Ruby central was short for cash, Shopify used that to pressure them into a takeover of several core community repos like bundler so that Shopify can control those indirectly? Is that it?
Ruby central was short for cash, Shopify used that to pressure them into a takeover of several core community repos like bundler so that Shopify can control those indirectly? Is that it?
I’m assuming there’s a ton of reputational risk in this move, and my understanding as an outsider is that Shopify already has a ton of weight in the Ruby ecosystem - they seem to be the one case quoted by everyone as the “proof that Ruby scales”.
Shopify is a multi-billion dollar company that has processed over a trillion dollars. They are a high value target for sophisticated attackers. It’s entirely possible they are trying to accomplish some security and supply chain goals to protect their Ruby pipeline, but completely messed up the execution and did not predict the community interpretation and backlash.
I doubt there will ever be a run-time dependency of rubygems with Shopify. I would be more alarmed if, say, Microsoft GitHub™, Google, Cloudflare would "step up to safe the project".
As an aside, I imagine the discussion of this will be end up being... difficult, because people are tending not react to these sorts of things well.
Oh, so this is just dhh doing a hostile takeover of core ruby infrastructure where previously he had to try to work with people, now he can just tell people what he wants to be done, because they work for him.
I remember Ruby Central denied they ever tried to deplatform DHH. But now when they are platforming DHH Sidekiq wants out.
I honestly think it is may be way simpler. Shopify is willing to sponsor and put money into it but they also want it done ASAP, preferably now. They give a deadline and Ruby Central didn't think, plan or act until too late.
And the moment it was badly done, politics creeps in.
And history ain't written. Who knows how this will hurt them.
Let's be paranoid for a moment. What if there's a supply side attack on a gem used by Homebrew. That's basically installed on every dev machine, auto-updates automatically/silently, could have sudo, that no one would care or even know how to point at a private gem repository.
Then again, that is not a very web scale suggestion.
0: https://www.shopify.com/news/david-heinemeier-hansson-board
Sounds like a variant of the xz takeover, but using money this time and in public.