11 ms·
Gem.coop
- halicarnassus 1y agoGreat move to counter the hostile takeover of the RubyGems GitHub repo (not the rubygems.org repo) and organization by Ruby Central. I hope they find financing to cover hosting costs.
- joeldrapper 1y agoI believe the hosting is already covered.
- mijoharas 1y agoIs there anything more you can share about that? I guess I should just sign up to the newsletter and wait and find out...
- NARKOZ 1y agoFYI, this is Ruby Central's response: https://rubycentral.org/news/our-stewardship-where-we-are-whats-changing-and-how-well-engage/ https://rubycentral.org/news/our-stewardship-where-we-are-wh...
- steveklabnik 1y agoThis cannot be a response, as it was posted days before this was released.
- dubbel 1y agoThe response you link to was published on September 30, 2025, so it's not the response to gem.coop? I'd say gem.coop is the response to Ruby Central's actions?
- sleight42 1y agoWhy is this flagged? This is super relevant to HN!
- wahnfrieden 1y agoBrigading
- captn3m0 1y ago+1.
- lcnPylGDnU4H9OF 1y agoI wrote this comment with what I understand to be the relevant context: https://news.ycombinator.com/item?id=45490531 https://news.ycombinator.com/item?id=45490531
- bloudermilk 1y agoIt’s amazing to see the open source community step up like this. Kudos and gratitude to everyone that made this happen!
- lemper 1y agoyeah, but still, the maintainers need to be paid for their time and expertise. not to mention, although bandwidth and storage is cheap, somebody still have to foot the bill. i suggest people donate to this project.
- splittydev 1y agoIs there any context on why? Is there some controversy regarding RubyGems.org I'm not aware of?
- KingOfCoders 1y agoAs I understood it, to secure (their words) the supply chain, they took ownership of the code and repo (which others disputed as being owned by them) and kicked out users from Github. It is said the underlying cause is that devs push rv which is threatening RubyGems.
- mosselman 1y agoHow is rv threatening rubygems? I am pretty excited about rv on first glance, I tried it and it was too beta when I did to work nicely, but definitely good to have a uv type tool for ruby.
- KingOfCoders 1y ago"Yes, I agree. And some of the “admins” even announced publicly many days ago they were launching a competitor tool and were funding raising for it. I’d not trust the system to such “admin”." https://bsky.app/profile/rmfranca.bsky.social/post/3lz7alpobhc2x https://bsky.app/profile/rmfranca.bsky.social/post/3lz7alpob... See https://spinel.coop/ https://spinel.coop/ "Spinel develops rv, the next-generation Ruby version manager"
- phoronixrly 1y agoThis doesn't explain how rv is threatening rubygems in any way.
- KingOfCoders 1y ago[flagged]
- phoronixrly 1y agoI hope they tackle the actual main issue with Rubygems -- lack of any sort of code signing... (I know the functionality exists, but it's not required to publish in Rubygems, and off by default on gem install. In other words it's as if it doesn't exist) The fash problem in the Rails ecosystem is next on the list, and I hope there is community consensus to fork this as well.
- burnt-resistor 1y agoIt has code signing. It's just optional, inconvenient, and so unused because of Tragedy of the Commons and complacency. https://guides.rubygems.org/security/ https://guides.rubygems.org/security/ https://www.benjaminfleischer.com/2013/11/08/how-to-sign-your-rubygem-cert/ https://www.benjaminfleischer.com/2013/11/08/how-to-sign-you...
- phoronixrly 1y agoAs I said, it's as good as no code signing. The very lack of a chain of trust stemming from rubygems that can be used to verify gem authenticity makes the whole thing useless.
- simianparrot 1y agoWhat does “fash problem” mean?
- phoronixrly 1y agoIf you know you know.
- ramon156 1y agoThere's some weird opinions coming from mostly DHH. My personal take is that they're blatantly racist, but everyone can have their own Here's some fun facts: - DHH enforced a "No Politics at Work" policy. - DHH wrote a post expressing that he wouldn't want to live in London anymore because it's "no longer full of native Brits", and expressed support for a Tommy Robinson march he called "heartwarming". Tommy Robinson is described as "an anti-Islam campaigner and one of the UK's most prominent far-right activists.". The march DHH praised featured speakers calling for ethnic cleansing via "remigration" and banning all non-Christian religions. - DHH also promoted "demographic replacement" conspiracy theories and used language connecting immigration to crime, particularly regarding "Pakistani rape gangs" and street theft. - DHH has been publicly critical of Diversity, Equity, and Inclusion initiatives. This one isn't backed by facts, so take it with a grain of salt.
- steve_gh 1y agoI'm really pleased to see this happening, but sad that it has come to this. What I'd really like to see is a whole bunch of people acting more professionally. Who you pray to, who you vote for, and who you sleep with are irrelevant to a professional context - and open source development is a professional context. So everyone needs to keep their professional and personal lives separate. I know that at best I would be disciplined, and at worst sacked if I made comments on the lines that some of the lead players in this sorry saga have made. And that's not pointing the finger at any one person.
- hiimkeks 1y agoIf who you vote for will put me into a torture camp (or otherwise devalues my life or personhood), then I can't work with you, so no it is not irrelevant. (neither the "me" nor the "you" here refer to you or me personally ofc.)
- deleted 1y ago[deleted]
- pil0u 1y agoAgreed. Your example could sound like exaggerated, but silence is a form of opinion, of vote, of approval. Even in a professional context, because work is part of the society we live in. This whole "DHH situation" with Rails has put my mind in weird position. I admire the Rails creator, the business man, the speaker. I admire what he builds, how passionate he is about his work and open-source software. But I very strongly disagree with his vision of immigration, nationalism, parenting, well most of his vision of society. I was made aware about these opinions because people talked about it. Thanks to these people, I read and listen to him with more nuance, more critical thinking. That does not necessarily mean I would discard Rails, cancel the dude or write shit about him, but that surely means that I will be more careful about how the opinions of this 1 person could impact mine, the ecosystem I work with and the larger ecosystem I live in that is society.
- kortilla 1y ago
- SSLy 1y agoflagged??
- milliams 1y agoBased on the comments getting downvoted, it feels like some brigading going on.
- joeldrapper 1y agoWhy has this been flagged?
- lcnPylGDnU4H9OF 1y agoJust some background: there is a controversy in the Ruby community[0][2] around the governance of the rubygems project. It has been maintained for a long time by employees of Ruby Central but not in a corporate capacity. There was a recent hostile takeover of this project by the Ruby Central corporate arm. The most likely reason it was flagged from my perspective is that David Heinemeier Hansson (who created rails) is kind of the figurehead of this community and he has controversial opinions[1] which people believe make him unfit to represent their community. The controversy has manifested as people speaking out against DHH in his position. So this post seems to have been flagged for being "political" because it is seemingly in opposition to rubygems for the DHH reason. 0: https://hn.algolia.com/?dateRange=pastMonth&page=0&prefix=false&query=%22ruby%20central%22&sort=byDate&type=story https://hn.algolia.com/?dateRange=pastMonth&page=0&prefix=fa... 1: https://davidcel.is/articles/rails-needs-new-governance https://davidcel.is/articles/rails-needs-new-governance (this article has a lot of examples from DHH's blog) 2: https://news.ycombinator.com/item?id=45348390 https://news.ycombinator.com/item?id=45348390
- ilikepi 1y agoEr...FYI, your [2] link is to a discussion about an article written by the person to whom you are responding. Personally, I think the reason this post about gem.coop has been flagged is that we've reached the point at which new HN threads about things related to the recent RubyGems shake-up quickly devolve into people rehashing the DHH "aspect" of it all. So it has become less about flagging the actual target of the post and more about flagging the parts of the discussion that seem to go nowhere. EDIT: expanded
- lcnPylGDnU4H9OF 1y agoThat's fair enough, I didn't actually notice. Regardless, I was offering the information for other readers, which may or may not include the person I'm replying to. Edit: > flagging the parts of the discussion that seem to go nowhere This is and isn't what actually happens, though. People do flag the parts of the discussion that don't go anywhere but then people also flag the post itself because they think there's no reason to discuss it at all for the fact there's a vocal part (minority or majority doesn't really matter) that wants to discuss a topic that's not going anywhere. People shouldn't flag the post itself just because it's likely to gather or even has gathered a crowd that will discuss such directionless topics when there are better topics to discuss, even (especially?) if they're not currently being discussed.
- directionless 1y agoGiven some of the ways Andre Arko gets described (See https://justin.searls.co/posts/why-im-not-rushing-to-take-sides-in-the-rubygems-fiasco/ https://justin.searls.co/posts/why-im-not-rushing-to-take-si... for a recent overview) I'm a little wary of what the motivation behind this is.
- directionless 11mo agoTo follow up here, it sure sounds like Andre is not entirely acting in good faith. https://rubycentral.org/news/rubygems-org-aws-root-access-event-september-2025/ https://rubycentral.org/news/rubygems-org-aws-root-access-ev... discusses that a precipitating event was Andre asking for a copy of the http access logs to monetize them. I think this is confirmed by Mike Perham's comment in https://www.reddit.com/r/ruby/comments/1o2bxol/comment/ninn6b4/?utm_source=share&utm_medium=web3x&utm_name=web3xcss&utm_term=1 https://www.reddit.com/r/ruby/comments/1o2bxol/comment/ninn6... > In this case I have first hand knowledge since he pitched me on the idea: would Sidekiq, being a big sponsor of Ruby Central in the past, be interested if rubygems could somehow use the remote IP to identify the companies downloading the sidekiq gem so I could use that to upsell those companies
- daniel_black 11mo ago^^^ THIS ^^^! This is not being highlighted enough.
- kimos 1y agoThis reads like a hit piece based on a personal vendetta. I'd be careful how much weight to give this.
- nomdep 1y ago> When Ruby Together first launched in 2015, the website suggested donations went to pay "our team" (...) This resulted in a nonzero number of donors believing they were funding the work of people like Steve Klabnik, Aaron Patterson, and Sarah Mei, when in fact only Andre was being paid at the time. This a fact. By this alone I don't think Andre Arko is an honest person.
- realty_geek 1y agoFlagging this post is quite disturbing. There is a conversation around this which needs to be had. Maybe on bsky or x? https://x.com/africajam/status/1975206106738901110 https://x.com/africajam/status/1975206106738901110 https://bsky.app/profile/indirect.io/post/3m2iq5p7eoc2j https://bsky.app/profile/indirect.io/post/3m2iq5p7eoc2j
- mijoharas 1y agoSo, ignoring everything that got us here, what do people think about this? As I see it, there is the original rubygems, which has lost all of it's maintainers, and this new one, that has most of the original active maintainers? (how many were there before? it has most of the ones I think about, but I didn't know who was active over there. I mostly saw activity from deivid and didn't know about most of the others to be honest). It kind feels like this fork is the better maintained piece of software now. Does anyone have any thoughts on this? Are any people thinking of moving over soon? Is there any information on what the funding model will be? Also @joeldrapper/anyone is there anything you can share about how the hosting is being covered?[0] [0] https://news.ycombinator.com/item?id=45490386 https://news.ycombinator.com/item?id=45490386
- mijoharas 1y agore: funding model, looks like it's TBD[0] [0] https://bsky.app/profile/indirect.io/post/3m2j2pcinz22j https://bsky.app/profile/indirect.io/post/3m2j2pcinz22j
- phoronixrly 1y agoI don't plan on switching to a rubygems fork that does not offer technical/security benefits over the original. They can win me over with a gem distribution site that requires code signing out of the box and a bundler that enforces it out of the box.
- mijoharas 1y agoFor me, having the software be maintained (and have a security engineer working on it) feels like a security benefit. Does the original have many maintainers left?
- phoronixrly 1y agoIt has allegedly been taken over by Shopify. I expect it to be very well maintained. The issues are of ethical character.
- sandstrom 1y agoI understand forking is sometimes needed, but it's also somewhat discouraging to see that the differences couldn't be reconciled. As long as people are aligned on advancing the Ruby ecosystem, I think it should be possible to cooperate even if there are disagreement in other areas [which political party you support, differences in personal opinions, etc]. Maybe it'll be resolved eventually, just like Merb <> Rails, Bundler <> RubyGems and RubyTogether <> RubyCentral were eventually merged. That's what I'm hoping for!
- thomascountz 1y agoIf we isolate this from the recent controversy: in general, is an alternative (yet mostly compatible) package source, package manager, and/or language version manager neutral, good, or bad for an open source ecosystem?
- MrDarcy 1y agoMostly good. Monopolies stagnate. Competition helps drive innovation. In open source too.
- soraminazuki 1y agoSo RubyGems has betrayed its community by ousting its maintainers. When a community-focused alternative created by the original maintainers is announced, it gets flagged on HN. What is wrong with people? This situation is eerily similar to the Freenode takeover[1] and the subsequent formation of Libera Chat[2] a few years ago, even down to the political leanings of those behind the takeover. Except if the Freenode incident occurred today, there would be a vocal portion on HN vehemently siding with Freenode solely based on the perceived political affiliations of its owners. Submissions about Libera Chat would face heavy flagging, much like this one has. It seems the Freenode team may have advanced their plans just a bit too early. [1]: https://news.ycombinator.com/item?id=27286628 https://news.ycombinator.com/item?id=27286628 [2]: https://news.ycombinator.com/item?id=27207734 https://news.ycombinator.com/item?id=27207734
- sosodev 1y agoFlagging is definitely getting abused more on HN lately. The consensus seems to be that politics and/or morals are irrelevant outside of personal affairs so we must not have these conversations here.
- soraminazuki 1y agoWhich is absurd because the hostile takeover of RubyGems primarily involves technology, with serious implications for the security and trust of nearly all Ruby code. Those flagging this submission are the ones prioritizing politics over this critical issue.
- busterarm 1y agoPolitically-charged ultimatums _caused_ the hostile takeover of RubyGems. This whole thing is politics all the way down.
- soraminazuki 1y agoSomeone withdrawing funding from Ruby Central doesn't necessitate a hostile takeover of RubyGems. The responsibility lies squarely on people doing the takeover. Needless to say, you haven't shown me any convincing arguments for suppressing the announcement of gem.coop.
- insane_dreamer 1y agoImportant move to maintain a free community. I'm switching over to Gem.coop now.
- salzig 1y agoJust a thought of mine: why don’t we switch fully to git? Commit signing, tag signing, Decentralize. Doesn’t that sound like a good alternativ?
- zdragnar 1y agoSomeone has to run the git server. Then, someone has to find the git server to pull each gem from, since not every git server is likely to be up-to-date with the each gem, or the correct version. Since these are all decentralized, each individual owner of a git server has to independently scale as more people start using each one. The benefit to being centralized is... everything is in one place. Everything scales at once. Every update is available at the same time. We did this back in the day using artifactory and co. to proxy NPM and a few other package managers as well as docker containers and some other things. No third party service going down could keep us from deploying. Not everyone does it because as a solo developer or a small team, as it feels like pointless overhead.
- salzig 1y agoSo GitHub would be one option. Developers already discover all kind of things there. And each gem can still be provided by its “main repository”, but I don’t mind on whatever domain that repository is located. Somewhat how container images are referenced/distributed already. I think go already does it like that too. having a decentralized, and maybe sometime unavailable, infrastructure would make more people think about the problem and maybe brings us more stable solutions than we have now.
- pornel 1y agoThe git protocol is more complex and harder to scale. It's especially wasteful if people are going to redownload all packages every time their amnesiac CI runs. Single-file archives are much easier to distribute. Digests and signatures have standard algorithms, not unique to git. Key/identity management is the hard part, but git doesn't solve it for you (if you don't confuse git with GitHub).
- 1y ago
- pdntspa 1y agoIs this not an overreaction to the rubygems rubycentral fiasco?
- florkbork 1y agoNo. Imagine if someone came into your house and changed all of the locks on you/your family, because "security". You had built that house from your original designs but the other party claims they own it now because they happen to manage a series of rental listings for houses built to your design. You had even made it so the plans could be copied and modified in private; if "security" were a real concern with about 10 minutes effort to do so. Would you agree that it is right, do nothing? Or would you rebuild something new, given how little time it takes to copy the plans. Swap "house design" for "software project" and "rental listings" for "running an instance of your software project" and you have the current situation. Developers are free to choose the party they trust more.
- pdntspa 11mo agoYeah and now we have a fragmented ecosystem. If the projects were placed under RubyCentral's management and active contributors' access is restored I don't see a big deal. Yes the manner in which it was handled was really bad but given the supply-chain attacks we're seeing against the Python and JS worlds, I think auditing contributor access and consolidating certain privileges is prudent. Again, handled poorly. But a lot of money rides on stuff like Bundler. We need a strict security posture. edit- I am an artist; I get the concern and distaste. But at a certain point your art grows bigger than you. If you as a private individual build a bridge used from a public roadway and you don't do the necessary maintenance or management your shit gets shut down. Not sure how this is much different.
- pluto_modadic 11mo ago...so your argument is.... stay with the abusers?
- 11mo ago
- sergiotapia 1y agoIs this political or does it have actual technical merit?
- CaptainOfCoit 1y agoThe best "technical" benefit from this is that if one goes down, you could switch to the other in a pinch, so arguably better than the status quo even if you disagree with the organizational/"political" motives.
- poorman 1y agoHere's the thing. They could have put up link to a git repository where others can follow along with the maintenance of this project, but here isn't one. There is a list of maintainers explicitly mentioned on this page but no link to the git repository. This leads me to think this project is not about the code but about the people.
- steveklabnik 1y agoSource lives here: https://github.com/gem-coop https://github.com/gem-coop
- byroot 1y agoThe only public repo is a static website.
- steveklabnik 1y agoAh! Good catch. I saw the repo exists but didn't dig into the contents, given that it's (as far as I know) purely a proxy for rubygems at the moment, I figured it would be pretty simple. I agree they should post the whole source, regardless.
- soraminazuki 1y agoIt's a package repository. A link to an Ansible repository or whatever doesn't need to be in the first announcement. > This leads me to think this project is not about the code but about the people. Trust is of utmost importance to a package repository. Even more so than code. A hostile takeover, like the one that occurred with RubyGems, fundamentally undermines that trust. In contrast, an alternative run by the original maintainers who have built years of trust, represents a positive shift. Unfortunately, it seems that your conclusion was drawn before your justifications. When you invent justification though, at least make sure you don't undermine your own position. Where's the prominent link to the Git repo on rubygems.org top page? https://web.archive.org/web/20251003112525/https://rubygems.org/ https://web.archive.org/web/20251003112525/https://rubygems....
- ChrisArchitect 1y agoA brief announcement post: https://andre.arko.net/2025/10/05/announcing-gem-coop/ https://andre.arko.net/2025/10/05/announcing-gem-coop/
- varispeed 1y ago> initially his own, but eventually others—by paying themselves a market hourly rate This is massively flawed thinking. So called "market rate" is actually a tool for value extraction from the workers and is not connected in any shape or form with what they create for company they work at. As corporations refer to this as if it was a consensus (as in developer should earn $x an hour), they pay this much and workers have no choice but to accept (if someone has working class background and no trust fund, it is rather impossible to throw the towel and start own business, sometimes there are even regulations designed to keep workers captive). In such a project, "founder level" people should pay themselves as much as they think their worth is. Simple as that. I often hear VC talking that if founder takes too much money, it's a bad look. They just want to shame people into not taking the slice they deserve. It's interesting that IT is full of intelligent people, yet they can't grasp how they are being played by the market frames set by the rich.
- eek2121 1y agohard disagree. For a project like this, all members should be paid a fair, but not "get rich" sum. There are companies out there that pay EVERYONE the same salary, all the way from CEO to janitor. Mysteriously, those companies don't have folks trying to hijack things, because nobody benefits. It's almost like removing money from the equation stops all the nasty stuff that happens inside organizations. Who'd have thought?
- varispeed 1y ago"Market rate" is not neutral. It is a wage‑fixing device that standardises labour pay while letting profits float to shareholders. Treating it as holy writ is how extraction is hidden in plain sight. Flat salaries do not remove politics. With unequal equity and control, a flat wage simply disciplines workers while investors keep uncapped upside. If money is the poison, start by flattening carry, liquidation preferences and board vetoes. Otherwise you have only flattened one side. Capping founder pay is class gatekeeping. It selects for people with savings or family safety nets and pushes working‑class founders out. Shaming those who take cash once they create surplus protects investor optics, not fairness. Equal pay only makes sense when ownership, risk and power are equal. Without that, "equal pay" is theatre.
- eek2121 1y agoI feel like a change to the way gems are distributed/downloaded could fix this. Unfortunately, the very powers that could make that happen are the powers that control the software and infrastructure, and have the least incentive to improve things. I honestly find it ridiculous that this situation happened to begin with, and I also have no clue why people are hating on DHH. The easiest way to kill an open source project is drama and forking like this. Ruby has been around forever, obviously, however it is far from the most used languages, and drama like this just hurts the ecosystem as a whole. As a former Ruby dev, it makes me sad.
- bitwize 1y agoDrama and forking aren't going to kill Ruby. This is a move like the one from Freenode to LiberaChat: hostile entities take over $thing, sensible people move on to $newthing, the new normal settles around $newthing. As for DHH, he's a far-right racist. https://jakelazaroff.com/words/dhh-is-way-worse-than-i-thought/ https://jakelazaroff.com/words/dhh-is-way-worse-than-i-thoug... Silencing and excluding such people from open source is the right thing to do because failure to do so means forcing others to interact with people who are hostile to their very existence.
- colechristensen 1y agoWhy?
- Mystery-Machine 1y agowhy's (poignant) Guide to Ruby
- deleted 1y ago[deleted]
- dcchambers 1y agoWell the site is blocked on my company laptop (reason given: newly registered domain), so it will be a rocky start for them. I love a good vanity domain but using a traditional .org domain probably would have been better, too. My 2c is that 95% of ruby developers aren't aware of the drama going on around Rubygems.org right now. They have probably seen emails from Ruby Central but largely ignore them and move on with life. Most people have no idea there are issues and they will just continue using Rubygems.org. Getting a project like this to critical mass is incredibly challenging.
- shevy-java 11mo agoThere is a recent tiny "update", or more a comment - see here (I only use old.reddit; the new reddit UI is so much worse, but this is an aside): https://old.reddit.com/r/ruby/comments/1nzxgb9/buckle_up_theres_a_new_gem_server_in_town_gemcoop/ni98rrt/ https://old.reddit.com/r/ruby/comments/1nzxgb9/buckle_up_the... In the event the ruby-reddit moderators remove it, the comment had this content verbatim at the time of linking to it here: "I have tried so much. It’s Ruby Central that won’t talk. They’re hiding behind lawyers at this point." Now, we have to concede that this could be wrong; or incomplete. Personally I believe him though, but in theory it could be a wrong statement. Nonetheless ... just think about this for a moment ... The organisation that claims it is all about the community, refuses to be transparent and now hides behind lawyers, after having been caught with making several incorrect statements before already. Does this look more like a community-centric organisation or possibly a front for corporations? Just think it through for yourself what it means when they suddenly have to hide behind lawyers. In my opinion they are now deliberately making the community angry. But, even without this, I believe we can conclude that by far the biggest fault for all of this lies on Ruby Central.
- RhythmFox 11mo ago-> In my opinion they are now deliberately making the community angry. This is one thing I think hasn't been talked about explicitly enough within the community (that I see at least) yet, Ruby Central seems to be actively trolling the 'other side' of this situation. It reads to me like they know they have the lawyer power to defend their castle and are enjoying pissing down on people and telling them it's raining. Oh and you should enjoy that because it means there will be flowers soon... or something. I think the dialogue of 'are they acting in good faith' only works in so far as they even care about the rest of the Ruby community at all. If they are indeed bad actors (motivated purely by greed, ambition, ego, etc) then they are not ever going to come clean and they would let the whole Ruby community die before they admit defeat or wrongheadedness. My favorite term for these types of actors is SCUM - Sufficiently Clever and Uncaring Malefactors.