Live data from Hacker News

NPM Is Joining GitHub

github.blog

521–530 of 588 posts

Re: NPM Is Joining GitHub

#521

Earlier quoted context omitted.

Let's face it. Microsoft is a business and at any point in the future it might change course if it has economic preasures to do so. It can only keep being "good" as long as it has a stream of money coming in that allows this to happen. So the important thing is how they make npm economically viable. They need to have a good business model. I can only imagine GitHub was economically viable when they bought it, hence t…

"So the important thing is how they make npm economically viable." Thats not the important thing, thats the problem. Npm could easily be an open source client. Contain less code and be better. And have a mirors system like every other repo so it does not need money for hosting. Npm wanted to control nodejs and make money out it. And they have. Microsoft purchased that control and plan to make money out of it. This is…

> Npm wanted to control nodejs and make money out it.

What does this even mean?

Re: NPM Is Joining GitHub

#522

Earlier quoted context omitted.

Let's face it. Microsoft is a business and at any point in the future it might change course if it has economic preasures to do so. It can only keep being "good" as long as it has a stream of money coming in that allows this to happen. So the important thing is how they make npm economically viable. They need to have a good business model. I can only imagine GitHub was economically viable when they bought it, hence t…

"So the important thing is how they make npm economically viable." Thats not the important thing, thats the problem. Npm could easily be an open source client. Contain less code and be better. And have a mirors system like every other repo so it does not need money for hosting. Npm wanted to control nodejs and make money out it. And they have. Microsoft purchased that control and plan to make money out of it. This is…

> Npm could easily be an open source client

The NPM client is and has always been open source: https://github.com/npm/cli.

> Npm wanted to control nodejs and make money out it. And they have.

In what way, other than offering private package hosting for enterprises?

Re: NPM Is Joining GitHub

#523
After how Microsoft have handled GitHub I'm not worried.

However even a non-.NET web-developer now could be using quite a bit of Microsoft owned tech; VSCode GitHub npm Azure

Re: NPM Is Joining GitHub

#524
post #517

Earlier quoted context omitted.

> after we saw what happened to yarn What happened with yarn? As a very casual user of it, it seems to work well and have pushed npm to innovate a bit when it was stagnating. But I haven’t followed it lately. Were there technical issues or political drama?

Yarn's new version does a bunch of weird, complex to reason about stuff that's closer to a bundler than it is to a module manager: https://github.com/yarnpkg/yarn/issues/6953

You can use the node-modules linker and then it’s exactly like yarn 1 except faster.

Re: NPM Is Joining GitHub

#525

Earlier quoted context omitted.

Agreed, could have worded it better. Now that Wine is good enough to run most of Windows software and backed by Valve via its Proton initiative.

Hasn't Wine been good enough for at least 10+ years? Furthermore, how does being backed by Valve actually be of any significant value? I've heard of this argument for a couple of years now and I'm still not convinced (not that I follow Wine development that closely).

> Hasn't Wine been good enough for at least 10+ years?

Depends on what you mean by "good enough". Wine is an incredible project that has achieved amazing successes, but it still falls short in a lot of ways.

Re: NPM Is Joining GitHub

#526
post #187

Earlier quoted context omitted.

Microsoft wants to host as much information as possible so it can collect data on developers and users. It is very hard to avoid giving data to Microsoft. GitHub, NPM, LinkedIn, Office 365, Teams, the lock-in is still alive. A decentralized web or a non-for-profit like Wikipedia is a much better model for these infrastructure projects.

Git was designed to be decentralized from the start. Is there a way to revitalize that heritage? Discoverability and pull requests are two big benefits that GitHub has offered. Could we create decentralized open source solutions to provide those benefits? Are there other benefits that we’d need to provide to have viable alternatives to centralization?

Supporting and using Git forges that support decentralized development, such as Pagure[0], would be a good way to do so.

Pagure supports submitting pull requests with Git repos on any server (regardless of whether it's running Pagure or not) with its remote pull requests feature. Issues, docs, and pull request metadata are all stored as git repos using JSON files as data, making it easy and portable to other Pagure instances and easy to convert for any other system.

As far as I know, Pagure is now the only Git forge software packaged in all major Linux distributions (Fedora+EPEL[1], openSUSE[2], Mageia[3], Debian[4], Ubuntu[5], Arch Linux AUR[6]).

It'd be nice to see people interested in this helping to build a future supporting portable, decentralized development.

[0]: https://pagure.io/pagure

[1]: https://src.fedoraproject.org/rpms/pagure

[2]: https://build.opensuse.org/package/show/openSUSE:Factory/pag...

[3]: http://madb.mageia.org/package/show/name/pagure/release/caul...

[4]: https://packages.debian.org/sid/pagure

[5]: https://packages.ubuntu.com/focal/pagure

[6]: https://aur.archlinux.org/packages/pagure/

Re: NPM Is Joining GitHub

#528

Earlier quoted context omitted.

I wonder why your (entirely reasonable) comment got down-voted so much. This is exactly the risk why people prefer a distributed and decentralized internet over one where all open source is stored in one central Microsoft subsidiary (e.g. GitHub).

The central repository is entirely optional when using npm the cli tool; many companies use a proxy repository (such as artifactory) to host their internal packages and cache public ones already. Anyone can already run their own, or install from remote git urls (not just github) as well. If the new organization undermines the community, the community can easily move. NPM the company has had a significant number of mi…

With NPM now being an (indirect) part of Microsoft, I would expect them to introduce proprietary extension to the repository protocol (or something similar) in an attempt to lock the open source community into their hosting solution.

And no, you cannot cleanly separate between an ecosystem-defining tool and the company that controls how said tool will behave after the next automated update.

Re: NPM Is Joining GitHub

#529
post #448
post #252

Earlier quoted context omitted.

> NPM being such an important pillar in the software supply chain while having an unviable business model and largely being funded by VC money was never a good position to be in. Why does NPM need to be funded as a commercial entity at all? What other open source library has a private company running its package manager? This one still boggles my mind.

PyPy runs on donated infrastructure that costs over 800K/month in hosting costs[1]. Not many non-commercial entities can afford that. [1] https://twitter.com/dstufft/status/1236331765846990848

Looks like they’re paying for bandwidth, aka “cloud pricing.” They could probably reduce those numbers significantly, but if it’s funded by a grant why bother?

Re: NPM Is Joining GitHub

#530

Earlier quoted context omitted.

> Microsoft doesn’t do everything right but the GitHub acquisition has honestly gone better than I ever expected. Rather than forcing GitHub to adopt Microsoft centric policies, Microsoft has adopted more GitHub stuff, especially from a product POV. GitHub still runs as a separate company (different logins and health care and hiring systems) with its own policies and point of view. That's what we said about the Skype…

I'm not at Microsoft anymore but I was there when Skype got acquired and I had a bunch of friends who worked on it. You have to understand that the technology underlying Skype at the time was very brittle and poorly designed. Google almost bought Skype before Microsoft did and backed out after they got a look at the code. When Microsoft acquired it Skype was routing its traffic over port 80 for example.

> You have to understand that the technology underlying Skype at the time was very brittle and poorly designed. > When Microsoft acquired it Skype was routing its traffic over port 80 for example.

__I have to understand__ ?

Who is saying this? do you have any credentials / knowledge of Skype technology? My understanding is that you only report indirect discussion from "your friends who worked on it"?

Having been there, I would say quite the opposite.

Skype had pretty intricate means to bypass NAT to NAT clients. I would even go as far as saying that Skype P2P connectivity tricks were top notch, considering the incredible amount of different network setups that clients could face. Even in the weirdest conditions, you could trust your Skype client to somehow find a way to get the call through. This was through an immense collection of in-house-trial-and-error-STUN-hole-punching like techniques.

Now I can understand that for people outside of the peer to peer connectivity world, these techniques could seem completely foreign and brittle, but it's not. It's the world of internet clients we live in. It's not related to Skype, it's the route all peer to peer clients have to deal with. If you don't want that, don't go peer to peer.

> Google almost bought Skype before Microsoft did and backed out after they got a look at the code.

Where did you get that information? I had never heard of that interpretation of the story before.

My view on this is that Google considered buying Skype, but backed up because they wanted to have a cloud based service, instead of a p2p one. Microsoft was in the same state of mind, but decided to go along and migrate Skype to be a cloud service, which they did.

Now if you really want to discuss technical details and the state of Microsoft/Azure at that time, I would be pleased to do so.

Microsoft started the migration of Skype to the cloud at a time Azure was just a big beta test. Nothing was working properly, the tools were sub-par or in-existent. Nothing was reliable. You would deploy Azure services through remote desktop automated by PowerShell scripts. Managing databases was done through in-browser silverlight clients - yes, that was already EOL at the time, but that was the only way to perform DB queries with a UI.

When complaining about the deplorable half-baked status of the tooling and cloud services that we were required to use to migrate Skype, the only response was "Yeahhh, Eat your own dog food".

Thanks but no thanks.

All the great Skype engineers left in the two years after the start of the migration to Azure - mostly to join Twilio.

Post reply on HN