4 ms·
Part of the problems is that certain software ecosystems (npm, rust+cargo, golang with "build against HEAD") seem to think it's "sexy" to declare war on the tra
by infinity0 9y ago
Part of the problems is that certain software ecosystems (npm, rust+cargo, golang with "build against HEAD") seem to think it's "sexy" to declare war on the traditional package management systems, because they see proper long-term maintenance issues as being a burden on developer time and the "move-fast-and-break-things" paradigm.
In certain cases this is driven by leaders of those ecosystems having more experience developing in a corporate environment where indeed everything builds against HEAD, not realising that this model completely breaks down in a decentralised free software environment where different teams are more asynchronous and have no chance of globally syncing with everyone else all the time.
Please stop treating FOSS distributions like dirt, our model works better in an environment where most maintainers are volunteers rather than full-time paid developers, for shipping stuff that is usable over a long (> 3 months) period of time.
- Xylakant 9y ago> rust+cargo ... seem to think it's "sexy" to declare war on the traditional That's not true. They do solve different problems, both are related to packaging, but still tangential to each other. You can use npm, cargo, bundler to build software which you then wrap to RPM/DEB ... system packages. I can recommend the talk that Yehuda Katz held on packaging/package managers at the Rubyconf Portugal '16 https://www.youtube.com/watch?v=Bwk8mdU6-ZY https://www.youtube.com/watch?v=Bwk8mdU6-ZY It's mostly about bundler and cargo and the design decisions behind them.
- infinity0 9y agoI'm not going to watch a 1 hour video just to "get" your point. I am a package maintainer, and my actual experience is it's much harder to package software in these ecosystems. When I bring up issues, they get brushed aside as "that's not how things are done", ignoring the actual issues. This is "declaring war", no matter how you try to paint it. Bundling is not packaging management, it's doing a disservice to your users. Bundled software is not maintained in the long run, no teams bundling software are tracking security and bug fixes for the full dependency tree. It's too costly to do this across all pieces of bundled software. That is why FOSS distributions put an emphasis on deduplication, proper API compatibility, and loose version constraints. The package managers I mentioned take the opposite approach, of strict version constraints and little API compatibility. This makes things easier for the developers, but much harder for maintainers. Every new version we have to carry, simply because developers were too lazy to maintain API compatibility, means more work for maintainers to track bugfixes. The original article is proposing a way to reward more maintainers. This is one way to put resources where they're needed. A better way is to arrange your system to not need so much resources. That is what FOSS distributions do.
- rwallace 9y agoWhat exactly do you find problematic about npm compared to the traditional package management systems (i.e. apt et al?)? I ask because having started using npm some months ago, I find it works better than anything I've ever previously encountered. Is there something I'm missing?
- infinity0 9y agoThat's because you're using it as a developer. Trying maintaining software "packaged" using npm and shipping it to users later in a way that follows best practises. You'll want to kill yourself.