Live data from Hacker News

Gem.coop

gem.coop

161–170 of 331 posts

Re: Gem.coop

#161

Earlier quoted context omitted.

I personally cannot think of a new ruby gems or bundler feature from the past decade that I noticed or cared about. That isn't to say that there aren't any; I just don't know what they are.

I think I basically agree with this, but my thoughts are more on which org is better placed now to respond to things like the recent supply chain attacks (ref for the specific recent ruby one[0][1]). I'm unsure on who is better placed to handle that stuff now. My view is that the people that were doing that are now with gem.coop, but rubygems still has the infra (i.e. you'd email security@rubygems.org still for now).…

Socket.dev states "Since at least March 2023". RubyGems says "Our team first detected this activity on July 20th". This attack has ran for almost 5 months undetected. I wouldn't feel reassured at all.

Re: Gem.coop

#162
post #94

Earlier quoted context omitted.

>It kind of feels like this fork is the better-maintained piece of software now. Maybe, but I feel the value of the index is the storage and bandwidth and not the software itself, isn't it? Could an index work by just being a search engine for gems, storing the hashes, but pointing to external resources, like GitHub repos, for the download itself?

Isn't that how golang works? I remember some complaints about the traffic that it produced[0] (though I don't think it's a bad idea. Basically federated downloads). [0] https://sourcehut.org/blog/2023-01-09-gomodulemirror/

Combining this with something like tangled.sh/bluesky's AT protocol or what forejo is working on in their activitypub federation integration can actually make it genuinely federated as well

Or maybe radicle as well if someone is okay with swapping in a custom software but the hiccups can be too much imo so tangled.sh is the most interesting thing to me right now

What is stopping something like gem.coop to exist with the at protocol/tangled.sh??

Re: Gem.coop

#163

So, ignoring everything that got us here, what do people think about this? As I see it, there is the original rubygems, which has lost all of it's maintainers, and this new one, that has most of the original active maintainers? (how many were there before? it has most of the ones I think about, but I didn't know who was active over there. I mostly saw activity from deivid and didn't know about most of the others to b…

I don't plan on switching to a rubygems fork that does not offer technical/security benefits over the original. They can win me over with a gem distribution site that requires code signing out of the box and a bundler that enforces it out of the box.

Which part of a project that kicked out its original maintainers still feels "original" to you? At this point, rubygems.org is the fork.

Oh, how times have changed. If Oracle were to close source OpenSolaris today, many here would likely rally behind it, especially if Larry Ellison appeared to align with the right. Submissions about Illumos would have been heavily flagged, much like this one has been for a while.

Re: Gem.coop

#164

Earlier quoted context omitted.

What makes you think they _haven't_ tried to work things out with Ruby Central? As per a separate article[1], this seems to be a last resort: > “Since Ruby Central has informed us they will never allow us to continue working on the projects they now claim they own, that we successfully maintained and operated for the last ten years, the former RubyGems team is launching gem.coop today.” [1]: https://socket.dev/blog/g…

I suspect many of these maintainers are making absurd ultimatums of RubyCentral.

That's a strange suspicion. Why?

Re: Gem.coop

#165
post #153

Earlier quoted context omitted.

Back in the day, nobody ever had said to me that they believed I was earning money from Ruby Together. This whole thing was speculation at best. And regardless, once it was suggested that this may be a possibility, it was immediately changed to be unambiguous. André is absolutely a standup individual. I have tried to stay in good terms with the other people involved in this (except DHH), but this claim was always rid…

I was misremembering it. Now that I've checked, it's clear that the claim was that the money was for paying "the team" [1], which consisted of André Arko and David Radcliffe [2] [1] https://web.archive.org/web/20150919025358/https://rubytoget... [2] https://web.archive.org/web/20150919025603/https://rubytoget...

I just want to know how much was David Radcliffe getting paid for his time?

Re: Gem.coop

#166
post #130

So, ignoring everything that got us here, what do people think about this? As I see it, there is the original rubygems, which has lost all of it's maintainers, and this new one, that has most of the original active maintainers? (how many were there before? it has most of the ones I think about, but I didn't know who was active over there. I mostly saw activity from deivid and didn't know about most of the others to b…

The main page itself provides little to no info so I’m going to make a few assumptions that, to me, seem logical: 1. It must depend on RubyGems in order to stay in sync, because people publish to RubyGems. 2. It has no UI to search or view gems, so still depends on RubyGems for that. Ignoring any question about technical detail or implementation: there is zero practical reason or motivation to switch unless I am ideo…

True, but this is a new beginning.Give time and credit to build an alternative. I think another repo server will not harm anyone in the long run

Re: Gem.coop

#167

So, ignoring everything that got us here, what do people think about this? As I see it, there is the original rubygems, which has lost all of it's maintainers, and this new one, that has most of the original active maintainers? (how many were there before? it has most of the ones I think about, but I didn't know who was active over there. I mostly saw activity from deivid and didn't know about most of the others to b…

I think right off the bat since they chose .coop as their TLD, a lot of corporate firewalls auto-block them and they have immediately decided to fight an uphill battle to get allow-listed to be a gem repo. This does not bode well for the team having the socio-technical savviness to see this project through.

[deleted]

Re: Gem.coop

#169

Earlier quoted context omitted.

This doesn't explain how rv is threatening rubygems in any way.

They were using the name "rubygems" to fund-raise for not-"rubygems."

But how is this a conflict? Both are not-for-profit projects with the same goal? How can one even use the term 'competition' in this context? What if the Ruby community embraces a new and better package manager? This is, again, a net win for the Ruby community, and both projects strive for that?

Re: Gem.coop

#170

Earlier quoted context omitted.

"will put me into a torture camp" for sure, but "devalues my life or personhood" is pretty vague. So, for example, if I value guns and consider them necessary for my well being and personal safety, should I refuse to work with anyone who votes for increased gun control? This sounds like a recipe for very fragmented, unstable society.

If gun owners are being denied health care or being told who they can marry ("it's illegal to marry a fellow gun owner"), then yes, they'll probably want to avoid anyone wretched enough to advocate that. Short of that, it's NBD right? Not really comparable.

It's absolutely comparable. They both involve limiting rights and freedoms.
Post reply on HN