frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

EchoJEPA: Latent Predictive Foundation Model for Echocardiography

https://github.com/bowang-lab/EchoJEPA
1•euvin•6m ago•0 comments

Disablling Go Telemetry

https://go.dev/doc/telemetry
1•1vuio0pswjnm7•7m ago•0 comments

Effective Nihilism

https://www.effectivenihilism.org/
1•abetusk•10m ago•1 comments

The UK government didn't want you to see this report on ecosystem collapse

https://www.theguardian.com/commentisfree/2026/jan/27/uk-government-report-ecosystem-collapse-foi...
2•pabs3•12m ago•0 comments

No 10 blocks report on impact of rainforest collapse on food prices

https://www.thetimes.com/uk/environment/article/no-10-blocks-report-on-impact-of-rainforest-colla...
1•pabs3•13m ago•0 comments

Seedance 2.0 Is Coming

https://seedance-2.app/
1•Jenny249•14m ago•0 comments

Show HN: Fitspire – a simple 5-minute workout app for busy people (iOS)

https://apps.apple.com/us/app/fitspire-5-minute-workout/id6758784938
1•devavinoth12•15m ago•0 comments

Dexterous robotic hands: 2009 – 2014 – 2025

https://old.reddit.com/r/robotics/comments/1qp7z15/dexterous_robotic_hands_2009_2014_2025/
1•gmays•19m ago•0 comments

Interop 2025: A Year of Convergence

https://webkit.org/blog/17808/interop-2025-review/
1•ksec•28m ago•1 comments

JobArena – Human Intuition vs. Artificial Intelligence

https://www.jobarena.ai/
1•84634E1A607A•32m ago•0 comments

Concept Artists Say Generative AI References Only Make Their Jobs Harder

https://thisweekinvideogames.com/feature/concept-artists-in-games-say-generative-ai-references-on...
1•KittenInABox•36m ago•0 comments

Show HN: PaySentry – Open-source control plane for AI agent payments

https://github.com/mkmkkkkk/paysentry
1•mkyang•38m ago•0 comments

Show HN: Moli P2P – An ephemeral, serverless image gallery (Rust and WebRTC)

https://moli-green.is/
1•ShinyaKoyano•47m ago•0 comments

The Crumbling Workflow Moat: Aggregation Theory's Final Chapter

https://twitter.com/nicbstme/status/2019149771706102022
1•SubiculumCode•52m ago•0 comments

Pax Historia – User and AI powered gaming platform

https://www.ycombinator.com/launches/PMu-pax-historia-user-ai-powered-gaming-platform
2•Osiris30•53m ago•0 comments

Show HN: I built a RAG engine to search Singaporean laws

https://github.com/adityaprasad-sudo/Explore-Singapore
1•ambitious_potat•58m ago•0 comments

Scams, Fraud, and Fake Apps: How to Protect Your Money in a Mobile-First Economy

https://blog.afrowallet.co/en_GB/tiers-app/scams-fraud-and-fake-apps-in-africa
1•jonatask•58m ago•0 comments

Porting Doom to My WebAssembly VM

https://irreducible.io/blog/porting-doom-to-wasm/
2•irreducible•59m ago•0 comments

Cognitive Style and Visual Attention in Multimodal Museum Exhibitions

https://www.mdpi.com/2075-5309/15/16/2968
1•rbanffy•1h ago•0 comments

Full-Blown Cross-Assembler in a Bash Script

https://hackaday.com/2026/02/06/full-blown-cross-assembler-in-a-bash-script/
1•grajmanu•1h ago•0 comments

Logic Puzzles: Why the Liar Is the Helpful One

https://blog.szczepan.org/blog/knights-and-knaves/
1•wasabi991011•1h ago•0 comments

Optical Combs Help Radio Telescopes Work Together

https://hackaday.com/2026/02/03/optical-combs-help-radio-telescopes-work-together/
2•toomuchtodo•1h ago•1 comments

Show HN: Myanon – fast, deterministic MySQL dump anonymizer

https://github.com/ppomes/myanon
1•pierrepomes•1h ago•0 comments

The Tao of Programming

http://www.canonical.org/~kragen/tao-of-programming.html
2•alexjplant•1h ago•0 comments

Forcing Rust: How Big Tech Lobbied the Government into a Language Mandate

https://medium.com/@ognian.milanov/forcing-rust-how-big-tech-lobbied-the-government-into-a-langua...
4•akagusu•1h ago•1 comments

PanelBench: We evaluated Cursor's Visual Editor on 89 test cases. 43 fail

https://www.tryinspector.com/blog/code-first-design-tools
2•quentinrl•1h ago•2 comments

Can You Draw Every Flag in PowerPoint? (Part 2) [video]

https://www.youtube.com/watch?v=BztF7MODsKI
1•fgclue•1h ago•0 comments

Show HN: MCP-baepsae – MCP server for iOS Simulator automation

https://github.com/oozoofrog/mcp-baepsae
1•oozoofrog•1h ago•0 comments

Make Trust Irrelevant: A Gamer's Take on Agentic AI Safety

https://github.com/Deso-PK/make-trust-irrelevant
9•DesoPK•1h ago•4 comments

Show HN: Sem – Semantic diffs and patches for Git

https://ataraxy-labs.github.io/sem/
1•rs545837•1h ago•1 comments
Open in hackernews

I'm leaving Ruby Central

https://gist.github.com/simi/349d881d16d3d86947945615a47c60ca
204•retrorubies•4mo ago

Comments

retrorubies•4mo ago
I’ve always acted as a community-oriented person, so I feel it’s my duty to share what really happened, what the current state is, and why Ruby Central has failed in the eyes of the community. This is my perspective — and why I’m leaving Ruby Central by choice, but am being forced out of Bundler, RubyGems, and RubyGems.org.
bradly•4mo ago
fwiw... rubygems.org was one of the only open source projects I contributed to on a regular basis (albeit once every year or two) and it was always a positive experience. Sorry its gone this way for you and others.

This all reminds me of the feelings after Merb was put down after pressure from Engine Yard so they could guard against their Ruby on Rails hosting business.

hosh•4mo ago
Do you have a source for that? I always wondered why Merb disappeared, even after Katz refactored Rails to use ideas from Merb.
bradly•4mo ago
Straight from the Katz mouth via https://yehudakatz.com/2020/02/19/together-the-merb-story/:

> But not everyone felt so good about it. I worked for Engine Yard, and we had made our mark selling Ruby on Rails deployment to large customers like Groupon, Kongregate and Github. I got hired at Engine Yard in part because the company's founders were worried that Rails wouldn't make it long-term. They wanted to hedge against this possibility.

> Unfortunately for me, waging an all-out war against Ruby on Rails from inside of a company that makes its money selling Ruby on Rails deployment is a pretty bad life strategy.

> I don't know everything that went on behind the scenes, but Engine Yard's management eventually asked me to consider merging with Rails. If I'm being honest, they pushed me to consider merging with Rails.

I'm sure there were other reasons for the merge as well, and I don't want to take anything away from Yehuda and the decision he made at the time, but I was a volunteer at the first MerbConf just a couple months before the "merge" and it all felt very sudden and at odds with the direction the project was headed. I had my cynical take that EY was behind the move, but those were just my personal feelings. Honestly it was refreshing to read Yehuda's story 12 years later as it helped put some of the pieces together as to why.

cyanydeez•4mo ago
the best evidence of unilateral decision making is the basic fact that github provides a direct route to _open issues and discuss changes_.

Did they do that?

dzdt•4mo ago
This post jumps into the center of some controversy in a very unclear place. Is there a short (preferably neutral) summary of what this is all about somewhere?
LightBug1•4mo ago
See the link in the third paragraph of this fine article.
dygd•4mo ago
Discussed today: https://news.ycombinator.com/item?id=45348390
shadowgovt•4mo ago
Oof. I'm sad to see this happen.

I got off the Ruby and Rails trains ages ago (around the time that Rails changed the package management solution it used; that convinced me the whole project was not in its "adults in the room" phase yet and I couldn't be bothered to keep up with a project that would require me to pay attention to it every quarter instead of putting a project down for a year and having it mostly work when I picked it up again). Sad to say this kerfluffle hasn't exactly shifted my opinion of the ecosystem.

moritonal•4mo ago
Contextually it might be relevant that Ruby Central said they wanted to have a Zoom call today to explain everything, then cancelled it. This was their message.

"Hello Ruby Community, We recognize that our originally scheduled Q&A session overlaps with the observance of Rosh Hashanah and may not have been the best timing for many in our community. We sincerely apologize for the short notice of this change, especially since the session was set to take place tomorrow. In response to the feedback we’ve received, we’ve made the decision to postpone the session. A new date and time will be shared with you in the coming days. In the meantime, we invite you to watch this statement from our Executive Director. This update is intended to ensure everyone receives the same information and can view it at a time that works best for them."

827a•4mo ago
Wow. I've seen less corpowashed decision making out of Microsoft. They set their house on fire, its burning down, but spraying water on it would get the curtains wet so we can't do that.
apercu•4mo ago
That's hilarious. "Our business decisions are questionable but for religious reasons we can't talk about it right now now"
dismalaf•4mo ago
It's literally a culture's New Year's Day and a holiday...
827a•4mo ago
There's an old piece of advice: If a girl cancels on you without taking the initiative to reschedule, it doesn't matter what the reason is, she's not interested.

In other words: They aren't respecting the holiday. They're using it as an excuse.

moritonal•4mo ago
It's more the "we have to move the meeting, but can't say when, please forget about this"
charcircuit•4mo ago
>This is not how open source works.

Open source is about licensing and not about governance. There are plenty of open source projects where the owner is a dictator. In this case the owner of the github organization has control over who is a part of it and who has permissions within it.

shermantanktop•4mo ago
Open Source as a licensing approach, sure, but that’s the narrow definition. The broader definition is inclusive of group culture, decision-making practices, tone of communication, and a lot more.

When someone says “open source,” that’s often shorthand for the broader definition.

kace91•4mo ago
Soo let me see if I get the context.

Ruby central was short for cash, Shopify used that to pressure them into a takeover of several core community repos like bundler so that Shopify can control those indirectly? Is that it?

jaredcwhite•4mo ago
In a word, yes.
kace91•4mo ago
What I don’t get is, what does Shopify get from this?

I’m assuming there’s a ton of reputational risk in this move, and my understanding as an outsider is that Shopify already has a ton of weight in the Ruby ecosystem - they seem to be the one case quoted by everyone as the “proof that Ruby scales”.

pityJuke•4mo ago
From all I can observe, it does seem to have a sinister political undertone. In that, Ruby Central's collapse started because Sidekiq disagreed with them platforming dhh, and then Shopify (who has dhh as a board member, and whose CEO races with dhh) used the funding weakness to demand a purge of anyone they disagreed with.

As an aside, I imagine the discussion of this will be end up being... difficult, because people are tending not react to these sorts of things well.

lamontcg•4mo ago
> who has dhh as a board member, and whose CEO races with dhh

Oh, so this is just dhh doing a hostile takeover of core ruby infrastructure where previously he had to try to work with people, now he can just tell people what he wants to be done, because they work for him.

ksec•4mo ago
>Ruby Central's collapse started because Sidekiq disagreed with them platforming dhh

I remember Ruby Central denied they ever tried to deplatform DHH. But now when they are platforming DHH Sidekiq wants out.

I honestly think it is may be way simpler. Shopify is willing to sponsor and put money into it but they also want it done ASAP, preferably now. They give a deadline and Ruby Central didn't think, plan or act until too late.

And the moment it was badly done, politics creeps in.

th0ma5•4mo ago
Money. Some people seek to extend their claimed intellectual property into previously uncapitalized contexts.
flkiwi•4mo ago
There are arguably larger reputational risk issues in a company with significant financial/payment activities not having adequate control of their technology. I'm not saying that justifies anything here as I don't know nearly enough about, but I'd wager that even a minor incident arising from them not adequately controlling their stack would create infinitely more issues than this move.
apercu•4mo ago
Supply chain attacks are big shareholder news lately?
hiharryhere•4mo ago
If supply chain integrity is the issue specifically for Shopify, couldn’t they run their own private, internally facing gem repository and whitelist everything that goes there? It’s not a requirement to use the public rubygems.
flkiwi•4mo ago
That's not what I said. I was responding to the parent comment's statement that "I’m assuming there’s a ton of reputational risk in this move" by noting that, in relative terms, this likely isn't something people are paying attention to outside a very, very narrow universe.
3eb7988a1663•4mo ago
I too am scratching my head at this. If the problem is the outside community could be a risk, just do not drink from the firehose. Have processes in place to slowly vet and bring the outside world indoors.

Then again, that is not a very web scale suggestion.

hobs•4mo ago
I dont understand how "well let's just manage the entire ecosystem" could help this problem.
kenhwang•4mo ago
They probably thought it would be easier to takeover rubygems than ensure every dev and every machine for every possible ruby tool could be and is pointed at the internal gem repository.

Let's be paranoid for a moment. What if there's a supply side attack on a gem used by Homebrew. That's basically installed on every dev machine, auto-updates automatically/silently, could have sudo, that no one would care or even know how to point at a private gem repository.

yakshaving_jgt•4mo ago
It was my understanding that they wanted to use Nix to solve this problem.
jcmfernandes•4mo ago
Exactly. While it seems like the overarching goals were well-suited, the process was... WTF.
rmoriz•4mo ago
They are a multi-billion company that is highly dependent of RubyGems and a breach could ruin their business. So they have intrinsic reasons to support anything that keeps Ruby and Rails floating.
bartread•4mo ago
That makes sense but, to put it mildly, I am not whatsoever a fan of corporate controlled and directed OSS. I'm even less of a fan of it when it's effectively controlled by only one corporation. The temptation to play high-handed with the community, and with the future, is overwhelming and not one that corporations seem able to resist. One example: Chromium, which is now effectively worthless as a serious web browser with support for MV2 removed, thus meaning that uBlock Origin (and the like) no longer work, due to Google forcing the issue with MV3.
rmoriz•4mo ago
I don't see the controlling aspect materializing, except forcing Ruby Central to build a reliable organizational structure. There are companies that are way more involved in controlling projects. Cloud providers or CDNs that start to sponsor, but after a while lose interest unless specific adjustments are being made.

I doubt there will ever be a run-time dependency of rubygems with Shopify. I would be more alarmed if, say, Microsoft GitHub™, Google, Cloudflare would "step up to safe the project".

bigiain•4mo ago
... so they locked out the main security contributor, and didn't see a need to replace them?
kelvinjps•4mo ago
Isn't most of the reputational risk going to Ruby Central?
kmacdough•4mo ago
I suspect they underestimated the lashback. They wanted to make their changes whenever they wanted, to fit their specific needs. They didn't think twice about the community, so much so that they didn't consider the community might not stand for it.

And history ain't written. Who knows how this will hurt them.

kimos•4mo ago
It’s easy to point at politics or people and some sinister motive. Maybe that’s what it is. But don’t underestimate what can be accomplished through incompetence.

Shopify is a multi-billion dollar company that has processed over a trillion dollars. They are a high value target for sophisticated attackers. It’s entirely possible they are trying to accomplish some security and supply chain goals to protect their Ruby pipeline, but completely messed up the execution and did not predict the community interpretation and backlash.

plorkyeran•4mo ago
We know very little about what happened between Shopify and Ruby Central. They said that they made no progress towards satisfying Shopify’s demands until they were 24 hours from the deadline, but not what those demands specifically were or why they failed to do anything. It’s possible that what they panickedly did at the last second wasn’t actually what Shopify had intended.
zorpner•4mo ago
DHH joined their board in 2024 [0], and is using this opportunity to purge people he disagrees with politically from the Ruby ecosystem. It really is as simple as that.

0: https://www.shopify.com/news/david-heinemeier-hansson-board

teeray•4mo ago
> Ruby central was short for cash, Shopify used that to pressure them into a takeover of several core community repos like bundler so that Shopify can control those indirectly

Sounds like a variant of the xz takeover, but using money this time and in public.

ChrisArchitect•4mo ago
Related:

Shopify, pulling strings at Ruby Central, forces Bundler and RubyGems takeover

https://news.ycombinator.com/item?id=45348390

Ruby Central's Attack on RubyGems

https://news.ycombinator.com/item?id=45299170

A board member's perspective of the RubyGems controversy

https://news.ycombinator.com/item?id=45325792

the__alchemist•4mo ago
Tangent: IMO this is why you keep your repos under your account, and don't give them over to a group acct. Unless you no longer want/care about control, or things like this happening. If that's the case and you've moved on or are OK with moving on, then do the group account.
viraptor•4mo ago
I'm large enough environments, it's not really safe to use individual accounts. A hack/takeover while someone's on holidays could take days to resolve. People leaving the project, getting sick, dying would cause havoc on processes and ownership. Once thousands of people depend on your project, you really should move it into an org with others.
jonquark•4mo ago
For those (like me) who didn't understand what MINASWAN means, it stands for Matz Is Nice And So We Are Nice: https://en.m.wiktionary.org/wiki/MINASWAN
chuckadams•4mo ago
Not that he has any real power here, but has anyone asked Matz what he thinks about all this?
kimos•4mo ago
He usually just stays out of this stuff.

The funny thing about inventing a language you love, is you spend your career writing C rather than actually writing code in the language you love.

em-bee•4mo ago
pike devs put it this way: we are writing C so you don't have to.
dismalaf•4mo ago
He's pretty tight lipped about his opinions. He does seem to get along with DHH and Tobi though, he shared a stage with them at one Rails World...

Also I doubt the culture warriors are going to get what they want from Matz, he's a devout Mormon, a religious group known for conservative beliefs.

thebrog•4mo ago
It's usually conservative religious groups that are culture warriors, so this would be getting what they want
1a527dd5•4mo ago
Crazy to see that embrace, extend, and extinguish are still fundamental game plans.

I guess the only lesson here is trust no one and keep your repos under your account.

istjohn•4mo ago
How does this fit the EEE pattern? For reference, here is Wikipedia's description of EEE:

> "Embrace, extend, and extinguish" ... is a phrase that the U.S. Department of Justice found was used internally by Microsoft to describe its strategy for entering product categories involving widely used open standards, extending those standards with proprietary capabilities, and using the differences to strongly disadvantage its competitors.

Not every instance of corporate bad behavior in open source is EEE. Shopify isn't in competition with open source or potentially threatened by open source. They are not extending open standards or technology.

Maybe I'm being pedantic, but I'd rather not muddy the water with unhelpful, sloppy metaphors.

charcircuit•4mo ago
Also, that wikipedia quote is wrong as it wasn't used internally at Microsoft.
tuyosvawnt•4mo ago
it was never clear what the niche of Ruby was other than being a modernish scripting language for non-critical web dev. I remember Ruby on Rails becoming trendy for web startups with inexperienced programmers (I was one of them) to prototype things in because Active Record was a simple ORM for its time, outside of that there wasn't much other justification for the stack and since the proliferation of similar easy-to-use frameworks in other languages it hasn't been necessary
paulddraper•4mo ago
> it was never clear what the niche of Ruby

Ruby on Rails

Chef

---

Some of the largest websites in the world run on Ruby: GitHub and Shopify.

rmoriz•4mo ago
Chef seems to be almost dead. I'm still using it personally but don't know a single company in Germany still using it.
paulddraper•4mo ago
I was responding to “it was never clear”

Ruby was used, for example, as the DevOps language prior to Go

hosh•4mo ago
The proliferation of frameworks came about from the ideas and design of Ruby on Rails. MVC and ORM had been around before web apps, but it was not consistently used in a web framework until Rails. Convention-over-configuration, “nested doll pattern”, and Rack protocol were all ideas widely ported and copied into other language platforms and frameworks.

Also, ActiveRecord gained significant capabilities with named scopes, something that isn’t as widely copied.

Finally, Ruby itself lends itself well to writing DSLs, something that Javascript and TypeScript sucks at, but sometimes I still see people try and fail.

To be fair, it is my personal opinion that there has not been anything substantially innovative since Rails 5. The features I have seen since is better done with Elixir/Phoenix, mainly because the BEAM runtime makes better concurrency primitives available.

dcrazy•4mo ago
> MVC and ORM had been around before web apps, but it was not consistently used in a web framework until Rails.

WebObjects and EOF were the MVC and ORM frameworks powering Disney (Go.com) almost a decade before Rails existed.

hosh•4mo ago
Were those tech open source?

A decade before Rails puts it in 1995. Do you have some resources on this? I like looking into the history of tech.

dcrazy•4mo ago
They were not open source. They were essentially NeXT’s only successful product. https://en.wikipedia.org/wiki/WebObjects

WebObjects was rewritten from ObjC to Java in the 2000s. EOF, the ORM layer it shared with NeXTSTEP/OPENSTEP, was rewritten as Core Data and released in Mac OS X Tiger.

mandevil•4mo ago
WebObjects was demo'd in 1995, and Version 1.0 was released in March 1996, by NeXT (Steve Jobs and crew). In 1997 when Apple bought NeXT and made Jobs its CEO again, it became part of Apple who open sourced it in 2006 and maintained it until 2009 (it powered iTunes, among other things).
cortesoft•4mo ago
Ruby has been my favorite programming language by far for 20 years now. The design decisions just make sense to me, and it is always fun to write.

It really occupies the same niche that Python does, but personally I find ruby more pleasant to work with in every way.

glimpse9348•4mo ago
Just a glimpse:

> London is no longer the city I was infatuated with in the late '90s and early 2000s. Chiefly because it's no longer full of native Brits [1]

[1] https://world.hey.com/dhh/as-i-remember-london-e7d38e64

tibbydudeza•4mo ago
I am so disappointed by this - thought he was a nice guy.
mr90210•4mo ago
For some reason I always had a feeling about him. Perhaps I couldn’t understand why a guy that did so well in life like him found so much time to pick fights on Twitter. With the kind of money he had, I’d pay to be anonymous.
rmoriz•4mo ago
I've seen a lot of "formerly nice guys" falling. It's very hard to let people go and to deal with them if necessary (like using their project). To this date I can't understand why he went this route. He's successful, family guy, very rich. Why going after immigrants, poor, diverse people? Same with Musk. He's a prototype awkward guy yet he started a holy war against all DEI. WTF. Don't get it.
wahnfrieden•4mo ago
dhh is fully mask-off maga

He also has a history of this kind of posting

> There was the post where he described an ad featuring a plus-sized Black women as “grotesque” and celebrated the ads being replaced with ones featuring “blond babies”

mr90210•4mo ago
Strange take for a Danish living in the US.
KevinMS•4mo ago
I'm baffled this is considered wrongthink. A place is more than a place, its a native culture too.
duxup•4mo ago
Someone took over the supply chain … to save the supply chain from someone taking it over?
rmoriz•4mo ago
Ruby Central should have been more involved in the development of rubygems (software) in the past and establish a community and contribution guideline, to secure the project, secure funding, maybe separating concerns (infrastructure, conferences, etc.)

However, taking away funding as retaliation for a conference talk is offensive, too. In the end facts (money) made the decision. I don't think Shopify has bad intentions.

Clearly, it's about the racists tweets and blog posts one prominent member of Rails has made. And the community needs to address this in a clear way. Not with boycotting the wrong parties, especially an infrastructure provider of our community. Thank you Sidekiq for supporting RubyGems in the past, but pulling the plug was not the best move for the community.

ipaddr•4mo ago
From my reading it was about rv the new tool that hopes to replace rubygems and the push to remove the competition.

The losing of sponsorships because of the talk is what gave shopify leverage. And they used it.. out of fear over the rv tool.

rmoriz•4mo ago
The offensive statement from the 'rv' readme is clearly alarming. Shopify, as every other Ruby user, is highly dependent of a working rubygems infrastructure. I can fully understand their motivation, to clarify the situation and to implement rules and separation of concerns. However, it's clear, that the whole process was a disaster in communication, planning, execution by Ruby Central.
hosh•4mo ago
Chances are, this will make rv into a bigger success. Assuming the rv developers delivers on their promises. (I tried using their first version on launch only to find that the features I wanted have not been written yet).

Where are you getting that Shopify fears rv?

ipaddr•4mo ago
They want Andre gone and won't allow him back according to the gist and this started because of the August 26 release where shopify starts worrying about security.

The tool looks to replace gems and it's ecosystem.

pygy_•4mo ago
And the best way to build trust in the new tool is naturally to sabotage the old one.

rv builds on André's reputation. The best way to squander it would be to attack the rubygem infrastructure.

jcmfernandes•4mo ago
An individual decided to stop donating 250k to an organization because he felt strongly about actions taken by the organization. How is this offensive?
rmoriz•4mo ago
To my knowledge: Sidekiq is the lead project of Contributed Systems LLC. Ruby Central also announced to end the "RailsConf" series after this year.

I fully understand and support to be angry about and cut all ties to the 3-letter-guy, but I think this Ruby Central/Rubygems issue is a case of "friendly fire".

jcmfernandes•4mo ago
It's widely known - there are podcasts focusing on this - that Contributed Systems LLC is a one-man show.
nicce•4mo ago
Imagine if someone did the same for Rust. I could not count all new crab languages.
nenenejej•4mo ago
The solution is to design package managers around the uniform resource identifier: a way to locate online assets that is mostly (ignoring DNS) decentralised and better than having one org own all the packages.
hosh•4mo ago
That sounds like a neat idea. Do you have a proposal for that?

Would it be compatible with specifying urls (such as git repos)?

hiharryhere•4mo ago
Bundler already does this.

  # From a specific branch
  gem 'my_gem', git: 'https://github.com/user/my_gem.git', branch: 'development'

  # From a specific tag
  gem 'my_gem', git: 'https://github.com/user/my_gem.git', tag: 'v1.2.3'

  # From a specific commit (ref)
  gem 'my_gem', git: 'https://github.com/user/my_gem.git', ref: 'a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0'
hosh•4mo ago
Yes, I know bundler does that. But I thought we were talking about urn instead of uri. Seems I was mistaken.
cortesoft•4mo ago
You can absolutely use bundler and gem without touching the rubygems servers. You can point to an alternate rubygems host (including one you run yourself), point to a git repo, or a local gem file source
rmoriz•4mo ago
This resembles the "monolith" vs "micro-services" discussion. If you spread the packages over thousands of domains, hosts, providers, reliability will be horrible. And it's uncontrollable. In theory, RubyGems could run code analyzers on all uploads to detected malware. Good look if you just haven an index of repositories/packages hosted elsewhere.
nenenejej•4mo ago
Step 2: store a copy of the library in your repo.

Sounds nut? We used to do this with .dlls in sourcesafe and was fine. boring.

notatallshaw•4mo ago
Taking PyPI as a central place of packages, it is known that their bandwidth bill would be $1.8+M per month (https://dustingram.com/articles/2021/04/14/powering-the-pyth...) were it not for Fastly giving them a 100% discount.

Are there any reliable decentralized package distribution systems operating at within 2 orders of magnitude of that scale? How do they handle administrative issues such as malicious packages or name squatting? Standards updates? Enforcement of correct metadata? And all the other common things package indexes need to handle.

I'm clearly skeptical, but would be very interested in any real world success stories.

hellcow•4mo ago
Go does this, and I’d say it’s been highly successful.
nextaccountic•4mo ago
There is, the web. The web distributes code directly to end users at a much larger scale. To distribute the bandwidth costs, the web is federated: to depend on a script you refer to its url, and whoever hosts this url foots the bill.

Deno is a Javascript implementation for the backend that attempts to mimic this pattern (it later introduced a more npm-like centralized repository, but afaik it's optional). Deno is of course less popular than Python, but its url-centered model can really scale imo.

notatallshaw•4mo ago
> There is, the web. The web distributes code directly to end users at a much larger scale. To distribute the bandwidth costs, the web is federated: to depend on a script you refer to its url, and whoever hosts this url foots the bill.

But the Web is notorious for the problems I listed, you end up with standards around not following standards. It leaves almost all the responsibility on the client tool (browser or whatever) to do validation to stop malicious sites, name squatting, accepting and "fixing" poorly constructed metadata etc.

> Deno is a Javascript implementation for the backend that attempts to mimic this pattern (it later introduced a more npm-like centralized repository, but afaik it's optional). Deno is of course less popular than Python, but its url-centered model can really scale imo.

I was not familiar with Deno, I've done some shallow reading on this now and it's certainly interesting. I don't know enough about the JavaScript world to make a comment on the pros or cons.

But I don't think can work for Python, as transitive dependencies would immediately conflict as soon as dependencies required a different version of the same transitive dependency. And the guarantee of Python packaging is you only have a single version of a library installed in an environment, while it can cause some dependency solver headache, it also solves a lot of problems as it makes it safe to pass around objects.

pmontra•4mo ago
> My critique is directed at the process, not at people.

People are not logs floating helplessly in a river. People take decisions and make things happen. They create and run the process, not viceversa.

The critique must be directed at people.

Terr_•4mo ago
Right, people build Unaccountability Machines [0] to shield themselves, which range from justified to malicious.

[0] https://press.uchicago.edu/ucp/books/book/chicago/U/bo252799...

fencepost•4mo ago
As a complete outsider I mostly find myself wondering if there's legal recourse for those who were forced out (noting the clear distinction that one person was commenting on between the service owned by Ruby Central and the code that Ruby Central likely has no legal claim to).
Fokamul•4mo ago
OT: DHH speaks true, not everything, but mostly yes. London is a hellhole, same like other big cities for example in Germany. (In my country (CZ), Germany is called new middle east, lol)

And as a bonus, you don't have any rights to self-defence, you cannot own a gun, in UK you cannot even use dumb pepperspray for defense, ridiculous. Great to live in country, where your only option for self-defense is to lay on the ground and die or be raped, while you wait for police.

All these lefties do is to destroy, they don't want to discuss anything.