17 ms·
Ruby core team takes ownership of RubyGems and Bundler
- dorianmariecom 1y agoso we get namespaces for gems?
- xbar 1y agoThank you Matz.
- sebiw 1y agoI think this is the right move. Thank you to Ruby Core and Matz for stepping up and providing stability to the language and community as a whole.
- delichon 1y agoMatz is a pillar. Remember "Matz is nice and so we are nice"? s/nice/nice and responsible/gc.
- sam_lowry_ 1y ago[flagged]
- binary132 1y ago[flagged]
- deleted 1y ago[deleted]
- dudeinjapan 1y agoSurprised to hear this, have been a Rubyist for many years and never felt this way about community as a whole. Come to Ruby Kaigi in Japan sometime!
- sebiw 1y agoI don't like talking about a heterogeneous group of people in a generally negative way. I try to stick to the people I perceive as sharing the same values that are important to me. And there are many such people in the Ruby community.
- deleted 1y ago[deleted]
- ryandv 1y ago> I don't like talking about a heterogeneous group of people > many such people in the Ruby community. In which case, this presumes that the values you share with the Ruby community are positive - otherwise you would be talking about this heterogeneous group in a generally negative way. This would appear to beg the very question under contention - that the values of the Ruby community are not in fact positive, but toxic; unless you wish to argue that a community can simultaneously profess positive values and still exhibit toxic behaviour. One position offers historical (and current) examples; the other offers an impressive feat of linguistic gymnastics.
- deleted 1y ago[deleted]
- s0sa 1y agoI think that viewpoint says more about you than it does the Ruby community.
- the_mitsuhiko 1y ago> Remember why the lucky stiff? I remember _why and I definitely don't remember him as toxic.
- sam_lowry_ 1y agoWasn't his identity revealed while he wanted to remain anonymous?
- gcr 1y agoPerhaps OP meant that _why was a victim of toxicity, rather than a purveyor of it?
- the_mitsuhiko 1y agoMy recollection is that some people in the community knew his identity. His sudden disappearance invited a lot of people to dig into it, many of which were not even Ruby people to begin with. There was even a newspaper article written about him years after. I would not attribute all that digging to the Ruby community. If anything I remember people being very respectful at the time.
- davidgerard 1y agothe one from Bluesky with the public real name? That one's literally a vibecamp neoreactionary, so ...
- the_mitsuhiko 1y ago_why isn't publicly active since his disappearance.
- deleted 1y ago[deleted]
- davidgerard 1y agoyes, I'm completely in error, sorry!
- runjake 1y agowhy’s identity reveal had nothing to do with the Ruby community. A random bad actor posted his personal details in a blog post. The Ruby community respected his pseudonymity. Some of us already knew his name.
- shevy-java 1y agoIs that a religion now? The pickaxe guys coined it. People repeat it without thinking about it. If matz were to say "jump from the bridge", people would do it, because matz is nice? Just to point out: I do think matz is nice and a great language designer. That in itself doesn't mean anything. Why would I proxy my own decisions based on any mindless slogan? That makes no sense. Why do people in the ruby ecosystem keep on repeating those pointless slogans?
- ubercore 1y agoI think it's pretty obvious to see the difference between being nice and jumping off a bridge? Curious why this cute phrase bothers you so much.
- vidugavia 1y agoThe phrase has been weaponized in the past many times. Some figures in the community are almost as far from "nice" as possible, but you're not allowed to call that out, because "it's not nice".
- zahlman 1y ago> but you're not allowed to call that out, because "it's not nice". I don't know about the Ruby community, but I've seen this sort of complaint made about many other online spaces (including HN) and my general finding is that it simply isn't true. The problem is that for a proper call-out, both form and content matter, and most people in a mindset to make call-outs don't seem very interested in norms surrounding either of those things. Especially the part where part of good form is accepting that not all kind, well-meaning people have the same moral values and calculus.
- fba11837 1y agoTry calling out Python's inner circle politely while they are openly rude to you. You do know that you also have keep up the pretense of Kim Yong Un as a glorious and benevolent leader even if he imprisoned some of your relatives. This is a response to your generalization, I do not know anything about Ruby politics.
- joeldrapper 1y agoThese projects were not Ruby Central’s in the first place. They were stolen for Ruby Central by a Ruby Core insider, HSBT. This is horrible news. They were stolen from André Arko, Colby Swandale, David Rodríguez, Ellen, Josef Šimánek, Martin Emde and Samuel Giddins.
- CaptainOfCoit 1y agoSo what? NPM wasn't originally owned by Microsoft, nor GitHub, but reality moves forward? As long as Matz is involved, I have a lot of faith things will get better, not worse, unless you have some strong indication of otherwise. If anything, because things will be nicer.
- joeldrapper 1y agoSo it’s okay for Matz to get HSBT to steal people’s open source projects? What if Matz sponsors stole Ruby from him? WTF?
- rich_kilmer 1y agoI was one of the originating authors of RubyGems along with Jim (RIP), Chad, David and Paul. I hosted RubyGems from my home for the entire community for many years. We never asked nor received anything for that. We wrote RubyGems for the Ruby community. Matz and the Ruby Core team is the right place for RubyGems. This is great news.
- sebiw 1y agoThanks for sharing. RIP Jim, I miss him being part of the community.
- the_mitsuhiko 1y ago> So it’s okay for Matz to get HSBT to steal people’s open source projects? Where is the theft? The projects were open source, they are still open source.
- IshKebab 1y agoIs this without the consent of Ruby Central? Sounds like some kind of hostile takeover! Edit: Seems like maybe a hostile take-back actually.
- dismalaf 1y agoRuby Central also announced it on their site.
- elliotec 1y agoThis is a fascinating and seemingly unusual development that will look obvious in history. I find “BDFLs” and open source communities so incredibly interesting. Especially in the context of geopolitics and state entities. Linux! This stuff is PHD material for sociology and polisci post-grads and I’m so interested in following the progression of history with these types of things.
- shadowgovt 1y agoI think you're absolutely right. We are starting to reach the age where a combination of large cooperative non-corporate tech projects and the Internet (that, partially at least, enabled them) are putting us in a place where the actual mortality of project owners matters. The "L" in BDFL is a finite constraint. I think there's going to be an interesting and complicated churn as several major projects under the BDFL model have their Ds succeed at passing the torch, struggle to pass the torch, struggle to realize the torch needs to be passed, or take the torch and do their best to burn the whole project down so it can't outlive them.
- gus_massa 1y ago> I find “BDFLs” and open source communities so incredibly interesting. Especially in the context of geopolitics and state entities. Linux! The diference is that with an open source licence, the comunity can just fork the project (assuming they have enough developers), so the BDFL must master the art of herding cats. A country has clear phisical borders and tanks, and people can't fork them and ignore the old power structure.
- undecisive 1y agoYeah, certainly tickles a few neurons. I feel like BDFLs are akin to the concept of village elders; they're not immune to corruption or scandal, but they often have this beloved status that can paper over a lot of cracks. That's probably dependant on their leadership style - the hard headed (Linus, DHH) vs the grandfatherly (Matz, Van Rossum). Which, going back to your note on geopolitics, leads me to wonder: Is it just that more power corrupts more, or is it that (modern-day definitions of) democracy require a desire for power? I guess as the "FL" part of "BDFL" comes to bite more of the communities, we'll see better how different succession styles have different effects. I also wonder if the analytical nature of the individuals within the "populations", and inability to police defectors will mean uprisings will be more successful, either in causing BDFL attitude adjustments, or just overturning the community completely (for example, there's already a lot of momentum for a complete fork of Rails) (Edit: having submitted this, I now see others have had very similar thoughts! Definitely an excellent conversation topic)
- white-moss 1y agoReally appreciate Matz stepping up to take on this difficult situation. As a Japanese developer, I’ve been worried about the direction things were going, so it’s reassuring to see this.
- shevy-java 1y agoStepping up how? It was always clear that Hiroshi Shibata didn't act solo without approval. I am not saying he knew the outcome before that, but WHEN was the decision made to take over gems + bundler? I have a slight suspicion that this may have been decided upon months ago already. > As a Japanese developer, I’ve been worried about the direction things were going, so it’s reassuring to see this. I am actually much more worried now. I don't live in the USA; I don't live in Japan. To me it seems as if Japan and the USA are totally over-dominating in the ruby ecosystem. While this is understandable that it is Japan (local community, I get it, this is different to english-speaking ones), I am absolutely upset that the USA has so much proxy-influence here. But I guess there is nothing that can be done. I guess in Python the USA also over-dominates. I just think this sucks really.
- dudeinjapan 1y agoShopify is pretty much dominating the Ruby ecosystem. It’s Canadian tho :)
- dismalaf 1y ago> I am actually much more worried now Why? Japanese culture is more conservative, less prone to knee jerk decisions, and Ruby is their biggest home grown programming language. I'm also not American nor Japanese and I think this is the best possible outcome.
- xg19837 1y agoYes. At least Ruby was always strongly Japanese though. In Python European and Asian developers are overtly exploited, with U.S. corporations and their employed stooges holding the reins of power. I'm considering switching to Erlang, which was developed at a corporation from the start and appears to be drama and cancel free.
- dluan 1y agoIn the long run, having multiple sources like gem.coop is probably a safer and more robust solution. But for RubyGems specifically, the trust was fully lost, through several layers - maintainers, community members, sponsors, etc. There's still open questions that probably need to be resolved like the funding and data privacy stuff, but I think most folks in ruby land will be supportive of this.
- lyu07282 1y agoThis is just the tooling though, not "rubygems.org" which is still owned by a hostile entity (depending on where you sit on this), so not sure how this would restore any trust?
- rich_kilmer 1y agoAs a co-author of RubyGems and one of the original Board members of Ruby Central, they are not a hostile entity. They are the entity that we gave stewardship of RubyGems and we/they have hosted it for its entire existence.
- lyu07282 1y agoIt goes without saying that Ruby Central doesn't think Ruby Central has ever lost any trust to begin with.
- monooso 1y agoI don't have a dog in this fight, but the discussion is about the phrase "hostile entity", not about a loss of trust.
- lyu07282 1y agoThat really doesn't matter. I think what happened could be described as "hostility" towards the community, that's what my impression was, it was appearing like a hostile takeover of the github repositories/organization with no discussion, no community involvement, no transparency. Obviously not everybody will agree especially not people working at Ruby Central.
- binary132 1y agoDecentralized package hosting is the only way.
- __float 1y agoWhat languages do you use that have adopted this well? I'm not counting something like C++ where there's effectively no "packages" to speak of.
- voxic11 1y agoGo has decentralized package hosting and it works reasonably well. Deno does also but I'm less clear on well how that is working out for them.
- delfinom 1y ago>Go has decentralized package hosting and it works reasonably well. All go package imports are proxied via Google. https://drewdevault.com/2022/05/25/Google-has-been-DDoSing-sourcehut.html https://drewdevault.com/2022/05/25/Google-has-been-DDoSing-s...
- lcnPylGDnU4H9OF 1y ago> (you can set GOPROXY=direct to fix this) https://drewdevault.com/2021/08/06/goproxy-breaks-go.html https://drewdevault.com/2021/08/06/goproxy-breaks-go.html Not that defaults don't matter, just offering the extra detail. And, as the post goes on to explain, this change seems to cause its own set of dependency issues.
- monooso 1y agoThe Deno people recently released jsr.io, "a modern package registry for JavaScript and TypeScript." I'm not familiar with the technical details, but at first glance it appears pretty centralised.
- 1y ago
- andsmedeiros 1y agoSo Ruby Central will still be running rubygems.org?
- byroot 1y agoSeems so yes https://rubycentral.org/news/ruby-central-statement-on-rubygems-bundler/ https://rubycentral.org/news/ruby-central-statement-on-rubyg...
- shevy-java 1y agoSadly yes. They probably have no other choice, because what else would they do with their time? Do the unthinkable and create gems other people would use? That would be too much work.
- byroot 1y agoRuby Central side: https://rubycentral.org/news/ruby-central-statement-on-rubygems-bundler/ https://rubycentral.org/news/ruby-central-statement-on-rubyg...
- gcr 1y agoFor context, also check out their previous statement from September 19, which also "reflects our shared commitment to the long-term stability and growth of the Ruby ecosystem" [sic]: https://rubycentral.org/news/strengthening-the-stewardship-of-rubygems-and-bundler/ https://rubycentral.org/news/strengthening-the-stewardship-o...
- shevy-java 1y agoThey keep on using buzzwords. These Ruby central guys never maintained a single gem used by many people in their life. I have no idea what they are writing, but it feels as if AI is writing their statements. Even then it is of such a poor, repetitive quality that even AI may just accidentally write better "summaries". People lost all trust in Ruby Central - there is no way for them to win back trust here. IMO it would be better to start from a clean slate; dissolve Ruby Central and bring back the community with a new policy, rules - but that's not going to happen. Ruby Central went the corporate way and that's it. It would just be ironic if, say in 10 years, gem.coop proves to be much more successful whereas Ruby Central still writes the same AI-generated text ("we care for the community even if everyone is now elsewhere already").
- the_hangman 1y agoAfaik many of the people who were on board to help start gem.coop have stepped back after the recent controversies with Andre Arko, at this point I don’t think it will ever be anything more than a ruby gems mirror
- florkbork 1y agoI sincerely doubt this without a source
- mikemcquaid 1y agoAs someone who spent a bunch of time talking before and after this all went down with current and past RubyGems maintainers, RubyCentral employees, Gem.coop maintainers and Ruby Core folks: this seems like the best outcome that was actually attainable. I've been working on Homebrew for 16 years and leading it for some proportion of that and this all "smells" like a more sustainable long-term solution than anything we've seen happen in the last year. Some proposals sounded nicer but were not going to be acceptable to one or more sides. Ruby already provides a vendored version of RubyGems and (more recently) Bundler so this seems appropriate. It also separates the "running a web service" which has guaranteed hosting costs, requires on-call, etc. from "running an open source CLI/library" which has no guaranteed costs. It will be interesting to see what the Gem.coop folks do now (disclaimer: I helped them with their governance process). If there's some competition for rubygems.org as a server implementation that feels like a good thing for the community overall. Good luck to all involved on all sides.
- ScotterC 1y agoThank you for your work in this arena and trying to add clarity. As a business owner and longtime rubyist, I'm very happy Ruby Core is taking stewardship here and that maybe we can put this tempest in a teapot behind us.
- winterqt 1y agorubygems.org will still be operated by Ruby Central, though, so you still have to trust them. Given the state of affairs, this is less than ideal, but it’s probably a better outcome than nothing changing.
- dismalaf 1y agoRuby Central has literally ALWAYS hosted rubygems.org.
- itsnowandnever 1y agothis is good and I hope this puts a lot of the drama in the rearview mirror. younger developers coming across Ruby must be like "wtf" about this situation. very peculiar to have these projects so politicised and I say that to the people that "try and keep politics out" (DHH) more than anyone. making your politics known and then being like "but you're not allowed to have an opinion on it" is't cute or clever. it's childish and everyone everywhere deserves to be treated with more respect than that.
- brightball 1y agoHe's also in a bit of a unique situation because of his public political profile was essentially forced. - Politics at work were becoming a huge problem at 37Signals - They asked that politics be kept out of company chats, but encouraged people to be political active on non-work channels/social media/etc even during work hours - People lost their minds at this incredibly reasonable request which then blew up on the internet - They offered any employee 6 months severance if they weren't comfortable with the new policy. About 1/3 of the company took it. - Rails Conf dis-invited the creator of Rails - Obviously, this was not going to sit well as people were trying to create a very public political flex against DHH and at that point, he started getting much more vocal about the problem of politics sweeping into every aspect of life. In the following years... - DHH becomes very publicly outspoken against politics infecting everything - 37 Signals publishes another successful book - Ships much more quickly as all of the people constantly distracted by politics at work are no longer in the building - Starts the Rails World conference to great success - Rails Conf shuts down - DHH ships Omarchy which is getting significant support So the end result has been that a bunch of people tried to essentially "cancel" DHH and the result was him having virtually non-stop, resounding success while publicly speaking out against those who created the problem in the first place...because some people really do just want to build cool things regardless of your politics.
- busterarm 1y agoGood summary. Also the ask for politics to be kept out of company chats is often what I find cited as the _core_ reason for why "DHH is a Nazi" in online discussions. It's _weird_. I think the real root of peoples' disagreement over what happened there is that rank-and-file employees wanted to assert a lot more control over what their company does than they actually could and they were informed that that wouldn't be acceptable. The six month severance was generous.
- gardnr 1y agoCan anyone please explain this in simple terms for a relative outsider?
- joshmn 1y agoChanged hands a couple times with “unclear” transition details at best. How it came about wasn’t all that transparent. Tensions within the community were heightened because its loudest voice and most recognizable figurehead has opinions that aren’t all that popular and he made them loud and clear as he’s a loud thinker.
- gcr 1y agoSee this thread for context: https://news.ycombinator.com/item?id=45299170#45300774 https://news.ycombinator.com/item?id=45299170#45300774 See especially Mike McQuaid's summaries. He did a bunch of mediation and comms work to make the situation digestible to outsiders. Check his recent posts (at time of writing) on https://bsky.app/profile/mikemcquaid.com https://bsky.app/profile/mikemcquaid.com
- shevy-java 1y agoYeah. I think everyone on all sides praises Mike for his effort. Cool guy.
- jrochkind1 1y agoprobably nobody can, no. Other than: a shitshow.
- phoronixrly 1y agoThank you! I was hoping for this development! Now how about taking away rubygems.org from Shopify?
- joshmn 1y agoThis is the only outcome that anyone who touches ruby cannot be upset with.
- baggy_trough 1y agocannot?
- riffraff 1y agoas a rubyist, I'd second "cannot"
- joshmn 1y agomy coffee hadn't hit—that was my intention, the "cannot"
- gus_massa 1y agoIf you go to https://news.ycombinator.com/item?id=45616729 https://news.ycombinator.com/item?id=45616729 you can fix it during a short window [2 hours?]. Add also at the bottom a short comment, so the other replies don't look wrong. Somethig like: Edit: fixed can -> cannot
- deleted 1y ago[deleted]
- shevy-java 1y agoHow so? I think there are a gazillion questions left. But, I also agree that the future will tell, e. g. we'll have to see how popular gem.coop will become (if they become popular). And I also, despite my disagreements, think that it may have been better to solve installations of ruby projects from the get go, e. g. Rust + cargo. But I also see this as separate from a service such as rubygems.org (or whoever provides any infrastructure). The question of who develops functionality can be separate, I have no strong preference here. And, I also agree that having both bin/gem and bin/bundle is not good. There should be a unified API (or two - a simple one maintained by ruby core, and then people can build extra functionality into their own variants). Sadly this all also may end up like this: https://xkcd.com/927/ https://xkcd.com/927/ What I liked about bin/gem was its simplicity. Bundler brought a few new things or easier things to the table. "gem" should make it much easier to use any source though, including gem.coop.
- pebble 1y agoBetter Ruby core than Ruby Central but still leaves me wondering what the hell happened and slightly sours me on the whole ecosystem.
- zer00eyz 1y agoI spend most of my time writing go (among other languages). Candidly its decentralized nature when it comes to "packages" is one of its strengths. It does have downsides, and yes GitHub could be at issue at some point. After this, after NPM compromises (left pad and more recently the supply chain attacks) why we arent seeing more community driven changes around decentralization and venturing is beyond me.
- madeofpalk 1y agoI don't think anything about the NPM supply chain attacks has to do with it being centralised. If anything, it made it easier to heal as NPM could centrally remove the bad packages.
- dismalaf 1y agoThis makes sense, considering Gem and Bundler are shipped with Ruby.
- shevy-java 1y agoWell - I'd actually argue that it would be better and simpler if there would be just one binary. How it is called is IMO secondary. It would be better if the whole API would be unified. Bundler came later though.
- jrochkind1 1y agoi believe that has been the goal of maintainers for a couple years now. Yeah, they had different histories where bundler was developed as an add-on.
- shadowgovt 1y agoWas there ever a mirror of this dustup in the Linux distro community? I'm unaware of one ever happening, and I'm wondering whether it's because of mere fortune or because there's something about the APT / dpkg model that precludes this kind of messiness. Perhaps the Ruby community is suffering the curse of having lived with reliable Internet for so long they never had to solve the problem of building up automatic package mirrors? This just feels like a lot of words and energy burned on a problem that ought to be as simple as "Here's the package, here's its checksum, go to town."
- busterarm 1y agoIdeologically-rooted dustups are popping off all across open source right now, it seems. Forks-included. I've even seen unironic claims of certain pieces of technology containing "Hitler particles". That shook me a bit because that's an old in-joke and was always intended to be a joke...
- shadowgovt 1y agoWho is the in-group for that in-joke?
- busterarm 1y agoLeftists. It's a Trotsky quote.
- shevy-java 1y agoThere was - see old systemd discussions. For instance, how devuan was started. It is not 1:1 comparable though. Ruby, python etc... have a much more varied community. People contribute code. Only few contribute to the linux kernel directly. There are many more who write "apps", so this could be comparable. Still it feels different to me, since a language community is different to a community that uses different programming languages. > Perhaps the Ruby community is suffering the curse of having lived with reliable Internet for so long they never had to solve the problem of building up automatic package mirrors? No, I think it is more that people never anticipated that corporations could take over projects. This has become more of a problem in the last years. Who controls github, for instance? > This just feels like a lot of words and energy burned on a problem that ought to be as simple as "Here's the package, here's its checksum, go to town." This is the issue of decentralized hosting versus top-down control. Ruby didn't have that problem in the past. It became more of an issue in the last some years. See DHH having an old tweet where he pointed out that he wants more control; I think this was from 2018. I don't remember it fully but it is on the ruby reddit.
- james_marks 1y agoMatz' action and tone in the announcement is impeccable. Humbling reminder of what greatness looks like.
- jcmfernandes 1y agoBy not addressing HOW the project ended up in RC's hands, Matz is effectively whitewashing the move.
- busterarm 1y agoUnless there is some yet-unnamed party with enough credibility and enough money to do a proper takeover from Ruby Central, this was always the inevitable way forward. In my 17ish-year involvement with Ruby, I can't think of one.
- jcmfernandes 1y agoI don't understand why the move wasn't undone. This is essentially kicking the can down the road.
- dash2 1y agoWhen I see opinions like this, I run, not walk, away from the community in question.
- jcmfernandes 1y agoLoved the... argument?
- florkbork 1y agoRight? Why is there (seemingly) no public offer to former maintainers to rejoin, or acknowledgement of wrongdoing having been done as part of this? It's practically zero cost to do that; as the Ruby core team is (largely) not the party that inflicted harm. Politeness? Conspiracy to have done this all along? Cultural differences around public vs private opinions? Something else? What would we think if this wasn't a software project but a hijacked community bus, being passed from party to party, pretending nothing is untoward about the whole situation while the passengers are still aboard? "Oh good, the new bus drivers are politely accepting the keys from the hijackers; all is well!"? Edit: https://www.reddit.com/r/ruby/comments/1o8zz3e/comment/njywbkr/ https://www.reddit.com/r/ruby/comments/1o8zz3e/comment/njywb... No discussion with maintainers
- mring33621 1y agoNGL, the drama is entertaining. I'm sorry for Ruby people that are negatively impacted, tho. Lastly, Matz is the best!
- mring33621 1y agoSo this whole thing stems from a dislike of DHH? It also seems like rubygems.org could simply fork the rubygems code, perform whatever 'security and governance' changes they believed were needed in their fork, and run with that? Isn't that the open source way of handling disagreements in direction?
- mcphage 1y ago> So this whole thing stems from a dislike of DHH? I don't believe this has anything to do with DHH.
- Mystery-Machine 1y agoIt seems like it stems from dislike of André
- saghm 1y agoAs best I've been able to understand it, a dislike of DHH led to the opportunity for those with a dislike of André to do all the stuff under discussion. I doubt we'll ever know the whole story, but in the absence of any of the additional context that some people claim exists (but haven't made public), this seems to be the most coherent explanation for what happened.
- blasphemers 1y agoIsn't rubygems distributed as part of Ruby
- florkbork 1y agoNo, no, no, this isn't the open source way at all! I can't believe you aren't getting it still! Because I once installed your project, I need to: - Take over all of the accounts/access you AND all of your friends/co-maintainers used in connection with it - Tell you it was a mistake, give back access temporarily - Do it again! - Have one of my board members who happens to be the treasurer say it was about the $ - Make a straight to camera YouTube post Addressing The Concerns - Make a first "continuing our series of transparency" blog post a week later, where I use a dense corporate laden dialect to claim it was for the betterment of all mankind and definitely not about the $; because I need you to understand Where We Are Now; What This Is and What This Isn't. - Open a Google forms question submission box. - Smear your reputation, because you had an idea once about tracking which packages go to which companies; so I'll insinuate that you want to read everyone's mail and snoop through their undergarments drawer. What's that? My actions affected much more than just you? Quiet now, we're reshaping the narrative to smear you. - Answer no questions, explaining that we chose to give you a regular series of Friday updates; but also We Want to Move On from the back and forth but also in that same publication have another go at the smear, because it partially worked. - Donate the project to my state library, to take some of the heat off of me Isn't that so much easier than typing "git clone" and "git remote add"? (I am consistently flummoxed that a handful of people here are buying this narrative; instead of as you point out... Just applying a smidgeon of critical analysis about the usage of tools that the majority of us must use day to day and coming to the conclusion you do. Instead of doing this or accepting this conclusion, there's a frothy passion it seems for Appeal to Authority/Argument from Authority where any excuse, flaw, etc on the part of the maintainers is used to justify the whole chain of events. It seems like it hits 5-7 facts and people can no longer manage them in short term memory, go and look at more than what is presented to them by a single party, etc; so they just default to the easiest mental shortcut. For some reason I keep falling into the trap that "people are more educated, capable of critical thinking, and have easier access to data than ever before in history"; which I rationally know is not true)
- shevy-java 1y agoThere are numerous questions here, but also a few answers. For instance, I pointed out days ago that Hiroshi Shibata did not act solo. Now this is confirmed - it was a matz directive. The main question to ask here is: could he not have made this open AND public from the get go? It would have lessened the confusion for some people. Unfortunately this also has a few added problems now, because ... say that you are an indie dev or a solo dev. Would you want to "interact" with the ruby core team if they can just oust people at will if they feel they need more top-down control? Or, worse, if they only get money if companies pay them to do so? I am not necessarily saying there was a 1:1 connection with money in mind. For instance, the bin/gem was not designed by the ruby core team, in many ways was a mistake from the get go - see how Rust avoided this by having cargo. But one can not help but wonder how deep that money situation goes. u/jrochkind on reddit pointed that out, e. g. that there is very clearly a connection to ruby losing users and developers in the last ~5 years, and a dry-up of financial assets in general. I agree with him. Even if this was not the case here (though I somewhat suspect money had to do with many things here), the situation for ruby in general is really really bad. Perhaps matz felt that this was the only way forward, who knows. Either way it is not a good situation to be had. It also shows how ruby is WAY too dependent on rails. If rails sinks, ruby sinks. That is BAD. DHH may contribute to this problem with the "I am the richest neo-boy in the USA" and odd blog entries (that's his though, he can write whatever he wants to), but the moment there is a financial interconnection is the moment there is no longer a fair field. And this is really bad, because it means ruby as such will be pulled by those who have money. Bye bye solo devs - you no longer have a place in the corporate infrastructure. And make no mistake about this: rubygems.org is a pure corporate entity now. Look at the new rules they forced onto everyone: https://blog.rubygems.org/2025/07/08/policies-live.html https://blog.rubygems.org/2025/07/08/policies-live.html This also reminds me of Pypi, by the way: https://blog.pypi.org/posts/2023-05-25-securing-pypi-with-2fa/ https://blog.pypi.org/posts/2023-05-25-securing-pypi-with-2f... Quote: "Isn't supply chain security a corporate concern?" And then he weakly tries to say "no, it isn't because corporations finance us now, it is all about LOVE, HAPPINESS and THE COMMUNITY". But in reality - it absolutely is. Corporations wanted more guarantees and these inrastructure-maintainers said "that's ok - we don't pay these indie devs anything but now we force them into mandatory 2FA, ad-hoc 100.000 restrictions (can not remove your gem past that limit) and any other random crap, such as not paying them anything and having them work for us for free". I am sorry but there are soooooooo many things going wrong here - I totally agree with duckinator. This was a hostile take-over, unfortunately now we also know that it was decided from within ruby-core itself. Note that I am not saying that it is a bad idea to have something such as gem maintained by the ruby core team, I totally understand the reason for this, and I also pointed at the example of rust/cargo. However had, the infrastructure shouldn't be a money-injection team for the ruby core team - the moment this happens is the moment things no longer work here. And ruby isn't merely the part designed by the core team; it also isn't just rails - you had many more people who contributed to ruby in the form of the ecosystem. Granted, many projects are abandoned (this is also a problem for rubygems.org by the way) but at the least this used to be true in the past. In a way this is all a bit rubbish, because we see MIT/BSD licences, so people could just fork ruby (not that this is likely; I haven't seen anyone object to matz being an excellent language designer. I also don't think it is a problem if matz and the core team profit from this financially, that's perfectly fine. But the whole ecosystem shouldn't be in such a top-down control where corporations just buy their way into things, with DHH making snide remarks on his blog ("we got rid of the boys controlling the infrastructure now") all of the time while on Shopify's payroll - that is no longer a fair playing field here. Everyone can see this.) Also, if matz made the decision weeks ago and told Hiroshi to do so, HOW was this fair to Mike McQuaid? The latter said he tried to act as man in the middle. But if the decision was made to finalize on this already prior to that, was Mike told that? If not, how is that fair? Either way I guess Mike gets the most praise from all sides simply for trying. We'll see what happens, whether people love the new corporate-controlled rubygems.org or prefer gem.coop (which, admittedly, still have to deliver). I favour the latter, like the rising phoenix from the ashes - in part because I hated the new corporate rules that was installed onto rubygems.org, including the crap 100.000 download limit, but in part also because I feel that if gem.coop gets enough momentum overall, they can actually begin to solve NUMEROUS issues in the ruby ecosystem, from documentation to namespaced accounts (users and the ruby code as such, see duckinator's proposal) and so forth. Considering the damage shopify caused while wanting to control more of the ruby ecosystem, I expect them to now send more workers to go and improve rubygems.org as much as possible - and not ruin things in the process. Otherwise they would have only caused damage without any real gains. The biggest loser in this are actually the folks at RubyCentral. Because ... what have they really ever done for the ruby community? Which high profile gems have they maintained? Just throwing fancy parties isn't going to cut it - Titanic was also sinking when it hit an iceberg. RubyCentral may still celebrate while sinking ...
- runjake 1y agoI think this is great news and the right move! At the same time, I would like more information around how the Gem supply chain will be handled, particularly how Rubygems and Bundler will be protected against supply chain attacks, which are becoming endemic.
- deleted 1y ago[deleted]
- AnonHP 1y agoSince Ruby Central is still very much involved, does (or would) this have any impact on the people who left recently (like Ellen Dash/duckinator)?
- riffraff 1y agoseems to me they can happily go back to contributing to the tools, and at the same time ignore the fact that rubygems.org exists, by running gem.coop or whatever else.
- florkbork 1y agoDo the former maintainers have full commit access? Remember, this is what was taken in the middle of a discussion about governance. https://github.com/rubygems/rfcs/pull/61 https://github.com/rubygems/rfcs/pull/61
- rvitorper 1y agoAs an outsider, I have two questions: - why is Shopify kind of hated in the comments? - what is it DHH said? Hoping for some context
- Alifatisk 1y agoI think because of this, which started this whole thing > Shopify demanded that Ruby Central take full control of the RubyGems https://joel.drapper.me/p/rubygems-takeover https://joel.drapper.me/p/rubygems-takeover
- drbragg 1y agoThis isn't true according to this article: https://www.404media.co/how-ruby-went-off-the-rails/ https://www.404media.co/how-ruby-went-off-the-rails/. Joel has a terrible habit of not citing his sources so I'm not sure if the post in question is the same but this seems to nullify that argument. TBF I do think there was pressure from Shopify to get compliance and security in order but saying "Shopify demanded that Ruby Central take full control of the RubyGems" is just plain not true.
- joeldrapper 1y agoRuby Central is making legal threats to its critics, so I hope you can see why people don’t feel safe to come forward on the record. I can tell you that two people with direct knowledge of the situation told me that Shopify demanded that Ruby Central take full control of the RubyGems GitHub organisation and packages. You can believe that I am lying if you want. But I can’t directly cite my sources in this case.
- drbragg 1y agoI never said you were lying. I said the quote that person pulled from your article isn't true. IIRC your article came out before the one I linked came out.
- 1y ago
- didip 1y agoHow’s th adoption and usage situation for Ruby these days? Is Ruby ecosystem doing well?
- krmbzds 1y agoAlive and well. I write Ruby every day and enjoy doing so. It's the only thing that consistently got better for me in the last 10+ years without losing it's simplicity and joy. Ruby is truly a programmer's best friend.
- notepad0x90 1y agoOther than personal preference, are there any features that make Ruby worth considering for new apps? As a user, my experience with gems hasn't been great. I don't know any Ruby, I'm just asking out of curiosity.
- kingnothing 1y agoI've used Ruby off and on since the hype train started with DHH's early videos showing how easily you can make a blog in Rails. Oof, that was published 20 years ago! I wouldn't use it for anything beyond simple shell scripts these days. You're better off with Go for back-end work.
- adamors 1y agoI’ve been writing Ruby profesionally for over a decade and while the writing has been on the wall for almost the entire time, it’s more certain than ever that Ruby is on its last legs. Big legacy companies who have invested heavily into Ruby cannot switch but every shop I’ve been at often started new services in non-Ruby (mostly Go but have seen plenty of Node/TS as well or Rust for that matter). If I were to start a new app Ruby would be far from my first choice and the biggest reason are types. After being in the weeds of big Rails apps while also working with Go/Ts/typed Python, Ruby seems very fragile in big codebases. Sorbet is also not enough.
- ufmace 1y agoRuby by itself is still a pretty decent scripting language. I still think Rake is highly underrated as a command runner. Rails is still a good web framework within its limits. If you want to build a small, modest complexity web app with like 1 or 2 developers and under maybe 6 months of active development, modest traffic needs, etc, it's a good way to get everything up and running fast with best-practices for everything. The lack of types may start to pinch some once you get an order of magnitude more developer-months into the app than that. Lack of overall speed, threading issues, and memory usage may be an issue once you get a few orders of magnitude more traffic. But while you're within those limits, I think you'll get features out on it faster than any other language or framework. As they say, a lot more startups have died due to not being able to iterate fast enough in the early stages than from their traffic capacity, hosting efficiency, and bug count once they get into serious growth.
- krmbzds 1y agoDoes that mean RubyCentral or anyone associated with them no longer have admin access to RubyGems GitHub organization? Watching the debacle unfold made me much less trusting of their "stewardship". It's good to hear Ruby core team took the ownership. Thank you Matz.
- codesnik 1y agoI waited for this as the more or less easiest option to regain back some trust. Benevolent leaders still keep many communities together.
- poemxo 1y agoDoes this potentially mean that RHEL will include more gems in their supported repos? It would be nice to script in Ruby instead of having to do everything in Python. Ruby is maybe my favorite language simply because of how it flows from left to right and how functional idioms come so naturally. But adding a gem sourced from community would be a hassle for my organization.
- tedchs 1y agoIs this announcement just about the gem and bundler packages themselves? I don't think Ruby core team is taking over the rubygems.org site right?
- bm5k 1y agoThis is satisfactory news. Now we can all get back to coding.