Discussion
Loading...

Discussion

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Jan Lehnardt :couchdb:
@janl@narrativ.es  ·  activity timestamp 3 weeks ago

[Update: it was a hostile takeover: https://narrativ.es/@janl/115258495596221725]

What the fuck is going on with Ruby? For the moment we have to consider all gems compromised: https://pup-e.com/goodbye-rubygems.pdf

Ah, oof: https://indieweb.social/@sstephenson/115231391147943333

And even more context (bad): https://bsky.app/profile/mikemcquaid.com/post/3lz7klsyue22f

  • Copy link
  • Flag this post
  • Block
RootWyrm 🇺🇦:progress:
@rootwyrm@weird.autos replied  ·  activity timestamp 3 weeks ago

@janl you mean besides the person who controls all of it being a very proud Nazi?

  • Copy link
  • Flag this comment
  • Block
jacobian
@jacob@social.jacobian.org replied  ·  activity timestamp 3 weeks ago

@janl ok so yes this looks really really bad but:

""we were offered millions of dollars from a hostile donor in exchange for control of the RubyGems infrastructure” <-- that's a HELL of an accusation to make, and I can't see any evidence of that whatsoever. Is there something I'm missing?

Because otherwise until we learn more this really seems like a "never attribute to malice what you can attribute to incompetence" sort of situation - right?

  • Copy link
  • Flag this comment
  • Block
roland
@roland@devdilettante.com replied  ·  activity timestamp 3 weeks ago

broken ruby gems social scene or something 😄 #SorryBrokenSocialScene #RubyIsMyFavouriteProgrammingLanguageButItIsNotImmuneToTheFollyOfHumans :-)

  • Copy link
  • Flag this comment
  • Block
Jocelynephiliac :reclaimer:
@twipped@twipped.social replied  ·  activity timestamp 3 weeks ago

@janl they looked at npm and said “Hold my beer”

  • Copy link
  • Flag this comment
  • Block
Garbage Data 🦝
@anomalocarididae@furry.engineer replied  ·  activity timestamp 3 weeks ago

@janl I know this is about the programming language and presumably gems are a type of library or package, but for a second I thought "oh shit, are there any other langs named after gems like Ruby and Perl that are compromised"

  • Copy link
  • Flag this comment
  • Block
Dusty
@d1@autistics.life replied  ·  activity timestamp 3 weeks ago

@janl there's a ton of #Jekyll sites out there which are also #Ruby-based.

  • Copy link
  • Flag this comment
  • Block
Chris [list of emoji]
@suetanvil@freeradical.zone replied  ·  activity timestamp 3 weeks ago

@janl

It wouldn't be hard to just pull the gems from git directly, then put the commit IDs into a checked-in lock file the way mruby does it. From there, you could automate pushing the clones to your own repos if you need them.

  • Copy link
  • Flag this comment
  • Block
Tony Hoyle
@tony@toot.hoyle.me.uk replied  ·  activity timestamp 3 weeks ago

@janl What a mess.. and what does that mean for mastodon which is written in ruby.

  • Copy link
  • Flag this comment
  • Block
James Jefferies
@jamesjefferies@mastodon.me.uk replied  ·  activity timestamp 3 weeks ago

@janl arrrghhhh!

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.3.13 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login