6 ms·
Out of curiosity, what benefits does Microsoft/GitHub get from owning a package registry? I'd be fascinated to learn more about their long-term strategy here.
by mtm7 6y ago
Out of curiosity, what benefits does Microsoft/GitHub get from owning a package registry? I'd be fascinated to learn more about their long-term strategy here.
- sneak 6y agoControl. Getting to decide what goes into npm (the client tool) and what does not allows them to focus the ecosystem onto brands that they own and encourages people to buy their proprietary software and services. It also provides them the option of cutting off third-party tools (e.g. yarn) in the future if they deem it beneficial. My prediction is that they will prioritize the platform features that can only be accessed by first-party, branded tools, like the forthcoming GitHub mobile app. Eventually they will stop maintaining support for the APIs that the other tools use, and it'll be Microsoft tools from end-to-end. Pushing to GitHub and publishing to NPM from right within VS Code, et c. Of course, using them on Windows will always work best, and deploying to Azure will always be easiest.
- lstamour 6y agoI’m less pessimistic. Microsoft has engineers with a business mindset in charge. For now, it’s true. But we saw node vs IO.js — Microsoft can’t afford a fork or they lose their own control. They won’t close open source, they’ll add subscription or cloud usage fees for large enterprises. The value, like GNU “open core” is that open is popular, while enterprise features on the other hand are expensive. The enterprise is being led now by open source because it’s cheap, then value add to solve the problems they still have around control and oversight, etc. If anything, I expect basic Visual Studio internals will eventually get open sourced as cheaper to maintain that way than Roslyn rebuild-all-the-things. And VS Code will adopt them and continue to cannibalize VS mindshare.
- lioeters 6y agoThe first word that came to mind was "integration", but I suppose "control" is another way of putting it. I doubt Microsoft would intentionally degrade developer experience, like "cutting off third-party tools". Rather, they're seeking to gain market advantage from the tight integration of services. It would make sense for them to encourage third-party tools to play well in that "Microsoft ecosystem". > Pushing to GitHub and publishing to NPM from right within VS Code That's exactly what I picture coming soon, if not here already. Also: develop in VS Code, click to build, push to GitHub, deploy to Azure.
- koolba 6y agoSynergy. End to end tracing of dependencies. Licensing mirrors subsets to on premise clients. Single point of flow for code to published package. There’s plenty of places to extend money they’re making elsewhere.
- deleted 6y ago[deleted]
- jawns 6y agoOthers have commented on why the acquisition makes strategic sense from a technological perspective, but I think it's also important to consider how it makes strategic sense from a psychological perspective. For a long time, devs loved bagging on Microsoft. I once saw some Microsoft guys demo something cool at a conference, and they had to basically apologize that they were from Microsoft, because dev sentiment toward the organization was so negative, even though they were doing cool stuff. The acquisition of GitHub was absolutely intended to capture a tool/ecosystem that developers liked using and benefit from that positive sentiment. That's why Microsoft has been so cautious about branding GitHub as a Microsoft property out the gate. It's trying to ease devs into the idea that the company is something devs can like, and I wouldn't be surprised if this psychological strategy is at work with the npm acquisition, too.
- deleted 6y ago[deleted]
- metreo 6y agoAccruing positive sentiment in the dev community through acquisitions of someone else's nice things. Who came up with that crazy idea? GitHub isn't Microsoft. You can't buy brand loyalty.
- kortilla 6y agoAh, but they can. The older folks will remember GitHub being a separate thing but as hundreds of thousands of new devs enter the ecosystem every year, they are introduced to a cool GitHub tool by Microsoft. They don’t know that it was separate nor the animosity towards MS. You can’t change people’s minds on emotional baggage like this. You just wait for them to die off/retire and target the new blood.
- metreo 6y agoPersonally I've always found GitLab's design much more user friendly and the code and repository layout is much nicer than the spartan and cold GitHub. About all Microsoft has dared to change (at least transparently) since obtaining GitHub has been the pricing page, and objectively speaking right now... it's a hot confusing mess. A mascot featuring tentacles is all too fitting here. I don't know a lot about NPM or JS but it's being described as a dumpster fire which is also all too fitting. And I'm able smirk as I write that with no animosity or skin in the game.
- empath75 6y agoThink webassembly, not node.
- saghm 6y agoIt's worth noting that TypeScript is a Microsoft product. As TypeScript has become increasingly popular, I'd imagine that Microsoft has also paid increasing amounts of attention to the JavaScript ecosystem.
- muglug 6y agoYup. There’s a great memo from 1995 describing the web as the next big platform: http://pstella.com/reading/THEWEB.pdf http://pstella.com/reading/THEWEB.pdf Looking at the massive growth in frontend technologies within the last decade, it’s easy to see why Microsoft wants to be a little ahead of the curve this time.
- saghm 6y agoThere was a time in the past when Microsoft was ahead of the curve too; they were the ones who invented XmlHttpRequest back in the day.
- metreo 6y agoThey want to buy a community of developers.
- prosim 6y agoIt's all about securing the software supply chain. Mark Russinovich had a keynote on the general topic at RSA 2020, especially the section on package managers from 0:29 onwards: https://www.rsaconference.com/industry-topics/presentation/collaborating-to-improve-open-source-security-how-the-ecosystem-is-stepping-up https://www.rsaconference.com/industry-topics/presentation/c...
- metreo 6y agoIronic really given that Microsoft has the most notoriously insecure products I can think of. Can anyone point to a technology company that has a larger attack surface or a more fundamentally insecure product?
- thelastbender12 6y agoLowering the entry barrier for JS developers increases the plausible TAM if you make money from downstream developer tools/services, described as 'commoditizing your complement`. (ref https://www.joelonsoftware.com/2002/06/12/strategy-letter-v/ https://www.joelonsoftware.com/2002/06/12/strategy-letter-v/)
- bobmaxup 6y agospooky music Maybe to be able to be "legally compelled" to distribute backdoors onto linux servers / developer machines running npm in exchange for being awarded the JEDI contract.
- DeathArrow 6y agoThey get developer mind share and goodwill. That means Microsoft selling more of its services to companies. The old model of business was like selling pies to dad. Dad might buy or not. Now, you give a free candy to the kid, and dad will buy the pie, too. :)
- mrscottson 6y agoI'm sure the prism/NSA angle is still in play, how easy is it to compromise millions of projects in production owning both github and npm?