist, I would have started trying to break down the install problem into many independent concerns that can be reasoned about individually and tried to solicit help in making a full installer out of it. If I'd known I'd still be trying to make yarn workspaces work for us 18 months later I probably would have.

Node modules in general have some bad patterns of delegation that are utterly antagonistic to self-documentation, and both yarn and npm seem to suffer from this as well. I think in the next week or so I'm going to have to set up a small test case that exhibits the yarn bug I'm seeing, or any of the half a dozen interlocking (emphasis on 'lock') npm bugs that now have me painted into a very tiny corner.

Re: NPM Is Joining GitHub

#196

Earlier quoted context omitted.

Tbf Microsoft have won back a lot of good faith with developers due to projects like VS Code and TypeScript, even for those of us who remember their past. And we're yet to hear of any negative impact of their Github acquisition (afaik - correct me if wrong).

Before someone else comes along and writes a monologue, the biggest downside might be how it handled (didn't break) its contract with ICE[0]. If the acquisition didn't happen, old GitHub might've dropped the contract immediately upon enough employees speaking about it. 0: https://news.ycombinator.com/item?id=21412600

That's a fair point - thanks for the reminder :|

Re: NPM Is Joining GitHub

#197

Earlier quoted context omitted.

Can I be so bold as to suggest a new feature? It'd be wonderful, as a package consumer, to have visibility into some security metrics for a given package. This would be useful both at initial install time, and when the package is upgraded. Something like: 1) who are the latest commits GPG signed by? 2) is the package publisher using 2FA? 3) what is the security profile of all dependent packages? 4) are there any new…

Yes, we (internally) call this a "Bill of Health" and believe that all packages should have this kind of diff-able information available. Understanding what's happening at the source level is key to being able to trust any package published.

NICE! It would be wonderful to expose that information!

Somewhat related, I believe NPM pulled in (or co-opted) some of the heuristics from this: https://github.com/npms-io/npms-analyzer (but those don't seem to include any of the aspects I suggested above).

Re: NPM Is Joining GitHub

#198
post #70

Heh, I called this 10 months ago: https://news.ycombinator.com/item?id=19838122 Somebody replied "Microsoft won't acquire npm for sure."

Neat contribution! You guessed one thing, someone else guessed another, but they were wrong, and you were right! Yay on @pavlov. Boo on them.

A special day. The stock market is down 388% and 142% of people are predicted to die, but I got Internet karma points for guessing something right and that's what really counts.

Re: NPM Is Joining GitHub

#199

Assuming this was an acceptable exit: I'm impressed that NPM pulled this off. They were basically doing the "no revenue model to speak of, hope we'll get acquired by a bigco" startup play that was starting to go out of vogue already when they were founded. I wonder to what extent they've had influence over their own success at all though. Basically they had to hope that JS stayed popular (it did), that Node stayed re…

Not sure how good an exit it was. Crunchbase says they have fewer than 50 employees [0], so I'm guessing the first 10 people did pretty well but that the rest got what amounts to a nice bonus.

Keeping the lights on long enough makes this kind of exit more likely. Paul Graham has a good article about this: http://www.paulgraham.com/die.html

NPM did better than "just" keeping the lights on, though. They even held Yarn at bay by adopting its best features very quickly.

[0] https://www.crunchbase.com/organization/npm

Re: NPM Is Joining GitHub

#200
post #179

Earlier quoted context omitted.

What does a trustworthy Microsoft look like to you?

Chapter 7 Bankruptcy where they get acquired by a newly-reformed Sun Microsystems (where no stock is owned by Oracle or Oracle shareholders). EDIT: I'm mostly kidding, but you can't really expect true change of morals when the vast majority of the upper management is the same under the new CEO as under the old one.

As a former Sun employee I love this comment, but in all fairness Sun did have its own level of sleaze in the C suite (neither Eric Schmidt nor Scott McNealy would really do well as ethical leader exemplars)

That said, I'm thinking Moon Microsystems :-) Not as big or as hot as Sun. (ok that is a bad punalogy) I did get the domain though, it was available and I couldn't resist.

Post reply on HN