Live data from Hacker News

Gem.coop

gem.coop

231–240 of 331 posts

Re: Gem.coop

#231

So, ignoring everything that got us here, what do people think about this? As I see it, there is the original rubygems, which has lost all of it's maintainers, and this new one, that has most of the original active maintainers? (how many were there before? it has most of the ones I think about, but I didn't know who was active over there. I mostly saw activity from deivid and didn't know about most of the others to b…

It's bittersweet.

The suckiest thing is if the fork pans out, it will look a lot like JS: "Which package manager do you want to use?". That beautiful simplicity of "just use bundler and ruby gems" will be gone.

One thing I will give them massive credit for is walking-the-walk. There wasn't really that much complaining for the aggrieved maintainers of RubyGems. They made a public statement describing their grievances, then quietly got to work on a fork. Taking on a fork of RubyGems seems impossible and foolish, but they now have a non-zero chance of succeeding because they're doing it.

Most people I've talked to inside of big orgs are going to stick with the "safe boring" thing, which will probably be RC backed by Shopify. They will probably throw security bureaucracy at the problem, which will make SOC 2, ISO 270001 auditors. I don't think we'll see a lot of innovation coming from RC since the executive director is non-technical and has demonstrated a very ham-fisted approach to running the organization that seems to be out of touch with developers.

On the flip side, I think if gems.coop takes off, it will be because it's a "better mousetrap". One of the people behind it, André, is working on https://rv.dev, which promises to be a faster, "all-in-one", tool for managing ruby versions, gem dependencies, and even has an "npx-like" run this from from the CLI, the right version of Ruby will install, the gems will install, and it will run. That's a much better DX that I could see developers going for.

I've seen discussions on the periphery of adding namespaces to gems, bringing in checksums, and overall taking a more aggressive technical approach to security. I could see that "winning" over a long enough timeframe if RC continues on their current course.

From a fund-raising PoV, I'm starting to put together the clues that André believes organizations with the means to pay for OSS infrastructure should pay for it. I think I agree with this point-of-view and think it's a path for funding that's more transparent than "A group of donors". I hope we start to see infrastructure run in a manner where the costs are accurately estimated, then divided by the number of companies with the means to pay to arrive at the price.

There's absolutely on consensus on my final point, but I think the root cause of RC's catastrophic failure is having too much of a concentration of funding from a few donors. If you're new to this drama, a major donor pulled funding from RC because they didn't ideologically agree with a conference guest. The details are out there if you want to dive into it, but to keep this thread on point, I hope Ruby Co-op figures out how to spread out their funding model across 100's or 1000's so this doesn't happen again.

Re: Gem.coop

#232

So, ignoring everything that got us here, what do people think about this? As I see it, there is the original rubygems, which has lost all of it's maintainers, and this new one, that has most of the original active maintainers? (how many were there before? it has most of the ones I think about, but I didn't know who was active over there. I mostly saw activity from deivid and didn't know about most of the others to b…

I think right off the bat since they chose .coop as their TLD, a lot of corporate firewalls auto-block them and they have immediately decided to fight an uphill battle to get allow-listed to be a gem repo. This does not bode well for the team having the socio-technical savviness to see this project through.

Don't think it will be the TLD specifically. Most corporate firewalls block domains under a certain age, so it will just be a matter of time.

Re: Gem.coop

#233
post #183

Earlier quoted context omitted.

Really? Maybe I'm naive, but why would .coop be blocked?

It is pretty common that "weird" tlds get blocked more or less whole sale in places you might not expect. The reason is spam. Before these can get wide spread "normal" adoption they can be heavily used by spammers. Its hard to say if that is because they have desirable look-a-likes available, or if its because the first year is offered at a deep discount. So, systems will get flooded, and on inspection they will see…

Pretty sure it is because they are cheep for the first year. And the blocks are often for domains younger than one year, instead of whole tld.

Re: Gem.coop

#234

Earlier quoted context omitted.

He posts about it on his personal blog, not on his company Slack.

Is world.hey.com/dhh a personal blog? It's literally on his company's domain... At least in the company slack your fash opinions would reach just your poor colleagues...

Everyone with a Hey.com email gets a world.hey.com account linked to your email. So yes it's a personal blog.

Hey.com is 37Signals' Gmail, not the company's private domain.

Re: Gem.coop

#235
post #66

Given some of the ways Andre Arko gets described (See https://justin.searls.co/posts/why-im-not-rushing-to-take-si... for a recent overview) I'm a little wary of what the motivation behind this is.

This reads like a hit piece based on a personal vendetta. I'd be careful how much weight to give this.

Does it? Seems pretty detailed with plenty of easily verifiable details...

Re: Gem.coop

#236

So, ignoring everything that got us here, what do people think about this? As I see it, there is the original rubygems, which has lost all of it's maintainers, and this new one, that has most of the original active maintainers? (how many were there before? it has most of the ones I think about, but I didn't know who was active over there. I mostly saw activity from deivid and didn't know about most of the others to b…

> So, ignoring everything that got us here, what do people think about this?

It's fine. Keeps all the complainers away from the larger ecosystem.

I personally trust Ruby Central, 37signals, Shopify, DHH, Tobi, Matz and others over the guy who was launching a startup to compete with rubygems while being a maintainer for rubygems.

Re: Gem.coop

#237

Earlier quoted context omitted.

It doesn't really matter if it's a non-profit. How do you think your company would react if you started raising money using their name?

Is Rubygems a company? My mind cannot comprehend why are people conflating not-for-profit open-source projects with for-profit companies... If Rubygems was a company, they'd have a trademark, they'd have patents, they'd have lawyers to protect the money they were making from their brand and product. But we are speaking about not-for-profit open-source projects, not for for-profit corporations!

Ruby Central is a company that manages rubygems.org and rubygems. The maintainers who were locked out were being paid by Ruby Central while fundraising for their startup creating a competitor.

Doesn't it seem like a bit of a security risk to you?

Re: Gem.coop

#238
Well the site is blocked on my company laptop (reason given: newly registered domain), so it will be a rocky start for them. I love a good vanity domain but using a traditional .org domain probably would have been better, too.

My 2c is that 95% of ruby developers aren't aware of the drama going on around Rubygems.org right now. They have probably seen emails from Ruby Central but largely ignore them and move on with life. Most people have no idea there are issues and they will just continue using Rubygems.org. Getting a project like this to critical mass is incredibly challenging.

Re: Gem.coop

#239

Earlier quoted context omitted.

With this is in place. A ".coop" domain does not signal trustworthiness. It's more like a childish revenge attempt. Don't get me wrong. I think it's a great idea for the original maintainers to begin work on a form. However, they could have chosen a better domain name.

Read https://en.wikipedia.org/wiki/.coop Think about all of the organisational structures you know of. Then ask yourself how is a cooperative fundamentally untrustworthy?

Nothing here instills trust or makes me want to learn more.

https://register.coop/

https://register.coop/services/

Re: Gem.coop

#240
post #239

Earlier quoted context omitted.

Read https://en.wikipedia.org/wiki/.coop Think about all of the organisational structures you know of. Then ask yourself how is a cooperative fundamentally untrustworthy?

Nothing here instills trust or makes me want to learn more. https://register.coop/ https://register.coop/services/

That website isn't the official registry. The .coop TLD has been operated since 2002, with the official registry at https://identity.coop.

Neither the current authorized registrar list (https://identity.coop/register) nor the archived 2013 list (https://web.archive.org/web/20131019082806/http://www.nic.co...) includes register.coop. Where did you find this site?

Post reply on HN