edit: Looks like they were public gems, but in general it's always good advice to consult a lawyer before disrupting commercial or public systems.
Good way of making sure no one ever contributes to FOSS again.
To establish criminality or liability intent is often looked at, and this is a pretty clear-cut intent to injure the other party.
I agree that keeping children in cages is not good, but there are solutions. If ice had a bigger budget maybe it could have more beds, larger cells, better food. I don't see how removing enforcement is a solution.
Come on, man.
I never saw anyone talking about "cages" until about a year or so ago. It seems the alternative of better accommodation isn't what people are demanding here, but rather, giving children a waiver to break any and all laws. If you want to see children being forced or recruited into cartels in record numbers, making them immune from any kind of border enforcement is a surefire way to do it!
The net impact is zero.
Make working with ICE a toxic asset. Make people not proud of working for ICE contractors.
>Make working with ICE a toxic asset. Make people not proud of working for ICE contractors.
This kind of activism in tech leads no where good. It will lead to witch hunts, more "cancel culture" purity spirals, and generally shit software used for critical functions of our government.
I suspected a small percentage of people with a hard, runtime dependency would be impacted, but I did not know Chef (the software) had a hard runtime dependency and was pulling that dependency from public RubyGems instead of a mirror they control.
First, always minimize runtime dependencies. I personally prefer compiled things for this very reason.
Second, if you’re going to include a third party dependency, how are you auditing it? There’s an unexplored area around security here too. The Node.js ecosystem has had a series of incidents where popular packages have had cryptocurrency miners injected into otherwise helpful packages. If you’re depending on third party runtime dependencies: how are you auditing changes and contributions, how are you scanning for vulnerabilities, how are you patching those vulnerabilities if you don’t have an internal fork upon which you build?
Third, RubyGems is a volunteer-run organization. I believe other software ecosystems are similar. From my understanding of the situation, a RubyGems outage would have had similar effect.