15 ms·
Windows Package Manager Preview
- ruffrey 6y agoIt talks about installing apps. But what about DLLs? .NET framework versions?
- pjmlp 6y agoIt has been ages that the best practices are to install them alongside the applications instead of polluting C:\Windows. Also .NET Core is supposed to be bundled with the application.
- rbanffy 6y agoUnfortunately, this causes file duplication (which is not that bad these days of endless storage) and unnecessary vulnerabilities when outdated vendored libraries are used by applications. Linux distributions tend to keep shared libraries in their own packages and applications depend on them so that when you install an app, the packages with the libraries also get installed. And all packages in the distribution tend to use the same versions of those shared libraries.
- pjmlp 6y agoWhich is why nowadays Linux suffers more from .so hell and ABI breakages than Windows does.
- rbanffy 6y agoHaven't seen that in ages, but, then, I try to avoid installing packages from non-official repos. Distributions work hard to make sure that everything within the distro ecosystem is self-consistent.
- AnIdiotOnTheNet 6y agoExactly, if you're not doing anything interesting you'll never notice, but the second you step out of the distro's box and do something crazy like try and install a new version of software direct from the developer, install a second version for testing, or run software compiled 10 years ago, the world falls apart.
- rbanffy 6y ago> if you're not doing anything interesting you'll never notice s/interesting/suicidal/ Replacing .so binaries with other arbitrary .so binaries is not what I would call "interesting". Interesting is deleting your /var folder. Or doing a `find /sys/devices/system/cpu -name 'online' -exec echo 0 > {} \;`.
- derefr 6y agoNot really? In the Debian ecosystem, at least (can't speak for any other), every major version of a library package is expected to be packaged as its own separate concurrently-installable package. You'll find e.g. postgresql-11-dev and postgresql-12-dev both exist as packages, and one provides libpq.11.y.z.so + its headers, while the other provides libpq.12.y.z.so + its headers. Each gets updates independently. One will never automatically switch you over to the other. And major versions are the only things that need to be separately packaged, because the Linux native-library ecosystem is expected to keep .so ABI compatibility through both "patch" and "minor" updates (the only difference between the two being that "minor" updates can add new exported symbols to the library; they still should not break usages of existing symbols.) This particular arrangement was, in fact, what the Semantic Versioning standard was introduced to accomplish—getting upstream developers to use their version-tuples to mean the same things that Linux-distro package maintainers expect them to mean, allow Linux-distro package maintainers to reuse upstream version schemes rather than needing to maintain their own.
- kasabali 6y agoAll true in theory, but in practice these mechanisms are worthless because for most libraries Debian developers are dropping older version of libraries immediately after transition to the new version is completed. Want to to run a 3rd party binary that depends on an older library? You're favorite package was dropped during the transition? Tough luck. Your best bet is installing needed library packages from previous debian release and praying that'll work.
- derefr 6y agoTrue enough, but if stability is your desire, that is precisely why distros cut releases (and especially LTS releases) in the first place. If you want a program that can run without ABI-conformance changes for years and years, base it on an LTS release, and that LTS release will keep whatever ABI-major versions of the .so library-packages it shipped with updated (with security updates, at least) until the release's EOL. If you don't want ABI breakage, then don't dist-upgrade! But, this is also to say: if you're creating a new, greenfield project, or a new major version of your own app—and you haven't yet deployed it into the wild as a fixed binary that people rely on to continue running on their boxes between upgrades—then nobody else but you has any incentive to keep things stable for you. If you want to develop against the newest Debian release at any given time, then it's up to you to catch up to whatever the newest ABI-major versions of your deps are at any given time. That's a problem you've chosen for yourself.
- jfkebwjsbx 6y agoNever had a single issue with official repositories.
- contextfree 6y agofwiw, on Windows MSIX deduplicates identical files across all package installs.
- rbanffy 6y agoIt gives rise to some interesting issues - if program A wants to update IMPORT~1.DLL that was installed also by program B, what happens if B requires a different version of IMPORT~1.DLL?
- pjmlp 6y agoThey don't, because MSIX introduces UWP sandboxes also for Win32 applications.
- contextfree 6y agoThen they'll no longer be identical, so they'll go back to having separate files.
- open-paren 6y agoThis[1] is the repository from which it pulls. It sounds like third-party repos are a planned feature. Basically, every package is a yaml file like this: Id: string # publisher.package format Publisher: string # the name of the publisher Name: string # the name of the application Version: string # version numbering format License: string # the open source license or copyright InstallerType: string # enumeration of supported installer types (exe, msi, msix) Installers: - Arch: string # enumeration of supported architectures URL: string # path to download installation file Sha256: string # SHA256 calculated from installer # ManifestVersion: 0.1.0 Doesn't look like there is field for dependencies of a package, but this is also a 0.1.0 release. [1]: https://github.com/microsoft/winget-pkgs https://github.com/microsoft/winget-pkgs
- DaiPlusPlus 6y agoYAML? That’s very surprising to me (I grew up in the XML-for-everything days). Would this be the first-ever first-party Microsoft project to use YAML?
- febstar 6y agoAzure (DevOps) Pipelines use YAML. Not sure if that counts?
- modernerd 6y agoNot sure about YAML, but I was happy to see Windows Terminal use JSON for configuration instead of XML. https://github.com/microsoft/terminal/blob/master/doc/user-docs/UsingJsonSettings.md https://github.com/microsoft/terminal/blob/master/doc/user-d...
- eigenvalue 6y agoI’m sure the developers of Chocolatey have been dreading this day for years.
- STRML 6y agoDreading? I doubt it. It's a relief when the problem your library solves no longer needs solving!
- _-david-_ 6y agoIf it was just a free library that would be one thing but they have a company with multiple employees.
- saxonww 6y agoI won't say it was silly to ever make Chocolatey, but it was living on borrowed time from day one. What's interesting to me about this announcement is that it seems to replace something they already had; Microsoft released OneGet several years ago and was positioning it (I thought) the same way they are positioning this. It's in maintenance mode now. So I would say Chocolatey is doomed only if this actually sticks.
- nindalf 6y agoNo, can't you see? Microsoft is going to Embrace, Extend, Extinguish Chocolatey!!! /s
- Sevaris 6y agoDepends on how good the Microsoft implementation is. Afaict, mainly power users use Chocolatey, and they're going to be particularly critical of a solution that is half-baked and doesn't solve the problem as well as an existing, third-party solution that they're already using and they're already used to. I'm certainly not going to switch over just because it's MS. It's going to have to prove it's at least as good as, if not better than, Choco. There are also benefits to Chocolatey that probably can't be replicated by MS, such as the package repo being a community effort and it being a relatively open platform for anybody to add whatever package they need.
- deleted 6y ago[deleted]
- ocdtrekkie 6y agoI found the issue I think Microsoft is going to actually foul up poorly here, which I... went ahead and filed an issue on: https://github.com/microsoft/winget-pkgs/issues/288 https://github.com/microsoft/winget-pkgs/issues/288 In short, a Microsoft employee added AdoptOpenJDK 8 to the repo. ...Java 8? ...In 2020? Another user has opened a PR to add what looks like the FSF's OpenJDK 14 to the repo. So are we supporting 8 or 14? Are users who want to "winget install openjdk" going to get 8 or 14, Adopt or FSF? I doubt Microsoft is willing to pick winners or losers or opinionate on the authority of third party package sources, and hence, the dream of "winget install powertoys" will probably only reliably do what it should for Microsoft tools.
- rbanffy 6y agoYou can have multiple versions of Java on your machine. Packages in other OSs usually have lists of packages they depend upon, packages they conflict with, and "virtual" packages they provide. Therefore, an app that prefers OpenJDK 14 can require it directly while one that doesn't care can require a virtual package called 'java' that's provided by both 8 and 14.
- ocdtrekkie 6y agoSure, but it doesn't really look like Microsoft has a plan or implementation for this yet, and currently serves a version of Java from 2014.
- Operyl 6y agoJava 8 is still widely used, it seems. For example, Mojang (owned by Microsoft) still ship Java8 with Minecraft. Pretty sure 8 still gets updates in 2020 too.
- throwaway8941 6y agoHell, even Spring boilerplate generator still defaults to Java 8. https://start.spring.io/ https://start.spring.io/
- sigsergv 6y agoWhat about uninstalling apps?
- nailer 6y agoHow does this relate to `install-package`, the Microsoft-official 'package manager for package managers' released a few years ago?
- techntoke 6y agoMicrosoft would be much better off if they had a YAML format for creating Windows installations, as opposed to their current unattended installs.
- Congeec 6y agoI'm pretty satisfied with the package manager scoop. Scoop for now works best when you just install binary software. It is not a replacement for package managers like vcpkg yet with which you can pull dev dependencies for a project. How does winget compare to scoop? Does it replace vcpkg/nuget/conan/...?
- pas 6y agoAnyone else looking to try scoop should be familiar with this list: https://rasa.github.io/scoop-directory/by-score https://rasa.github.io/scoop-directory/by-score
- deleted 6y ago[deleted]
- eclipsetheworld 6y agoI'd recommend to take a look at the project's roadmap to get an idea where Microsoft is going with this: https://github.com/microsoft/winget-cli/blob/master/doc/windows-package-manager-v1-roadmap.md https://github.com/microsoft/winget-cli/blob/master/doc/wind...
- mavhc 6y agoIt mentions oneget, isn't that nuget now? and also by Microsoft?
- tjoff 6y agoDo you need a microsoft/whatever account for this? I can't see anything about it but wouldn't be surprised if they forgot to mention it...
- phiresky 6y ago... this thing literally just downloads .exe files and then executes them. There's no dependency management. Look at the firefox "package": https://github.com/microsoft/winget-pkgs/blob/master/manifests/Mozilla/Firefox/75.0.yaml https://github.com/microsoft/winget-pkgs/blob/master/manifes... There isn't even any uninstall functionality. This is a package manager as much as a piece of cardboard is a swiss army knife. Even if you say "but it's a preview", there's just no where to go when your starting point is "execute some arbitrary binary". The point of packages is to be declarative as much as possible.
- nojito 6y ago>There isn't even any uninstall functionality. Control Panel --> uninstall apps The issue is with how windows setup exes are designed. Most allow you to uninstall after running the exe again...others do not and leave traces of themselves everywhere. This is a great first step and leads to some automation possibilities when setting up new installs.
- olyjohn 6y agoAs a former SCCM admin, I can tell you that packaging things like this will be a nightmare. Microsoft really needs to revamp the way software is installed on Windows, and make it all work the same way. Putting a wrapper around an MSI or EXE can be a nightmare. I mean, /SILENT is not good enough for many apps to make installers silent, so the switch /VERYSILENT came out. And even then, it's still not standardized, and many programs will still pop up dialogs and kill your automation. And then you'll find that the same package won't run the same depending on what version of Windows, what edition, 32 or 64 bit, etc and the installer will fail. Then when the MSIs aren't built correctly, they will leave you with a detection method that gets hosed when the software auto-updates. So you run your package manager, and it'll detect that your software is no longer installed, because the MSI product code changed for the newer version. I mean we have so many ways to do software on Windows. Let's count them: * MSI * EXE * MSU * AppX * Windows Features * dism * Windows Update * SCCM Deployments Even just open up the "Uninstall Apps" control panel, or the old "Add / Remove Programs" and look how long it takes to load the list. It's pulling from like 20 different places in the registry and various places in the WMI database just to build that list. So when you want to use that as a detection method, good luck...
- lrpublic 6y agoI like scoop, and this is a show stopper for me. "This project collects usage data and sends it to Microsoft to help improve our products and services. See the privacy statement for more details." from https://github.com/microsoft/winget-cli https://github.com/microsoft/winget-cli
- GordonS 6y agoI don't personally mind telemetry, as long as it's opt-in, or I can at least opt-out, and the data that is collected is clear. The docs don't make any mention of how to opt out, or what data is collected. Which is incredibly annoying, as I really want an official package manager for Windows :/
- nojito 6y agoWhy is that a showstopper? People do not give feedback so it's impossible to tell how their programs are being used. The other choice is to listen to the vocal minority that offers feedback than you get into issues of implementing features that no one wants/uses.
- lrpublic 6y agoIt's not opt-in, so quite likely a breach of GDPR. The telemetry in question seems to be logging what is installed, not just how the application is used. Regardless of consumers willingness to provide feedback it's not a reasonable choice for a large software vendor to collect data from customers computers about competitors products.
- nojito 6y agoIt’s logging what’s used so that the app can be improved to fit the use cases of its users. Of course it’s reasonable. The other choice is developing blindly or listening to the vocal minority. Both of which hurt ALL users in the end.
- lawnchair_larry 6y ago
- wronex 6y agoAre they doing any form of caching (think CDN) to battle link rot?
- charlesdaniels 6y agoI'm not a Windows user... but didn't they already do this with OneGet? Did that get deprecated? Is this just a re-branding?
- GordonS 6y agoI'm a Windows user, but I've never even heard of OneGet?
- charlesdaniels 6y agoThis one, as I recollect: https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_packagemanagement?view=powershell-7 https://docs.microsoft.com/en-us/powershell/module/microsoft...
- 6c696e7578 6y agoSo in 199{7,8,9}? I was using yast and/or apt-get to get packages. That was >20 years ago. Now MS have offered something like tar.gz of binaries without dependencies. But I guess this is an answer to the "where's package management" question. Still not there.
- recursive 6y agoAll the dependencies are just in the original thing. I have very limited experience with Linux but chasing down problems with dependencies of dependencies feels like a special circle of hell to me.
- 6c696e7578 6y ago> chasing down problems with dependencies of dependencies feels like a special circle of hell to me. Were you getting source from author sites or using the package manager? I've never had problems with apt or yum. In the days before yum it was a different story in Red Hat. Debian have always had it right with apt IMO. You could attribute the success of Ubuntu to it I feel.
- recursive 6y agoI don't remember. I tried to do some rails development in linux like 10 years ago. I know I was using apt, or at least started there. I don't think I ever even got the environment running. I'm sure I was doing something wrong, so no need to blame me, I already know.
- totony 6y agoStill better than the status-quo where you have different launchers auto-updating programs and programs self-updating randomly (and some just not updating causing security issues)
- jamieweb 6y agoI'm interested to know whether the SHA256 hashes are just done on a TOFU basis, or whether they actually verify the Authenticode/GPG signatures of the EXE files to get an 'authoritative' or 'trusted' hash.
- rkagerer 6y agoSoftware management on Windows is such a mess. After decades of opportunity for improvement, it's largely gotten worse. Uninstall is too often a myth, and the majority of programs out there leave bits and pieces behind. These add up over time to bloat your registry, disk, kernel drivers, etc, degrading the performance and reliability of your computer. Multiple conventions for where things go makes it difficult to track down the bits. (Program Files? (x86)? AppData\[Local|LocalLow|Roaming]? SteamApps\common? ProgramData? System32/SysWOW64? Dozens of registry locations?) So many installers require unfettered, administrative access to my computer with little indication of exactly what they intend to do (Litter my desktop with new shortcuts? Add shell hooks? Install a rootkit?) and no opportunity from the OS to consent your partial permission or retroactively examine the changes. (Don't miss that popup balloon about a new driver! Have fun parsing through all the noise in your event logs). Even simple chores like managing file type associations became more painful somewhere along the way. There's a reason professionals so often fall back to advising a reformat. Makes me miss the days when your program went someplace like C:\PHOTOSHOP and most everything for it was contained within. It's easy to point fingers at individual software publishers (I've called out some incompetent ones) but mostly I blame Microsoft for failing to evangelize rigorously thought-through best practices and provide better tooling to make it dead easy for developers to get it right. I might be wrong about this, but the preview looks like a gimmick for finding and running installers. I would have liked to see improved methodologies, packaging tools, and end-user empowerment announced alongside it. Hats off to folks like Nir Sofer and Mark Russinovich who've shown the world just how much you can pack into a small, single-file, zero-installation EXE that just runs when you click it. I've been using the same computer for 10 years now (with upgrades to components like video, RAID controller, SSD's) and have over 700 programs installed on it. I use third party monitoring software [1] to capture a disk and registry snapshot before and after any installation (and often on updates). The machine is still nearly as snappy as the day it was built (yes, I benchmark!), but it's taken a LOT of ongoing work to keep it that way. I use other tricks, like locking down certain registry keys and folder locations which programs like to pollute (or where that causes breakage, using startup scripts to clean them out after the fact in a cat and mouse game). One big win was completely giving up on My Documents. I treat it like just another AppData, and organize the content I really care about elsewhere. All that said, I really like that my Windows software still comes directly from the vendors. I'm not sure how I feel about distribution becoming more centralized under Microsoft's control. Part of me hopes to see a vibrant ecosystem of third-party repos emerge, while another part dreads the confusion about where to get a package that may entail. I do have to give Microsoft credit for enabling third party tools to take care of some of the shortfalls they haven't. On more locked down platforms that's been more difficult. [1] https://www.martau.com/ https://www.martau.com/
- alexeiz 6y agoFrankly, this is a very lame attempt at the package manager. All it does is download installer executables and run them. There is no ability to list installed packages, neither is the ability to uninstall. Where's the actual package management functionality? Both Scoop and Choco are way better than this.
- akandiah 6y agoIs this an msi hiding in a wrapper? Anyone who has dealt with the innards of an msi file knows it's a dog's breakfast!
- milkthefat 6y agoMost of the responses here do a really great job at pointing out the flaws of this project. My biggest gripe is it currently has no plans to be integrated by default. So just like all the other package management tools for windows the tool itself is a prereq requiring another hoop. If I have to deal with more configuration management to install this from the app store I’d rather use chocolaty at least that can be installed reliably.
- Ari_Ugwu 6y agoMaybe the most exciting thing I've heard so far from Build 2020. Getting Closer to my dream install: * WSL 2 * VS Code * .NET 5 * Windows Terminal * Package Manager * Edge All that's missing is Edge on Linux and letting me write cross platform apps that use edge as a (headless) common runtime.
- eat_veggies 6y agoGiven that edge is just chromium now, I'm curious as to how an edge headless runtime would differ from node or electron