3 ms·
Oh the timing. So, there was a big meeting, where some of the devs pleaded the case that the recent wave of security issues in the Ruby world were a tipping poi
by static_typed 14y ago
Oh the timing. So, there was a big meeting, where some of the devs pleaded the case that the recent wave of security issues in the Ruby world were a tipping point, and that we were over it. They presented a good case, and I think the architects were close to permitting the usage of Ruby and Rails in their current cases.
Then we get an interruption, as a couple of projects had updated their gems today, and there was a concern about overall security of the apps.
IT Security required the apps were offlined, and the green light was given to the PHP and Python guys in house (and a few retained developers) to start the process of rewriting the apps.
It will be painful, but, I think, the business has lost it's appetite for the constant Ruby idea of "Let's run with Yaml", before firstly "Let's walk safely with Yaml".
- PommeDeTerre 14y agoI'm glad to hear that at least one organization has done the right thing, and started the process of moving completely away from Ruby and Ruby on Rails. It's just the responsible and sane thing to do, given how the software and the community apparently can't be trusted.
- sergiotapia 14y agoI see where you're coming from, it's a shame that so many bugs are available in Rails.
- railsblob 14y agoBugs is evrywher evn in javacs code. Rubby haz some of th finnest midns in comptuers and wil rzie agani.
- pifflesnort 14y agoIt's a tipping point, but not of the kind that they thought.
- Xylakant 14y agoI can understand it's bad timing, but the reaction seems ad-hoc. AFAIK neither python eggs nor PHPs packagist repository sign their packages, so in theory they're open to the same attack vector [1]. Judging from the docs, composer doesn't even allow signed packages. A better reaction would have been to fix the process: Allow only signed gems or cache and audit the packages you install. You don't need to depend on rubygems. [1] Even OS package repositories or mirrors were broken into. I faintly remember a break-in where debian(?) had to check all their mirrors.