- Attacks on supply chains are way up
- Use of open-source software is way up
- Shopify is already contributing engineering time to bundler and rubygems.org
- And there is additional shovel-ready work that Ruby Central could execute on with a financial contribution.
Proactive security work now reduces the chances of a successful supply chain attack and the costs associated with recovery, investigation, and mitigation in addition to reputational damage.
There are secondary benefits, too: when we're confident in the supply chain, we can more confidently update our dependencies in a timely fashion, meaning our developers have access to the newest library features; and we're able to patch known vulnerabilities faster. We invest a lot in feedback loops internally, and this is just another facet of that build/measure/learn cycle.
I made the initial pitch that we should support Ruby Central, but it took off very quickly once senior leadership saw the pitch. Once we got the go-ahead it was mostly worked out by Mike Dalessio (aka flavorjones) and Rafael França for Shopify and Evan Phoenix for Ruby Central.
Being a dev myself and knowing how the sausage is made and how FOSS is the casing that holds it all together, this investment makes perfect sense. But I can also see how investment types would complain, it doesn't exactly look like an investment in the books.
It should be, but conventional bookkeeping hasn't really kept up with the economic realities of this industry. Same reason why they fail to account tech debt as a liability, refactoring as amortization and debugging as interest payments.
They have a ton of terrific engineers but the nouveau riche people from the IPO are largely insufferable, and the amount of reverence for tobi inside and outside of the company is just unhinged.
I've started responding to "hey, do you want to talk to sales?" messages with "sure", just to see what stuff costs in the real world. Everything is 5 or 6 figures, even static website hosting. I wouldn't pay $20,000 a month to host a static website, but someone must be, because that's what people are asking for on these calls. I can see a world where you say yes to even a few of these vendors, and the cost of securing the entire Ruby ecosystem looks like a rounding error in comparison.
At the end of the day, I doubt the investors care. If they want to cut costs, there are much better ways.