9 ms·
Npm Private Modules
- mts_ 11y agoEverything looks pretty awesome, except the payment model. I'm a little surprised they didn't go with a model similar to GitHub: - Payment plans with X number of private modules, or $1/month per private module - Unlimited paying/non-paying collaborators for private modules (perhaps only read access for non-paying) With npm's model all my collaborators will have to pay for npm private modules as well.
- substack 11y agoCharging per-module like github would encourage people to author fewer packages and to lump more functionality into the same package, which goes completely against the ethos of npm and the spirit of tiny abstractions that do one thing well. The way that npm has structured things, programmers pay once for membership in a commercial tier, where presumably money is already changing hands to work on private code. I think this makes much more sense and won't bias the code itself in a negative direction.
- mts_ 11y agoThat's a very good point! I hadn't thought of it from the point of encouraging/incentivizing the authoring of more public packages. But couldn't the current model then discourage the authoring of public packages, and lead people to start primarily publishing private packages. I assume whatever reason people are authoring public packages today won't change because they get a paid account. Let's at least hope that's the case.
- thedufer 11y agoSounds like a big pain to have to pay individually for each person on a team if your company wants to use private modules. We're generally willing to throw money at problems like those private modules solve, but if we have to do it a dozen times it probably isn't going to happen.
- skrebbel 11y agoDoes anyone know whether the open source NPM implementation allows me to implement and host my own private repository system without forking npm? Or is npm (and thus node and iojs) hard-tied to npm, Inc's proprietary offering for private modules?
- amelius 11y agoHave a look at the sinopia package. You can run your own server on your own machine (without costs).
- substack 11y agoYou can configure different registries on a global and per-scope basis: https://docs.npmjs.com/misc/scope#associating-a-scope-with-a-registry https://docs.npmjs.com/misc/scope#associating-a-scope-with-a... Some of the other commercial npm hosts and open source offerings already support scoped packages.
- skrebbel 11y agoOh wow, I'm so behind the times :) great, and thanks! Ok in that case I hereby officially really like the way npm Inc are working on monetization.
- altcognito 11y agoNexus serves NPM packages, Ruby GEMs, YUM packages and also serves as a Maven repository. https://books.sonatype.com/nexus-book/reference/npm-configuring.html https://books.sonatype.com/nexus-book/reference/npm-configur... Source code: https://github.com/sonatype/nexus-oss https://github.com/sonatype/nexus-oss
- Roboprog 11y agoThat was my first thought on reading the business plan: it sounds like the "nexus" tools used with Maven. I suppose if you are not using Maven, though, a custom tool integrated with the Node toolchain would be more comfortable.
- 11y ago
- amelius 11y agoI recently got interested in nodejs. However, then I discovered that: 1. It doesn't support threads (facilitating structural sharing of large data-structures between parallel tasks, which cannot be done using ordinary processes). 2. The module-loading mechanism ("require()") natively doesn't support delayed loading, which is needed when loading from within a browser. Yes, there is the "browserify" package, but, come on, something as basic like this should be supported out of the box. Especially considering the fact that there is a "http" module hardwired inside nodejs (why isn't this a separate npm module, btw?) 3. To make my own privately held modules and install them properly, I have to run a npm server? This seems like an awful lot of work for something as basic as this. Ok, so now I can use the cloud for this, but come on, I should be able to do this just from within the filesystem, like e.g. git does it. For people interested, one can use the package "sinopia" for hosting your own private modules. It seems to be a pretty decent package, but be aware that the authentication settings out of the box are completely insecure.
- deleted 11y ago[deleted]
- lost_my_pwd 11y agoOne can also install modules from a git repo, from which access to the module can be controlled in the regular git fashion: "dependencies": { "private-module": "git+ssh://..." } or: "dependencies": { "private-module": "git+https://<user>:<password>@..." } If one chooses to use Github, there is also the option to use an auth token in the url scheme instead of needing to distribute an SSH PK (bad) or having login credentials in the package.json: "dependencies": { "private-module": "git+https://<token>:x-oauth-basic@github.com/<account>/<repo>.git" } One could also just have a folder of private modules mounted from some shared file server or whatever. An NPM server is not an absolute requirement to use npm.
- TomFrost 11y ago1. Node.js is (for the most part) single-threaded; that's its draw. It's not trying to be a swiss army knife, and if your use case requires a threaded language then Node.js certainly isn't the tool for that job. But it might find a useful place in your toolbox for other tasks. 2. require() is part of the CommonJS spec, and how it physically works is dependent on the implementation. You point out that Node's implementation doesn't work well in the browser, but Node itself does not work in the browser so that point is moot. I agree that it might be interesting to load remote modules in Node, but keeping that operation synchronous does simplify the language quite a bit. 3. You can also map modules to public or private git repositories in the package.json, as long as the private key used during npm install has access. If the git repo has tags, a tag can be specified in the git uri as well. Private npm repos are the superior way to distribute private modules with wider access, but I think this is handled fairly cleanly already.
- archgrove 11y agoWe're already using "private" modules, by hosting them in a private git repo. NPM can install from these, e.g., git+ssh://user@server:Account/Repo.git, without problems. I'm not sure what value this would add for us, and the URL doesn't sell me well on it.
- seldo 11y agoWe're glad private repos work for you :-) However, the overwhelming feedback from our users has been that git dependencies are a gigantic pain in the neck, and this has been our own personal experience as users of npm. Much like npm itself, we are doing something you could do without npm, it's just much easier with npm, and we hope that reduction in friction is valuable :-)
- thom_nic 11y agoIs it modeled strictly per-user or is there any notion of an "organization" similar to Github? It's hard to imagine a business having to manage paying for a bunch of individual accounts so they can have access to the company's private repo.
- mts_ 11y agoOrganization accounts are coming soon: Currently, private packages are only available for individual users, but support for organization accounts is coming soon. Feel free to create a user for your organization in the meantime, and we can upgrade it to an organization when support is here. https://www.npmjs.com/private-modules#organizations https://www.npmjs.com/private-modules#organizations
- warfangle 11y agoNPM Enterprise is a potential solution. You have to host it yourself, but it gives you namespaced modules and the option of selectively mirroring the public registry.
- Touche 11y agoI take this to mean you won't be improving git dependencies then.
- kennethh 11y agoSuggestion, add a pricing link? I usually do a ctrl-F to search for pricing in a service like this, make it easier for me to find.
- NietTim 11y agoIf anybody else is wondering, it costs $7 per month (per user)
- jazzcar 11y agoi just find my ansewr here www.jazzcar.net
- talles 11y agoIf anyone is wonder the pricing like me just head to the home page: "publish unlimited private modules for just $7/month". Here's a question: people with read-only access (to my private packages) have to be paid users too?
- LukeB_UK 11y agoFrom the page: > Give read access or read-write access for those packages to any other paid user
- talles 11y agoMy bad, I completely missed that. So in the end is $7 per user, you can't have just one paying user publishing for everyone else. I guess I'll have to wait for organizations accounts for now.
- BinaryIdiot 11y agoSo this reads to me that they're simply not going to update the ability to use GIT. Right now you can point to a repo or specific branch / tag but it doesn't read any of the versioning like bower does, so it can't handle versioning properly. If they updated the use of GIT you could completely eliminate the need for this feature. That kinda rubs me the wrong way; it feels like they're trying to force this monetization as they've had plenty of us from the community wanting better GIT support for this very reason. Honestly npm isn't a very complex piece of software, you could even replace it with bower if you want git with versions. I wonder if any competitors are going to spring up who can simply iterate faster. I won't even get started on their login system, ugh.
- warfangle 11y ago> Right now you can point to a repo or specific branch / tag but it doesn't read any of the versioning like bower does, so it can't handle versioning properly. You can even point to a specific commit hash. But no, it doesn't read any of the versioning. What if two different branches have the same version number? The publish step is pretty important, because ... > If they updated the use of GIT you could completely eliminate the need for this feature. ... You'd still miss out on the prepublish hook - one of the major reasons I've looked into using NPM Enterprise. Sometimes your package needs to do some housekeeping _before_ you publish, and the files generated by that should be distributed -- but not checked into source control.
- Touche 11y ago> You can even point to a specific commit hash. But no, it doesn't read any of the versioning. What if two different branches have the same version number? The semver mechanism would be based on the tag, so it would not work when pointing to a specific commit hash (and you wouldn't want it to). > ... You'd still miss out on the prepublish hook - one of the major reasons I've looked into using NPM Enterprise. Sometimes your package needs to do some housekeeping _before_ you publish, and the files generated by that should be distributed -- but not checked into source control. That's a nice feature and all but not required to have proper git support.
- 11y ago
- jbob2000 11y agoI'm fearful of where this monetization is going. Part of what I like about npm is that everything is free, from the dinky little packages that do one thing really well, to the monumental ones that provide a host of functionality. I would hate if NPM went the way of wordpress plugins, where every stupid little plugin costs $5 to access.
- laggyluke 11y agoAnd now it's down: http://status.npmjs.org/ http://status.npmjs.org/
- laggyluke 11y agoAnd back up, but you can see a dip on charts.
- laurencerowe 11y agoThe Python equivalent to this is to simply place your source release tarballs on a simple private web / filesystem directory: pip install --find-links http://dist.example.com/packages/ This also makes it simple to mirror all requirements locally for more reliable installs. I wish I could do the same with npm.
- nabaraz 11y agoI might have missed the obvious but what is the difference between this and hosting your own private git repository?
- joesb 11y agoIMHO, tying language's defacto package management's capabiity to a single company's business model may hurts node. No other language does this. you have all the same capability for propretary package with RubyGem/Python/Nuget, even Ubuntu allow you to add third party package repository. It gives me the clue that npm may no longer improve, or many improvement will be "premium" feature. I hope someone fork npm and add ability to parse semver from tag for github repo.
- yellowapple 11y agoSomewhat off-topic: "NPM Private Module" would be an excellent recursive acronym.