5 ms·
Everything You Wanted to Know About Yarn Package Manager
- gotofritz 10y ago- promises "everything you wanted to know about yarn" - has barely any content
- joelthelion 10y agoWell, most people don't want to know much about Yarn. Granted, mostly because they don't even know it exists :)
- sotojuan 10y agoWhat do you expect when Yarn has been out for less than a couple of weeks and this person isn't involved with the project in any way?
- choward 10y agoI was thinking the same thing. I want to know about the pitfalls and reasons not to use yarn. For example, does it support modules from github?
- ittan 10y agoYarn needs to learn from lein for clojure. Yarn is the wrong way forward, but an incremental fix for npm.
- agnivade 10y agoWhy can't all of this be patched in npm ? Why do we have to create a new tool every time ? It makes no sense and honestly makes me want to tear my hairs.
- Touche 10y agoA lot of people say this and I'll repeat the answer: go look at npm's source code and tell me you'd like to "patch in" a large change such as the one Yarn takes on. No seriously, go look at their source code. In particular go look at the caching code, one of the big things that Yarn fixes. You think their time would have been better spent hacking on that?
- throwanem 10y agoMaybe? It'll be interesting to see how many bugs turn up in Yarn that've already been fixed in npm. Until we can perform that kind of comparison, I'm not sure it is possible to know whether building a new package manager from scratch was more worthwhile than improving the one that everyone already uses.
- agnivade 10y agoExactly my point. I am not totally against reinventing the wheel. Sometimes its fun and sometimes interesting results do come out of it. I am especially looking at the servo project. But considering the amount of collaboration effort it took to build this (fb said they collaborated with multiple companies in different timezones), wouldn't it be better to spend a little more time understanding npm's codebase and get it patched ? Maybe I'm wrong, but yea just a thought.
- Touche 10y ago> But considering the amount of collaboration effort it took to build this (fb said they collaborated with multiple companies in different timezones), wouldn't it be better to spend a little more time understanding npm's codebase and get it patched ? Better for you? You know that open source work is free labor, right? Why should they prefer to spend weeks trying to understand undocumented, opaque and "clever" code (much of which has never been refactored) when they can start from scratch with a codebase of their own design? What I'm asking is, what is the value to them? Or to you (assuming you ever do open source)? Unless you are getting paid for your OS work, you're under no obligation to do things any way other than what works for you.
- matthewmacleod 10y agoI have such a burning, unquenchable hatred for NPM that I just switched to using Yarn. It's fine, has done what I expect it to, and hasn't caused any problems so far. Maybe not an ideal solution, but for someone coming primarily from languages that have non-shitty package managers it's a breath of fresh air.
- eric_b 10y agoThis post contains content that is plagiarized verbatim from other sources. Namely Yehuda's blog post and the Yarn homepage itself.
- noir_lord 10y agohttp://yehudakatz.com/2016/10/11/im-excited-to-work-on-yarn-the-new-js-package-manager-2/ http://yehudakatz.com/2016/10/11/im-excited-to-work-on-yarn-... for those who where curious.
- Kiro 10y agoWhat's the benefit of having a lockfile compared to just specifying exact versions in your package.json?
- throwanem 10y agoBecause you can only specify exact versions for your top-level dependencies. Whether or not they pin versions of their own dependencies is up to their own maintainers; you can't control it from package.json. And, while a lot of npm packages adhere to semver and avoid shipping breaking changes on minor version number bumps, a lot of npm packages don't. So you can get hosed through no fault of your own by an Nth-level dependency. 'npm shrinkwrap' solves this by pinning the currently installed versions of everything under node_modules/, regardless of dependency depth. Yarn does the same thing, but by default rather than, as with npm, an optional extra. There's an argument to be made that the correct place to shrinkwrap, if you want to, is in your build process. But I suspect that, in practice, Yarn defaulting to it will prove a net positive, albeit a bit of a speedbump for people looking to do turnkey migrations from npm.
- Kiro 10y agoOh, of course. Thank you!
- kyriakos 10y agoanyone knows if yarn has an equivalent of --no-bin-links option? EDIT: guess not according to https://github.com/yarnpkg/yarn/issues/929 https://github.com/yarnpkg/yarn/issues/929