Earlier quoted context omitted.
It's so weird of you to jump in like this, man.
Can you explain what you find so weird? From what I can tell, the GP is adding useful information using his firsthand experience.
Gem.coop
281–290 of 331 posts
Re: Gem.coop
#282Earlier quoted context omitted.
Is Rubygems a company? My mind cannot comprehend why are people conflating not-for-profit open-source projects with for-profit companies... If Rubygems was a company, they'd have a trademark, they'd have patents, they'd have lawyers to protect the money they were making from their brand and product. But we are speaking about not-for-profit open-source projects, not for for-profit corporations!
Ruby Central is a company that manages rubygems.org and rubygems. The maintainers who were locked out were being paid by Ruby Central while fundraising for their startup creating a competitor. Doesn't it seem like a bit of a security risk to you?
Re: Gem.coop
#283Earlier quoted context omitted.
The package repository going rogue is a significant escalation compared to merely having individual malicious packages that go undetected. You can't possibly argue that those two are the same.
To put my cards on the table: RubyGems.org seems plenty trustworthy to me. They seem to be shitty at communication, but locking down production access to systems in light of the state of supply chain attacks in 2025 is the kind of thing that reduces the risk of rogue repo-level activity. But to your comment: I'm not arguing the same, I'm arguing that the results are the same. If I'm consuming packages from a repo, an…
Also, you don't secure a package repository through hostile takeovers, and you certainly don't build trust with such an obvious lie. Claiming that the current rubygems.org is in any way trustworthy is utterly absurd.
Re: Gem.coop
#284Earlier quoted context omitted.
They had a minor security incident right off the bat, demonstrating they don’t even fully understand what they stole. They aren’t equipped to do the job.
I missed that. What happened?
Re: Gem.coop
#285Earlier quoted context omitted.
It is pretty common that "weird" tlds get blocked more or less whole sale in places you might not expect. The reason is spam. Before these can get wide spread "normal" adoption they can be heavily used by spammers. Its hard to say if that is because they have desirable look-a-likes available, or if its because the first year is offered at a deep discount. So, systems will get flooded, and on inspection they will see…
.xyz is open registration and is known to be a spam/abuse source. .coop is restricted to legally-formed cooperatives. Apples and oranges.
Re: Gem.coop
#286Earlier quoted context omitted.
This absolutely happened and is not speculation. I can't find the emails from the individuals that emailed me, but I did find my email to the board of directors asking that the website language be changed because people had pinged me thinking I would be getting money, or that the money would go to fund rubygems.org. At the time I'd sent the email I was unaware Ruby Together was on HN front page (and that's why people…
It's so weird of you to jump in like this, man.
Re: Gem.coop
#287Earlier quoted context omitted.
Can you explain what you find so weird? From what I can tell, the GP is adding useful information using his firsthand experience.
Did they? No evidence and worded to suggest Steve didn’t experience it, that counts as useful information now?
> This resulted in a nonzero number of donors believing they were funding the work of people like Steve Klabnik, Aaron Patterson, and Sarah Mei, when in fact only Andre was being paid at the time.
Steve said "that didn't happen to me" and then Aaron said "that definitely did happen to me". Seems pretty relevant. I don't think he was claiming steve was wrong in not having heard that, but Aaron was saying it did happen to him, so the claim is true.
(and in terms of evidence, do you want him to share the emails he got? A first hand account seems enough evidence to me)
Seems pretty unambiguous, and a good reason to chime in.
Re: Gem.coop
#288Earlier quoted context omitted.
>It kind of feels like this fork is the better-maintained piece of software now. Maybe, but I feel the value of the index is the storage and bandwidth and not the software itself, isn't it? Could an index work by just being a search engine for gems, storing the hashes, but pointing to external resources, like GitHub repos, for the download itself?
Trustworthiness is far more important for a package manager. No amount of storage or bandwidth can compensate for an untrustworthy package manager.
Re: Gem.coop
#289Why has this been flagged?
Just some background: there is a controversy in the Ruby community[0][2] around the governance of the rubygems project. It has been maintained for a long time by employees of Ruby Central but not in a corporate capacity. There was a recent hostile takeover of this project by the Ruby Central corporate arm. The most likely reason it was flagged from my perspective is that David Heinemeier Hansson (who created rails) i…
Basically just a blog post from some guy aghast that DHH has different political opinions to him. I'm politically on the left too but I can't imagine getting so incensed about someone else having right-leaning views.
Do these people never leave the house to meet anyone outside their echo chamber? The mind boggles.
Re: Gem.coop
#290So, ignoring everything that got us here, what do people think about this? As I see it, there is the original rubygems, which has lost all of it's maintainers, and this new one, that has most of the original active maintainers? (how many were there before? it has most of the ones I think about, but I didn't know who was active over there. I mostly saw activity from deivid and didn't know about most of the others to b…
Which fork of what software..?
> We’re excited to introduce gem.coop – a new server for gems in the Ruby ecosystem.
This is a new hosting service for gems, not a fork of bundler. Or is there missing context?