4 ms·
(I helped make the case internally at Shopify.) The key points we emphasized are in the Ruby Shield announcement, but to summarize: - Attacks on supply chains
by flavorjones 4y ago
(I helped make the case internally at Shopify.) The key points we emphasized are in the Ruby Shield announcement, but to summarize:
- Attacks on supply chains are way up
- Use of open-source software is way up
- Shopify is already contributing engineering time to bundler and rubygems.org
- And there is additional shovel-ready work that Ruby Central could execute on with a financial contribution.
Proactive security work now reduces the chances of a successful supply chain attack and the costs associated with recovery, investigation, and mitigation in addition to reputational damage.
There are secondary benefits, too: when we're confident in the supply chain, we can more confidently update our dependencies in a timely fashion, meaning our developers have access to the newest library features; and we're able to patch known vulnerabilities faster. We invest a lot in feedback loops internally, and this is just another facet of that build/measure/learn cycle.