Live data from Hacker News

Ruby core team takes ownership of RubyGems and Bundler

ruby-lang.org

361–370 of 407 posts

Re: Ruby core team takes ownership of RubyGems and Bundler

#361
post #38

Decentralized package hosting is the only way.

What languages do you use that have adopted this well? I'm not counting something like C++ where there's effectively no "packages" to speak of.

Do Linux repos not implement decentralized (perhaps “federated” is a better word here) package management?

Btw, I’m definitely not saying anything is doing this really well yet, but I do think Linux distributions are a pretty good implementation of it. I think it would be pretty difficult to stamp out Linux and Linux packages.

Re: Ruby core team takes ownership of RubyGems and Bundler

#362
post #354

Earlier quoted context omitted.

> If you want to build a small, modest complexity web app with like 1 or 2 developers and under maybe 6 months of active development, modest traffic needs, etc, it's a good way to get everything up and running fast with best-practices for everything. Of course lets silently ignore Github, Gitlab, Shopify and others: all small, modest complexity web apps built with Ruby on Rails. Look at Shopify last year black friday…

But would they still build with Ruby if they had to rewrite it today? It seems other commenters are saying they wouldn't. I wanted to see if it offered anything more than my python and Go preference.

Let me ask you a different question:

Would they be where they are today if there weren't been built at that moment with Ruby?

Both these questions are hard to answer without connecting the dots, looking backward.

Github was started in 2007, Shopify in 2006, Gitlab in 2011, Whop in 2021

It takes a long time approximately for a company to get out of the medium zone and go really big. So the only answer for this is we don't really know.

For any programming language you can find similar stories.

I tried to answer this question 6 years ago by analysing company data from YCombinator and TechStars: https://github.com/lucianghinda/programming-languages-in-sta...

Here is some data I found back then in 2019:

- Ruby companies raised 13 Billion dollars

- Python companies raised 11 billion dollars

- Java companies raised 1.5 billion dollars

- PHP companies raised 1.4 billion dollars

- Go companies raised 1.3 billion dollars

- Node.js companies raised 800 million dollars

Of course this data is 6 years old and it was based on the initial programming language and also it is about funding amount and not revenue.

I did not had time these days to update the data there.

Re: Ruby core team takes ownership of RubyGems and Bundler

#364
post #354
post #285

Earlier quoted context omitted.

Ruby by itself is still a pretty decent scripting language. I still think Rake is highly underrated as a command runner. Rails is still a good web framework within its limits. If you want to build a small, modest complexity web app with like 1 or 2 developers and under maybe 6 months of active development, modest traffic needs, etc, it's a good way to get everything up and running fast with best-practices for everyth…

> If you want to build a small, modest complexity web app with like 1 or 2 developers and under maybe 6 months of active development, modest traffic needs, etc, it's a good way to get everything up and running fast with best-practices for everything. Of course lets silently ignore Github, Gitlab, Shopify and others: all small, modest complexity web apps built with Ruby on Rails. Look at Shopify last year black friday…

I did say that those aspects of Ruby would start to be painful at that scale, not that it was totally unusable. Clearly it's usable, and there's certainly less scale-able things than Ruby on Rails out there serving big production traffic today. But I wouldn't recommend switching an app that big in some other language over to Ruby, and at least as many companies have moved off of Rails monoliths when they outgrew them, like AirBnB for example.

Re: Ruby core team takes ownership of RubyGems and Bundler

#365

Earlier quoted context omitted.

I love that you had to link to the Wikipedia question for "loaded question" for this. So you're saying, the answer is "yes": he logged into the root account, after he lost access to his own account, and changed the root password. OK then! Here's what I think: people are starting from a sympathetic principle (independent community-minded maintainers are better that corporations) and working their way back to what they…

The world doesn't line up with lies and spins of the most transparently corrupt actors either. Shopify stole RubyGems from the maintainers, do you deny it? They tried to do so in secret, keeping the maintainers and the larger Ruby community in the dark. Their claim that the access revocations were a mistake was a blatant lie. Moreover, they spun even more conspicuous falsehoods in response to the public backlash. Whe…

The premise of "have you stopped beating your wife" is that you made up the idea that I might have done it; simply asking the question is a form of slander. But that's not at all the case with Andre Arko and RubyGems. From everything we know: he really did (1) lose his personal access, (2) log in with a stale AWS root credential, and (3) change the password on the root account. We also know that (4) he attempted to quietly monetize the server logs from RubyGems.

These aren't insinuations; they're direct factual claims. They're well-founded and they're either true or they're not. No, you can't just jazz-hands your way through this.

Re: Ruby core team takes ownership of RubyGems and Bundler

#366

Earlier quoted context omitted.

He changed the AWS root password for the account.

Yes, and he already explained why he did it. Yes, he should have communicated it clearly. That's on him. At the same time, why didn't RC call him to ask? Was it easier to write about a security INCIDENT throwing shade at Arko? With that said, let's keep focused on the real issue: RC did a hostile takeover of the projects. That's not been properly disputed so far. Matz is, therefore, accepting to steward stolen projec…

It was a security incident!

Re: Ruby core team takes ownership of RubyGems and Bundler

#367

Earlier quoted context omitted.

The world doesn't line up with lies and spins of the most transparently corrupt actors either. Shopify stole RubyGems from the maintainers, do you deny it? They tried to do so in secret, keeping the maintainers and the larger Ruby community in the dark. Their claim that the access revocations were a mistake was a blatant lie. Moreover, they spun even more conspicuous falsehoods in response to the public backlash. Whe…

The premise of "have you stopped beating your wife" is that you made up the idea that I might have done it; simply asking the question is a form of slander. But that's not at all the case with Andre Arko and RubyGems. From everything we know: he really did (1) lose his personal access, (2) log in with a stale AWS root credential, and (3) change the password on the root account. We also know that (4) he attempted to q…

I'll repeat:

When you twist protective measures against ongoing theft or shitty proposals that went nowhere into a nefarious conspiracy to justify the theft of critical Ruby infrastructure, it’s time to take a hard look in the mirror.

What are you trying to achieve here, bringing up debunked insinuations over and over and over again? And haha no, going over every cherry-picked fact and half-truth you explicitly stated doesn’t prove you aren’t making insinuations.

> insinuate: to impart or suggest in an artful or indirect way

https://www.merriam-webster.com/dictionary/insinuated

Note the word "indirect."

Re: Ruby core team takes ownership of RubyGems and Bundler

#368

Earlier quoted context omitted.

He changed the AWS root password for the account.

Yes, and he already explained why he did it. Yes, he should have communicated it clearly. That's on him. At the same time, why didn't RC call him to ask? Was it easier to write about a security INCIDENT throwing shade at Arko? With that said, let's keep focused on the real issue: RC did a hostile takeover of the projects. That's not been properly disputed so far. Matz is, therefore, accepting to steward stolen projec…

It doesn't matter why you break into your former employer's server. That's the point.

> Matz is, therefore, accepting to steward stolen projects.

You know Arko didn't even start working on Rubygems until it was nearly 10 years old, right?

One of the original authors is in here and on X saying he supports it being taken over by RubyCore. Which matters much more than whatever the maintainers who were locked out think.

Re: Ruby core team takes ownership of RubyGems and Bundler

#369

Earlier quoted context omitted.

The premise of "have you stopped beating your wife" is that you made up the idea that I might have done it; simply asking the question is a form of slander. But that's not at all the case with Andre Arko and RubyGems. From everything we know: he really did (1) lose his personal access, (2) log in with a stale AWS root credential, and (3) change the password on the root account. We also know that (4) he attempted to q…

I'll repeat: When you twist protective measures against ongoing theft or shitty proposals that went nowhere into a nefarious conspiracy to justify the theft of critical Ruby infrastructure, it’s time to take a hard look in the mirror. What are you trying to achieve here, bringing up debunked insinuations over and over and over again? And haha no, going over every cherry-picked fact and half-truth you explicitly state…

Which of these insinuations have been "debunked"? Did they happen or not? If they happened, but you're OK with the reason they happened, they weren't "debunked"; they were, to you, "mitigated".

Re: Ruby core team takes ownership of RubyGems and Bundler

#370

Earlier quoted context omitted.

Yes, and he already explained why he did it. Yes, he should have communicated it clearly. That's on him. At the same time, why didn't RC call him to ask? Was it easier to write about a security INCIDENT throwing shade at Arko? With that said, let's keep focused on the real issue: RC did a hostile takeover of the projects. That's not been properly disputed so far. Matz is, therefore, accepting to steward stolen projec…

It doesn't matter why you break into your former employer's server. That's the point. > Matz is, therefore, accepting to steward stolen projects. You know Arko didn't even start working on Rubygems until it was nearly 10 years old, right? One of the original authors is in here and on X saying he supports it being taken over by RubyCore. Which matters much more than whatever the maintainers who were locked out think.

> It doesn't matter why you break into your former employer's server.

Arko already stated that he didn't know he had been fired. Geez.

> You know Arko didn't even start working on Rubygems until it was nearly 10 years old, right?

The project was stolen from a set of maintainers, not just Arko. Let's stick to the facts: someone with admin rights over the repos revoked the access of other admins without their consent. What do you call this?

> One of the original authors is in here and on X saying he supports it being taken over by RubyCore. Which matters much more than whatever the maintainers who were locked out think.

How in the world is that relevant? I have a lot of respect for Rich, but he wasn't a maintainer.

Post reply on HN