frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Shopify, pulling strings at Ruby Central, forces Bundler and RubyGems takeover

https://joel.drapper.me/p/rubygems-takeover/
110•bradgessler•1h ago

Comments

leakycap•1h ago
I wasn't expecting such a nice writeup. Worth a read.

The Ruby community has been eating itself alive since almost the beginning, but it is sad to see the short-sighted destruction of trust and connection that this has had.

softwaredoug•56m ago
> they had a problem with Ruby Central taking control of the RubyGems open source code repositories and gems, which Ruby Central never owned.

I don’t quite get how this happened? Ruby Central can’t just reach into my GitHub and declare they own something. Was it under the Ruby central account? Or an org account that decided they “own” the repo?

doctorpangloss•50m ago
It sounds like RubyGems was renamed to Ruby Central.
TechIsCool•48m ago
At the GitHub Enterprise level, you can see that reflected if you look at any of the users profiles https://github.com/mghaught
janpio•39m ago
That is explained in the "On 9 September, HSBT ..." paragraph, which describes how an existing RubyGems maintainer did - and then undid (most) - changes. A new user remained as an owner of the RubyGems GitHub organization - which allowed Ruby Central to do things later.
joeldrapper•39m ago
I said in the post that HSBT who was a maintainer invited Marty as an owner of the GitHub account. This was against the wishes of the other maintainers who had established practices for adding new maintainers.
infamouscow•53m ago
I have a difficult time reading this as anything other than a bunch of political activists upset and throwing a tantrum because they can't use their positions of relative power to manifest certain outcomes they personally desire.

The cultural hegemony that blue team activists have enjoyed is over, and now those with actual power are finally asserting it and ousting all of the trouble-makers.

I'm happy to be proven wrong here, but I really need evidence rather than some highfalutin argument that rests on reasoning by analogy.

Edit: I see more downvotes than replies. I suspect I'm correct.

apercu•48m ago
"The cultural hegemony that blue team activists have enjoyed is over, and now those with actual power are finally asserting it and ousting all of the trouble-makers."

That's your take?

I simply observe lawlessness.

infamouscow•45m ago
Please cite what applicable laws are being violated.

I have a hard time believing a company as large as Shopify or others using Ruby will take these actions without first consulting their legal departments. Maybe I'm wrong, but you have to cite an applicable law. Just saying something is lawless doesn't mean it actually is.

kkaske•51m ago
I don't follow this kind of thing so forgive my ignorance. Why was "platforming" DHH bad? Honest question.
sussmannbaka•47m ago
He’s been posting increasingly inflammatory articles, for the most recent round refer to https://tekin.co.uk/2025/09/the-ruby-community-has-a-dhh-pro...
DrProtic•26m ago
I'm sorry but if DHH posted some inflammatory articles maybe it's better to post those articles for people to judge themselves, than to post what someone else thinks.
bakugo•47m ago
He held the wrong political opinions.
4ndrewl•11m ago
He's regurgitating racist tropes. Whether he knows that or not I don't know. He might be racist, it might just be Dunning-Kruger around whether he can speak authoritatively on social issues (in his post there's no attempt at original thought, just copy-paste).

But...it makes it a little difficult to build an inclusive open source community with that at your head.

jjgreen•43m ago
Judge for yourself: https://world.hey.com/dhh/as-i-remember-london-e7d38e64 (a web search on "Tommy Robinson" would help with context).
rs_rs_rs_rs_rs•35m ago
Are you sure you posted the right article? There's nothing about Ruby or RubyGems in it.
madeofpalk•32m ago
The question was "Why was "platforming" DHH bad?". Some people disagree with the views represented in that linked blog post, and do not wish to sponsor events that showcase him.

Personally, I think DHH is a troll and would never be interested in sponsoring, or attending, an event that involved him.

vidarh•30m ago
There is, however, a whole lot that says a lot about the character of DHH in it, such as by repeating rhetoric of the UK's racist far-right.
bakugo•23m ago
Pushing everyone who doesn't have a 100% positive opinion on mass immigration under the label of "racist far-right" actively contributes to the strengthening of said "racist far-right". I hope you're aware of that.
philipwhiuk•9m ago
Stephen Christopher Yaxley-Lennon is openly racist and definitely far-right.
DrProtic•21m ago
If speaking of problems caused by immigration makes you racist far-right means you effectively can't speak about those problems.

Having a city turn from majority British to British being minority means something very strange and damaging is happening.

madeofpalk•15m ago
DHH has not spoken about the problems caused by mass migration. Just lamenting the fact that a country is apparently less white than it used to be.
bakugo•7m ago
He brings up several significant problems in his post, such as police arresting people for making anti-immigration posts on Twitter while real heinous crimes go unpunished. Your choice to refuse to acknowledge them as problems and attack a strawman instead doesn't change that.
jjgreen•8m ago
Londinium was founded by foreigners; bloody Italians coming over here and establishing our capital, mutter mutter ...
notwhereyouare•27m ago
David Heinemeier Hansson, also known by his initials DHH, is a Danish programmer, writer, entrepreneur, and racing driver. He is the creator of Ruby on Rails, a web framework written in Ruby.[1]
lbrito•34m ago
Having read stuff from DHH for a long time, this does not surprise me in the least. It just feels like he picked the right time, zeitgeist-wise, to fully come out of the closet.

I distinctly remember a specific Twitter comment, maybe 7ish years ago, that solidified my view on DHH as a person. It was a thread about remote work. Someone from South America commented trying to be nice to David, saying something like "you should work remotely from Chile, it has a great Ruby community" etc, to which his response was "I've no interest in living in a 3rd world country".

Notch-esque politics aside, that was mean-spirited, inconsiderate behavior which should not be applauded. From that day I strongly sensed that was who he truly was.

ecshafer•31m ago
What is the issue? He liked the nationalistic display of a march in England?
aduty•27m ago
That is the gist of it.
doublerabbit•22m ago
> He liked the nationalistic display of a march in England?

Replace "nationalistic" with "fascist". That's the issue.

bhouston•17m ago
Shopify's support for DHH's world view makes sense. Shopify's executive team has been right-wing for a while now:

https://pressprogress.ca/shopify-executives-right-wing-media...

https://disconnect.blog/the-conservative-tech-alliance-is-co...

basisword•14m ago
He's really gone off the deep end and evidently knows fuck all about London or the patriotic march he's discussing.
hamandcheese•41m ago
I too am wondering this.
icelancer•28m ago
DHH is not a left-leaning person and isn't afraid to say it. This is fine in the tech community generally but not in the open source community which is heavily left-leaning.
basisword•10m ago
People are free to lean left or right. Unfortunately bigotry and racism has been rebranded as simply being right leaning politically. Reading some of his recent articles he's neither left or right - just a bit of a racist bigot.
bryanlarsen•39m ago
Given the recent pwnage of part of the npm ecosystem, a panicked overreaction from Shopify & RubyCentral almost seems inevitable.
charcircuit•34m ago
Owning a source code project doesn't entitle you to admin in the github organization it belongs to, so I don't get why this article keeps hammering that point. Ownership of rubygems doesn't matter as all that's changing is members of a github organization.
_fat_santa•32m ago
> Sidekiq withdrew its $250,000/year sponsorship for Ruby Central because they platformed DHH at RailsConf 2025.

Honest question: What's the issue with DHH here? What did he do that caused them to pull support because he was platformed at RailsConf?

aduty•29m ago
He has been adopting a more conservative slant and that makes some people irrationally angry.
lavela•28m ago
"The Ruby community has a DHH problem":

https://tekin.co.uk/2025/09/the-ruby-community-has-a-dhh-pro...

dismalaf•28m ago
Probably the fact that DHH introduced Solid Queue to Rails which can replace Sidekiq. Of course they're not going to say that, it'll be some excuse about his lukewarm European politics...
vinceguidry•17m ago
The Ruby community has long had a rift between two types of members, the really nice folks that take after Matz, and techbro assholes like DHH. The former have mostly tolerated the latter creating an ugly toxicity that the community has become known for, and is why I use Ruby, but have not involved myself with it. Zed Shaw, a well-known asshole himself, described it in this piece: https://harmful.cat-v.org/software/ruby/rails/is-a-ghetto

DHH has been going off the deep end with his rhetoric for years, the current political environment has made it so that he can't be ignored anymore.

bhouston•16m ago
> the current political environment has made it so that he can't be ignored anymore.

But Shopify is also right wing in its executive team, and via these move they appear to be support DHH:

https://pressprogress.ca/shopify-executives-right-wing-media...

https://disconnect.blog/the-conservative-tech-alliance-is-co...

vinceguidry•8m ago
Right wing protects their own.
dismalaf•4m ago
Except Matz is aligned with DHH, Tobi and others. I think lots of people confuse "nice" with "supporting every weird American left-wing cause". Keep in mind most of the people who actually run the Ruby ecosystem and drive it forward aren't American, and it's mostly Americans whining about it.
baggy_trough•3m ago
It would be more accurate to say that the rift is between intolerant progressive activists and people who just want to work on the code without getting politics involved.
ZhadruOmjar•6m ago
They don't like his refusal of support for any and every cause. DHH focuses on software and it's capabilities instead of whatever the cause of the day is no matter how irrelevant.
tennis_80•3m ago
He used to, but is now stepping into politics, in a conservative / reactionary way.

See: https://world.hey.com/dhh/as-i-remember-london-e7d38e64

dismalaf•29m ago
Y'all know that Ruby Central has run rubygems and rubygems.org for years now, right? This isn't a coup, takeover, whatever. The author of the first article criticizing this was formerly employed by Ruby Central. They're just tightening up their own ship...
sussmannbaka•21m ago
this article isn’t about rubygems the service and it repeatedly states so
dismalaf•20m ago
If you know anything about the ecosystem you'd know that Ruby Central runs the website/servuce AND maintains the gems, bundler included. Which is why I mentioned both.
joeldrapper•20m ago
I don’t think you read the post. Ruby Central has never owned the source code. They operated a service that had the same name.
dismalaf•17m ago
Read an open source license for once.

If you have the source code, you own the source code. Other people own it as well. This is literally the defining feature of open source. If I have Ruby source code and Rails source code on my machine, I own it, no one can take it away or tell me what to do with it.

Anyhow, Ruby Central managed the GitHub repo, the website, the gem, bundler, etc... before this.

If some disgruntled former employee/contractor wants to hard fork they can, they also own the code. But I heard they've started a competitor and are looking for funding (probably part of the reason Shopify and others wanted to consolidate control; a maintainer with admin privileges starting a literal competitor is a liability).

NoNameProvided•29m ago
Can somebody provide an archive link? Trying to access the site, I get a Cloudflare security page that says my access has been blocked by some security rules.
OptionOfT•23m ago
https://archive.ph/tg8pQ
NoNameProvided•18m ago
Thank you!
croes•22m ago
https://web.archive.org/web/20250923163607/https://joel.drap...
ChrisArchitect•26m ago
Related:

Ruby Central's Attack on RubyGems

https://news.ycombinator.com/item?id=45299170

A board member's perspective of the RubyGems controversy

https://news.ycombinator.com/item?id=45325792

OptionOfT•23m ago
https://archive.ph/tg8pQ
bhouston•22m ago
Why were Samuel Giddins and André Arko singled out to be removed? What was their transgressions and to whom? From the write-up it sounds like Shopify wanted them out, but why?
janpio•19m ago
The article has a section about something that might be related: https://joel.drapper.me/p/rubygems-takeover/#rv
bhouston•12m ago
Quote:

> In his blog post, André says, “For the last ten years or so of working on Bundler, I’ve had a wish rattling around: I want a better dependency manager. It doesn’t just manage your gems, it manages your ruby versions, too. It doesn’t just manage your ruby versions, it installs pre-compiled rubies so you don’t have to wait for ruby to compile from source every time. And more than all of that, it makes it completely trivial to run any script or tool written in ruby, even if that script or tool needs a different ruby than your application does.”

> Bluesky threads reveal that Rafael França (Shopify / Rails Core) saw this tool as a threat, saying “some of the “admins” even announced publicly many days ago they were launching a competitor tool [rv] and were funding raising for it. I’d not trust the system to such “admin”.”

So a dev was innovating to better tool to meet their needs (which is what most open source maintainers are generally doing all day), and then some guys immediately jumped to the possibility that they would then actively sabotage RubyGems? Whoa, that is insane.

Trying to kill innovation and a start-up out of fear doesn't sound like Shopify's branding in the media.

ZhadruOmjar•8m ago
At some point the majority will learn that no matter the public messaging most large companies will do what benefits their incumbency over what is best for the industry or customers.
dang•17m ago
Related. Others? (most recent first:)

An Update from Ruby Central - https://news.ycombinator.com/item?id=45344448 - Sept 2025 (1 comment)

A board member's perspective of the RubyGems controversy - https://news.ycombinator.com/item?id=45325792 - Sept 2025 (148 comments)

Goodbye, RubyGems - https://news.ycombinator.com/item?id=45306135 - Sept 2025 (1 comment)

Ruby Central's response to the RubyGems situation - https://news.ycombinator.com/item?id=45301949 - Sept 2025 (1 comment)

Ruby Central's Attack on RubyGems [pdf] - https://news.ycombinator.com/item?id=45299170 - Sept 2025 (244 comments)

richardlblair•9m ago
I get that when drama unfolds like this there is going to be a shake out. It's always valuable, to some degree, to know what happened and why.

I just wish we could get to the part where the community can know and trust that our supply chain is safe and can be trusted.

Show HN: Production Deployable Prediction Market Platform, SocialPredict v0.0.4

https://github.com/openpredictionmarkets/socialpredict/releases/tag/v0.0.4
1•wwwpatdelcom•2m ago•0 comments

Artificial plant device purifies radioactive soil with sunlight alone

https://phys.org/news/2025-09-artificial-device-purifies-radioactive-soil.html
1•geox•5m ago•0 comments

Mage Lab v0.7.2

https://magelab.ai
1•germaincampman•7m ago•0 comments

Show HN: A personalized HN feed that learns from your favorites

https://hn.shaped.ai
8•tullie•7m ago•1 comments

MiniMeshT: A tiny terminal chat client for Meshtastic. No protobufs, no bloat

https://github.com/allanrbo/MiniMeshT
1•allanrbo•8m ago•0 comments

Seven Years of Firecracker

https://brooker.co.za/blog/2025/09/18/firecracker.html
2•eatonphil•9m ago•0 comments

Imec's superconducting chips to shrink power usage 100x (2024)

https://spectrum.ieee.org/superconducting-computer
1•campers•11m ago•1 comments

Show HN: Generate Realistic Fake Twitter/LinkedIn Posts-No Design Skills Needed

https://zapshot.in/
1•Fayaz_K•12m ago•0 comments

XposterAI: Engage with X Effortlessly

https://xposterai.com/
1•diydev•13m ago•1 comments

Master Lovable in 17 minutes (Starter Tutorial) [video]

https://www.youtube.com/watch?v=Vf2K0pcTLEo
1•doener•14m ago•0 comments

Parker: PARtitioned KERnel

https://lore.kernel.org/linux-pm/20250923153146.365015-1-fam.zheng@bytedance.com/
2•wicket•14m ago•0 comments

Phishing attacks with new domains likely to continue

https://blog.pypi.org/posts/2025-09-23-plenty-of-phish-in-the-sea/
2•todsacerdoti•16m ago•0 comments

OpenAI Announces Another GPU "Strategic Partnership"

https://theahura.substack.com/p/tech-things-openai-has-another-gpu
2•theahura•16m ago•0 comments

US Intel officials "concerned" China will soon master reusable launch

https://arstechnica.com/space/2025/09/us-intel-officials-cite-reusable-launch-as-difference-maker...
2•cryptoz•16m ago•0 comments

Amp Tab: fast and free AI suggestions for VS Code and forks

https://ampcode.com/news/amp-tab-for-all
4•beyang•18m ago•0 comments

State of Devs 2025

https://2025.stateofdevs.com/en-US
2•sneakerblack•18m ago•0 comments

Chrome Extension Fingerprinting in the Wild

2•AmazingTurtle•19m ago•0 comments

Seeing Is Deceiving:Mirror-Based Lidar Spoofing for Autonomous Vehicle Deception

https://arxiv.org/abs/2509.17253
1•bikenaga•21m ago•0 comments

On benchmarking: "measuring performance is hard" (2017)

https://ruudvanasseldonk.com/2017/07/09/on-benchmarking
2•davikr•23m ago•0 comments

Animation of the Callide Unit C4 incident [video]

https://www.youtube.com/watch?v=vbLvjFohK9g
1•GeoAtreides•24m ago•0 comments

Running a Linux Router on macOS

https://amodm.com/blog/2024/07/03/running-a-linux-router-on-macos
1•romac•24m ago•1 comments

OpenSSF warns that open source infrastructure doesnt run on thoughts and prayers

https://www.theregister.com/2025/09/23/openssf_open_source_infrastructure/
6•rntn•25m ago•0 comments

House Arab

https://bidoun.org/articles/house-arab
2•speckx•26m ago•0 comments

How AI slop is clogging your brain

https://www.npr.org/2025/09/08/nx-s1-5528762/ai-slop-attention-economy
2•stefap2•26m ago•1 comments

Show HN: Vault-AI – an open-source digital safe for AI secrets (v0.3.2)

1•vaultaiproject•27m ago•1 comments

'I regret to inform you Meta's new smart glasses are the best I've ever tried'

https://www.theverge.com/tech/779566/meta-ray-ban-display-hands-on-smart-glasses-price-battery-specs
1•MilnerRoute•28m ago•0 comments

We Built the Responses API

https://developers.openai.com/blog/responses-api/
1•dphuang2•30m ago•0 comments

US Secret Service disrupts telecom threat near UN GA with 100K SIM cards

https://www.bbc.com/news/articles/cn4w0d8zz22o
1•bhouston•31m ago•0 comments

Show HN: MiniTools – Privacy-focused online utilities (QR, passwords, colors)

https://www.minitools4u.com/
1•asifnawaz•32m ago•0 comments

Align Your Actions and Identity

https://kupajo.com/grow-inherently-not-apparently/
2•kolyder•34m ago•2 comments