Live data from Hacker News

NPM Is Joining GitHub

github.blog

461–470 of 588 posts

Re: NPM Is Joining GitHub

#461

Microsoftie here — throwaway for obvious reasons. Microsoft doesn’t do everything right but the GitHub acquisition has honestly gone better than I ever expected. Rather than forcing GitHub to adopt Microsoft centric policies, Microsoft has adopted more GitHub stuff, especially from a product POV. GitHub still runs as a separate company (different logins and health care and hiring systems) with its own policies and po…

[deleted]

Re: NPM Is Joining GitHub

#462

Earlier quoted context omitted.

> after we saw what happened to yarn I missed something, what happened to Yarn?

The maintainer released Yarn 2. Yarn 2 is pretty foundationaly different than Yarn 1, and can and does break a lot of products/projects if used. Some folks are not happy about it, although Yarn 1 will probably continue to be maintained by the community for a while. This seems to be pretty fair about the whole thing: https://shift.infinite.red/yarn-1-vs-yarn-2-vs-npm-a69ccf022...

One of the big additions in Yarn 2 is Plug N' Play, which allows for more flexible module resolution.

Support is middling, but once you get it working, you have near-instance near-zero size installs.

Re: NPM Is Joining GitHub

#463
post #291

Microsoftie here — throwaway for obvious reasons. Microsoft doesn’t do everything right but the GitHub acquisition has honestly gone better than I ever expected. Rather than forcing GitHub to adopt Microsoft centric policies, Microsoft has adopted more GitHub stuff, especially from a product POV. GitHub still runs as a separate company (different logins and health care and hiring systems) with its own policies and po…

> Google and Amazon have the EEE under lock right now what is EEE?

Oh sweet summer child.

Re: NPM Is Joining GitHub

#465

Earlier quoted context omitted.

The maintainer released Yarn 2. Yarn 2 is pretty foundationaly different than Yarn 1, and can and does break a lot of products/projects if used. Some folks are not happy about it, although Yarn 1 will probably continue to be maintained by the community for a while. This seems to be pretty fair about the whole thing: https://shift.infinite.red/yarn-1-vs-yarn-2-vs-npm-a69ccf022...

What happened to yarn is they released a v2 with some backwards incompatibilities... and for this reason we should be glad facebook didn't buy npm? (Also facebook doesn't actually own yarn). Well I'm confused.

some backward incompatibilities? You apparently can’t run node directly. That’s kind of a problem for all but the most obvious of use cases.

Re: NPM Is Joining GitHub

#466

Earlier quoted context omitted.

Why would NPM run out of money? NPM is the primary vendor for worry-free distribution and management of private JavaScript packages for $7/month/user. In a time where bandwidth is basically free (outside AWS/Azure/GCP) that should surely pay for server costs and a handful of developers. It probably isn't going to 20x VC money, but it sounds like it would be profitable to run as a business.

Agreed. It was profitable before, (no indication they sold at a loss), it will probably be profitable after for MS. "2fa" sounds bad. That is clearly marketing bs for linking your npm account to a MS account with more personal info attached. Ease of publishing will be the first thing to go. Then the fun will disappear with MS as owner, like when Oracle bought Java. Happy to be a rustacean.

Regards 2FA/Login: Except that Microsoft has not done this with GitHub. And NPM is joining GitHub not Microsoft. You will see non login vanishing in favor of GitHub Login for sure. And the second factor, see what GitHub offers. For me that is currently a OTP generator

Re: NPM Is Joining GitHub

#467
post #419
post #180

Earlier quoted context omitted.

VS Code is also spyware; I am not sure that this argument furthers your intended point. The fact that it is open source and popular is not sufficient on its own. It had to be forked (vscodium) to show basic respect for the user’s privacy and system resources.

> VS Code is also spyware This is such an extreme & pretentious viewpoint. Microsoft knowing that I have VS Code installed & getting a report when it crashes is not in mine, or really any normal developer's threat landscape.

Don’t forget you’re on HN.

Re: NPM Is Joining GitHub

#468
post #372

Earlier quoted context omitted.

It depends on what the alternative is. When NPM starts running out of money to run the service what would happen? More VC, but only to a point and the firms would be increasingly be influencing NPM to make money by any means(probably not good for anyone but the firms). Alternatively a cash strapped NPM fails to invest in security and availability of the service leading to widespread outages or worse a large scale sup…

The alternative is that the entire source control system (GitHub) and the entire artifact registry (npm) are run by a giant multinational military defense contractor with close and longstanding ties to the US military. Did we forget so soon that the Snowden slides are PowerPoint ? I'm not sure that's an improvement in any way whatsoever.

No US company is better in that regard. I prefer one with an army of lawyers. Damn, should have gone to Oracle. That is a joke. A joke!!!

Re: NPM Is Joining GitHub

#469
post #372

Earlier quoted context omitted.

It depends on what the alternative is. When NPM starts running out of money to run the service what would happen? More VC, but only to a point and the firms would be increasingly be influencing NPM to make money by any means(probably not good for anyone but the firms). Alternatively a cash strapped NPM fails to invest in security and availability of the service leading to widespread outages or worse a large scale sup…

The alternative is that the entire source control system (GitHub) and the entire artifact registry (npm) are run by a giant multinational military defense contractor with close and longstanding ties to the US military. Did we forget so soon that the Snowden slides are PowerPoint ? I'm not sure that's an improvement in any way whatsoever.

> Did we forget so soon that the Snowden slides are PowerPoint?

what does that mean? That Microsoft works for the NSA or something?

Re: NPM Is Joining GitHub

#470
post #439

Earlier quoted context omitted.

https://www.nytimes.com/2019/02/27/us/immigrant-children-sex... https://www.newyorker.com/news/q-and-a/inside-a-texas-buildi...

Bad people exist and bad things happen in every large organization in every government of every country. It is not representative nor useful in discussing the behavior of the whole.

Yes they do. But important part is what organisation does about that. Does it close the eyes, does it encourages it, does it publicaly removes bad people from org to send the message?
Post reply on HN