Live data from Hacker News

Gem.coop

gem.coop

201–210 of 331 posts

Re: Gem.coop

#201

Earlier quoted context omitted.

It has allegedly been taken over by Shopify. I expect it to be very well maintained. The issues are of ethical character.

Well maintained? Rubygems has had no commits in the last 10 days and that's not a good sign. I don't think you can find a window with no commits for 10 days in its 15+ year history. History has shown over and over that when a for-profit org takes over public infrastructure, maintenance is cut to the bone.

> Rubygems has had no commits in the last 10 days and that's not a good sign.

I honestly can't tell if this is satire.

You think no commits for 10 days for a piece of software that has existed for around 20 years is a sign that it's dead?

What kind of code churn do you think this project requires? Perhaps the old development was too unstable if there wasn't a single 10 day window without a commit in 15 years, for what is essentially a solved problem and a tool that people depend on to be stable.

Re: Gem.coop

#202

Earlier quoted context omitted.

But how is this a conflict? Both are not-for-profit projects with the same goal? How can one even use the term 'competition' in this context? What if the Ruby community embraces a new and better package manager? This is, again, a net win for the Ruby community, and both projects strive for that?

It doesn't really matter if it's a non-profit. How do you think your company would react if you started raising money using their name?

Is Rubygems a company? My mind cannot comprehend why are people conflating not-for-profit open-source projects with for-profit companies...

If Rubygems was a company, they'd have a trademark, they'd have patents, they'd have lawyers to protect the money they were making from their brand and product. But we are speaking about not-for-profit open-source projects, not for for-profit corporations!

Re: Gem.coop

#203

Earlier quoted context omitted.

I don't plan on switching to a rubygems fork that does not offer technical/security benefits over the original. They can win me over with a gem distribution site that requires code signing out of the box and a bundler that enforces it out of the box.

Which part of a project that kicked out its original maintainers still feels "original" to you? At this point, rubygems.org is the fork. Oh, how times have changed. If Oracle were to close source OpenSolaris today, many here would likely rally behind it, especially if Larry Ellison appeared to align with the right. Submissions about Illumos would have been heavily flagged, much like this one has been for a while.

Excellent point, I can't help but feel gem.coop is essentially Ruby Together 2.0 which reinforces my opinion that the merger of RT with RC was a huge mistake. (It certainly made sense at the time…hindsight is always 20/20…etc.…but still.)

Re: Gem.coop

#204
post #37

Earlier quoted context omitted.

Agreed. Your example could sound like exaggerated, but silence is a form of opinion, of vote, of approval. Even in a professional context, because work is part of the society we live in. This whole "DHH situation" with Rails has put my mind in weird position. I admire the Rails creator, the business man, the speaker. I admire what he builds, how passionate he is about his work and open-source software. But I very str…

> but silence is a form of opinion, of vote, of approval. I disagree. We don't have to have an opinion on everything. And what worries me is those (both on the left and on the right) who think that silence is a form of opinion or approval. It's getting very close to "those who are not with us are against us". And that's a worldview I have very little time for.

> that's a worldview I have very little time for

Only people who already live in a position of privilege get to have "little time" and settle for worldviews which advocate for a sort of bland tolerance of extremism. I can assure you, for people who are being actively harmed by hateful rhetoric and political policies, "those who are not with us are against us" is absolutely a reality.

Re: Gem.coop

#205
post #135

Earlier quoted context omitted.

I've been in the "keep work and politics" separate camp most of my life. However, with the lines that have been crossed recently, where literal democracy and freedom are at stake, I don't think people have the luxury of keeping work and politics separate any longer. Fascism is bad and people cannot be silent.

[flagged]

If you say something like “if you invoke the word "fascism" in the context of today's politics, your opinion is immediately worthless”, your opinion is immediately worthless.

Re: Gem.coop

#206
> initially his own, but eventually others—by paying themselves a market hourly rate

This is massively flawed thinking. So called "market rate" is actually a tool for value extraction from the workers and is not connected in any shape or form with what they create for company they work at. As corporations refer to this as if it was a consensus (as in developer should earn $x an hour), they pay this much and workers have no choice but to accept (if someone has working class background and no trust fund, it is rather impossible to throw the towel and start own business, sometimes there are even regulations designed to keep workers captive).

In such a project, "founder level" people should pay themselves as much as they think their worth is. Simple as that.

I often hear VC talking that if founder takes too much money, it's a bad look. They just want to shame people into not taking the slice they deserve.

It's interesting that IT is full of intelligent people, yet they can't grasp how they are being played by the market frames set by the rich.

Re: Gem.coop

#207

Earlier quoted context omitted.

With this is in place. A ".coop" domain does not signal trustworthiness. It's more like a childish revenge attempt. Don't get me wrong. I think it's a great idea for the original maintainers to begin work on a form. However, they could have chosen a better domain name.

Read https://en.wikipedia.org/wiki/.coop Think about all of the organisational structures you know of. Then ask yourself how is a cooperative fundamentally untrustworthy?

My first-order heuristic is that legitimate websites tend to get one of the top TLDs (.com/.org, maybe .net/.io). In general, why should I trust domain_name.xyz over domain_name.com? There are obvious caveats, e.g. it doesn't matter as much for generic words like "gem" and for personal sites that I don't trust much in the first place. In this case, 3 seconds of critical thinking makes it clear that they have a plausible reason for choosing .coop. But given that much of this controversy is premised on toolchain trust, there's plenty of other domains that seem even more trustworthy to me at first glance, e.g. gem-lib.org, gemcoop.org, stuff like that.

Again, a domain name is pretty minor in the scope of this whole fiasco, and I wouldn't have bothered with bringing up this point, but on balance I agree with it.

Re: Gem.coop

#208
I feel like a change to the way gems are distributed/downloaded could fix this. Unfortunately, the very powers that could make that happen are the powers that control the software and infrastructure, and have the least incentive to improve things.

I honestly find it ridiculous that this situation happened to begin with, and I also have no clue why people are hating on DHH.

The easiest way to kill an open source project is drama and forking like this. Ruby has been around forever, obviously, however it is far from the most used languages, and drama like this just hurts the ecosystem as a whole.

As a former Ruby dev, it makes me sad.

Re: Gem.coop

#209

Here's the thing. They could have put up link to a git repository where others can follow along with the maintenance of this project, but here isn't one. There is a list of maintainers explicitly mentioned on this page but no link to the git repository. This leads me to think this project is not about the code but about the people.

It's a package repository. A link to an Ansible repository or whatever doesn't need to be in the first announcement. > This leads me to think this project is not about the code but about the people. Trust is of utmost importance to a package repository. Even more so than code. A hostile takeover, like the one that occurred with RubyGems, fundamentally undermines that trust. In contrast, an alternative run by the orig…

I think the issue that you overlook is that you assume this group of individuals is trustworthy.

I'm not saying they aren't, but there are a LOT of conflicting opinions about what happened, why it happened, and who was right/wrong.

This it what tends to happen when money gets involved in a project without a clear structure/business plan/guarantees put in place. People just did whatever and made assumptions, and now suddenly the whole community is rocking and rolling thanks to the actions/view points of a select few.

Re: Gem.coop

#210

> initially his own, but eventually others—by paying themselves a market hourly rate This is massively flawed thinking. So called "market rate" is actually a tool for value extraction from the workers and is not connected in any shape or form with what they create for company they work at. As corporations refer to this as if it was a consensus (as in developer should earn $x an hour), they pay this much and workers h…

hard disagree. For a project like this, all members should be paid a fair, but not "get rich" sum. There are companies out there that pay EVERYONE the same salary, all the way from CEO to janitor. Mysteriously, those companies don't have folks trying to hijack things, because nobody benefits.

It's almost like removing money from the equation stops all the nasty stuff that happens inside organizations. Who'd have thought?

Post reply on HN