Microsoft announces official Windows package manager. 'Not a package manager' users snap back
- Reference: 1589989105
- News link: https://www.theregister.co.uk/2020/05/20/microsoft_announces_official_windows_package/
- Source link:
Announced at the (virtual) Build conference under way now, the imaginatively named Windows Package Manager is for installing applications, rather than components for developers, for which there are solutions like [1]NuGet and [2]NPM .
Among the best features of Linux is the availability of package managers, such as Debian's Apt, that can install, remove and manage dependencies for applications from the command line. It is not perfect – dependency version issues or broken configuration files can be a problem – but most of the time it makes it easy to get what you want, and is scriptable. Many users would like Windows to be equally convenient to use.
Microsoft has reinforced its relatively newfound love for the command line by introducing [3]Windows Package Manager which lets you install packages from repositories. The default repository is called the [4]Community repo . Malware is a concern, and the company said: "we leverage SmartScreen, static analysis, SHA256 hash validation and a few other processes to reduce the likelihood of malicious software making its way into the repository and onto your machine."
A quick look at what is currently available shows a range of applications including 7Zip, AWS CLI (Command Line Interface), Azure CLI, Discord, Dropbox, KeePass, Git, Inkscape, TreeSize, LibreOffice, PowerToys, SQL Server Management Studio, Gimp, Visual Studio, Firefox, Spotify, Zoom and many more. You can search for packages and validate hash values, a useful check against tampering. You can also add third-party repositories, though none yet exist. When generally available, it will support Windows 10 version 1709 and later.
[5]
Some of the packages available in the Windows Package Manager
Getting to those issues, the first that comes to mind is: why has Microsoft created a new package manager rather than using an existing one? Alternatives include [6]Chocolatey which says it has over 7,700 packages and over a billion packages installed by users?
"There were several reasons leading us to create a new solution, Microsoft's senior Program Manager Demitrius Nelon said.
These are mainly to do with the security of the community repository, though he said there were unspecified challenges around "delivering the client program as a native Windows application." He added: "If you are happy with your current package manager, keep using it."
More seriously, the current preview is limited to installation; it does not even have a remove option for packages. It does not auto-update packages or even have any mechanism to update them, and there is no specific dependency management. On the [7]to-do list are features including uninstall, update, and Store app support.
These problems have led to a [8]fundamental issue raised on the WinGet GitHub repository, titled: "Not a package manager." The poster opined: "All it does is downloading installers (which are not packages) and executing them (which is not management)."
Group program manager Andrew Clinick [9]replied that WinGet is a response to requests for "the ability to script what is required to setup a developer machines" and that the real solution to Windows package management is in [10]MSIX , the preferred deployment method, but that WinGet cannot afford to exclude other types of install, since many applications do not yet support MSIX. "Once you're in MSIX we can keep the app up to date, uninstall cleanly plus understand what dependencies are required," he said.
Windows is always in transition, but reaching the point where MSIX is sufficiently well embedded to enable satisfactory package management still looks some way off. There is also the issue of paid-for applications which WinGet does not currently address.
WinGet can be improved, but getting it to work in the way it should depends on the evolution of Windows itself. ®
[1] https://www.nuget.org/
[2] https://www.npmjs.com/
[3] https://devblogs.microsoft.com/commandline/windows-package-manager-preview/
[4] https://github.com/microsoft/winget-pkgs
[5] https://regmedia.co.uk/2020/05/20/winpackage.png
[6] https://chocolatey.org/
[7] https://github.com/microsoft/winget-cli/projects/
[8] https://github.com/microsoft/winget-cli/issues/223
[9] https://github.com/microsoft/winget-cli/issues/223#issuecomment-631224512
[10] https://docs.microsoft.com/en-us/windows/msix/overview
Re: One software manager to rule them all!
If I understand correctly, historically Windows has taken a slightly more MacOS-esq approach of assuming apps will redundantly install various versioned copies of libraries in their local Program Data (or .App) directories - rather than orchestrating shared ones (which bigger Linux distributions have the luxury of being able to coordinate. Would that make this more of an MSI-on-steroids rather than a "traditional package manager"?
Not sure myself yet.
One of the things I dislike about the way it's done on Linux is that it places a heavy emphasis on a distro adopting a piece of OSS software and including it in their repositories. Ok, for the able Penguinista it's perhaps not so difficult to use cmake or, heaven forbid, ./configure to build from source. But it's at that point where you've pretty much lost the un-*nix-savvy user. Even if a software developer chooses to go to all the phaff of maintaining packages for all the myriad different systems out there, it's still beyond the un-*nix-savvy user to add the software developer's repos to their apt, or yum, or dnf, or snap, etc setup.
The duplication of libraries thing: in my view its swings and roundabouts. Just this afternoon I've been needing an older version of the lexxer generator Flex. And, with Ubuntu / apt, finding and installing an older package version is an absolute nuissance. Microsoft's way does at least make this kind of thing totally trivial; you just uninstall the new version (though even that's not totally necessary, it's down to the app and how it manages its install), install the old, et voila you're off and away.
Also, with a large distro-centric package repository there's a need for each and every application within it to be built against the versions of libraries that are chosen for it. This has never been achieved 100%; dig around in some of the more obscure corners of a repo and its generally quite easy to find something that, though all dependencies are claimed to have been met, has been packaged up with the wrong dependencies for that particular version of the app.
Also, I'm just not convinced that storage is, generally speaking, sufficiently scarce to warrant a package management system that strives to ensure that the bare minimum of space is taken up by shared libraries. It's not exactly resulting in a modern full-fat Linux distro being anything less than a few GB installed. With a lot of software these days what takes up space is all the pretty bits - bitmaps and such - and they're generally not shared between applications anyway. Mass market IoT stuff in priinciple benefits on price from efficient use of storage space, but then again how much of that stuff is actually updated ever, anyway?
Anyway, it's sounding like MS have realised that getting rid of application installers ("Use the MS Store") was a bad idea, and is undoing that somewhat. Good.
Why not use an existing Package Manager?
Are you mad?
You WILL do things the Microsoft way or not at all. That is the Microsoft Way, the world masters of NIH.
Oh, and they'll change the package format with each and every update. /s /s /s
Yet more proof that MS invent nothing, perhaps it is time to start doing unto MS what they did to their competition?
WinGet is a response to requests for "the ability to script what is required to setup a developer machines"
So, Ansible, but Invented Here.
Cough, Splutter, Gasp
From the article:
Among the best features of Linux is the availability of package managers, such as Debian's Apt, that can install, remove and manage dependencies for applications from the command line.
Also among the very worst features of Linux distros is the availability of FAR TOO MANY DIFFERENT PACKAGE MANAGERS.
That is all.
snap
"snap" is not the most fortunate word to use in this context ... if it was intentional it causes too much pain :)
One software manager to rule them all!
Oblig. xkcd references... https://xkcd.com/1654/ and https://xkcd.com/927/
I'd like to see Microsoft improve on chocolatey, if they insist on doing it themselves.
Chocolatey was a revelation for me, coming from a yum/apt background.
If I understand correctly, historically Windows has taken a slightly more MacOS-esq approach of assuming apps will redundantly install various versioned copies of libraries in their local Program Data (or .App) directories - rather than orchestrating shared ones (which bigger Linux distributions have the luxury of being able to coordinate. Would that make this more of an MSI-on-steroids rather than a "traditional package manager"?
But if it comes pre-installed, is GPO friendly, and allows securely and reliably pulling things like Notepad3 and Chrome from their respective github/3rd party mirror locations - I'm up for giving it a go...