deanc
7 hours ago
I don't agree with everything that Homebrew does, but the primary maintainers are visible, vocal and very opinionated. They have shown credibility and earnt my trust over the years given it is a crucial entry point to potential malware to my system.
Homebrew has continued to improve performance each major version. It's certainly a lot quicker nowadays than 5 years ago. I want reliability and safety in a package manager, speed is nice to have.
I applaud competition, but something like this starts with trust zero as far as I'm concerned. If there is one place that I want human input over LLM it's here. It needs to scream: smart humans are in control and overseeing the project. I don't see that here.
codetiger
6 hours ago
100% agree on your comment. For a package manager, speed is aspiration but security and reliability are basic requirements. And the credibility is a big plus. Today anyone can build a package manager in a week with AI, but once the system grows, how is the team going to manage? This is where credibility matters.
unsnap_biceps
4 hours ago
Honestly the latest speedups have brought it fast enough that I no longer really notice it anymore.
eviks
5 hours ago
> If there is one place that I want human input over LLM it's here. It needs to scream: smart humans are in control and overseeing the project. I don't see that here.
How is Homebrew fundamentally different (as of today) - they vibe code. For example, the new app BrewUI is vibe coded, Claude is #2 contributor.
Does this scream "smart humans"?
saagarjha
5 hours ago
I don't see what is unreasonable about vibe coding an optional GUI for your package manager
eviks
5 hours ago
It doen't align with "your" principle of "If there is one place that I want human input over LLM it's here."
saagarjha
5 hours ago
Yes, but the point is that the humans made the choice to apply it to something that is of low importance and not core to the project.
eviks
5 hours ago
That wasn't the point, and it's also a fundamental mistake to think that the app store app for anapp store is of low importance, but also it doesn't resolve anything - if it's "a crucial entry point to potential malware to my system." how does it help that it's an entry point to a smaller part of your user base? And if that's just fine, what principle would stop the vibes from permeating "the core"??? The core also has llm contributions
anonreplier
4 hours ago
The point you are ignoring or missing is that the homebrew maintainers have earned the trust to use AI contributions and have not simply whacked out a 100% vibe coded app in a week.
eviks
4 hours ago
That's another made up point not coming from the source. But also, that's almost literally what they did. Ok, it wasn't in a week but a few months and the % is not 100%, but still more than 50% But then this project's first release was in Feb, so it's actually been longer in development than the brew UI app! It's not a 1-week app! Stop making hypothetical stuff up, look at real apps
anonreplier
3 hours ago
This isn't just a replacement for the homebrew UI, it's for the CLI too, so comparison invalid. I see the dev behind it has a whole 4 years of github experience - only the most recent 2 of which with anything significant (presumably model written), how reassuring.
eviks
19 minutes ago
The comment you originally replied addresses the "invalid" comparison, so circle back there. And you have the same issue here - how does "years of github experience" connects to concerts about LLM output in security-critical package managers?
cpursley
4 hours ago
Yes, using tooling is literally what differentiates humans from the apes. Claude and the like are just the next evolution of tooling. BrewUI looks fine to me and I certainly prefer it (as it's native) over all the "hand-crafted" node/electron dumpster fires. If you want to continue to rub sticks together to make fire, nobody is stopping you (except perhaps the market).
eviks
4 hours ago
No, you have a primitive understanding of evolution. Apes literally use tools. And if you want to play with AI fire in the "crucial entry point to potential malware to my system", nobody is stopping you either (even if you trust your own ringing security endorsement of "looks fine to me"), but that would still not address the core point of this discussion
lrvick
an hour ago
Maybe Homebrew is reliable, but do not assume it is safe. It has always operated on the honor system for contributions and code review. Every maintainer is able to merge anything they want without review or signatures. No matter how good their intentions, Homebrew is a massive supply chain attack waiting to happen.
gentlerain
5 hours ago
The biggest challenge with all these new packages coming up is support for edge cases and maintainability over the years.
AI may make it easy to clone or port something to a new language but it will later need a dedicated human to put in a shift and fine tune it.
So unless you are ready to keep jumping to the newest, it's better to stay with the trusted for now.
tacker2000
6 hours ago
Smart humans?
Is it smart to deprecate everything the minute Apple sunsets their OS version?
This is not a smart package manager, its a manager for the “dumb” masses, that need to be saved and protected from themselves by forcing them into the next walled garden, so to speak…