I really want to improve the rubygems.org codebase so we can put it on rubyonrails.org/docs/referen...
gems.org
Colby Swandale
@colby.fyi
Technical Lead @ RubyCentral. Making rubygems.org, bundler/rubygems & rubyapi.org
I really want to improve the rubygems.org codebase so we can put it on rubyonrails.org/docs/referen...
gems.org
Security Advisory: Possible exposure of legacy RubyGems.org API keys. If you use RubyGems client < v3.2.0 or a legacy API key, review your account. No evidence of malicious use. Scoped API keys are not affected. buff.ly/u0xAec3
Security advisory: Possible leak of legacy API keys via improper cache configuration
A CDN caching bug on RubyGems.org could hand one account’s API key to another person for up to an hour. If you signed in to RubyGems.org with a gem client older than v3.2.0, your key could have bee...
blog.rubygems.org
Honestly not sure what we did that was so wrong here A GitHub issue would've taken the same time as that post, and we'd have jumped straight on it. There are already follow-up PRs, for what it's worth. 😔
AI tools have made finding security issues cheap. Verifying them still takes people. Thanks to Alpha-Omega, Ruby Central is helping close that gap. Read more here👉️
Strengthening Security for the Ruby Ecosystem: A Team of Security Engineers in Residence
We’re excited to announce that Ruby Central has been awarded a grant from Alpha-Omega to help improve the security of the Ruby open source ecosystem. With this support, Ruby Central is funding a team…
rubycentral.org
Hello Rubyist. Working hard all day is great, but maybe it's time to cool down. New in RubyGems/Bundler 4.0.13: blog.rubygems.org/2026/06/03/c...
Cool down before you install: give new gems a few days to be vetted
Most supply-chain attacks against RubyGems exploit a narrow window: an account is compromised, a malicious version ships, and any bundle install in the minutes that follow resolves straight to it. ...
blog.rubygems.org
RubyCentral is building a small team of 3-4 engineers to hunt for vulnerabilities in the most critical packages in the Ruby ecosystem. Get in touch if this sounds like you.
Flying into RubyKaigi, I thought we had months to stand up AI-assisted vulnerability scanning for rubygems.org. Turns out we were out of time. We started prototyping during the conference, scanned the most critical gems, and four hours later submitted our first advisory to Nokogiri.
I'm going to be attending the AWS Summit in Sydney on Day 1, would love to catch up and say hi if anyone else is going!
Flying into RubyKaigi, I thought we had months to stand up AI-assisted vulnerability scanning for rubygems.org. Turns out we were out of time. We started prototyping during the conference, scanned the most critical gems, and four hours later submitted our first advisory to Nokogiri.
Scaling Ruby's defenses with AI
On April 23rd, we submitted a vulnerability report to the Nokogiri maintainers. It was the first one our team has filed using AI-assisted scanning. The maintainers accepted the report and published...
blog.rubygems.org
I finally got around to writing about the recent rubygems.org security improvements we've shipped! blog.rubygems.org/2026/04/09/p...
Protecting rubygems.org from the outside in: DoS prevention and compromised passwords - RubyGems Blog
09 Apr 2026
blog.rubygems.org
I joined RubyCentral to release a postmortem, and today I'm delivering my report on what happened. The hope is to provide more transparency and closure, 194 days since the incident on September 18. I've named the incident "RubyGems Fracture." Read my report. #ruby rubycentral.org/news/rubygem...
rubycentral.org
I've been heads-down behind the scenes helping maintain rubygems.org and strengthen its operations. Richard's report is thorough & transparent, which the community has long deserved. rubygems.org is a pillar of the Ruby community. I'm committed to finding a path forward that works for everyone ❤️
I joined RubyCentral to release a postmortem, and today I'm delivering my report on what happened. The hope is to provide more transparency and closure, 194 days since the incident on September 18. I've named the incident "RubyGems Fracture." Read my report. #ruby rubycentral.org/news/rubygem...
Botched my CFP submission and won't be able to speak about the Bundler & RubyGems unification project 😔
rv has a big release, with windows support and gem CLI tools! the fastest way to generate a rails app is now `brew install rv; rvx rails new`. check it out: https://spinel.coop/blog/rv-0.5-cli-tools-windows/
rv 0.5: CLI tools + Windows
spinel.coop
The Ruby community shines because of leaders who build, care for, and sustain it. The Community Leadership Gem Award honors those who create safe, inclusive spaces through meetups, conferences, and local communities worldwide. Nominate a community gem: airtable.com/appBBx7FkmSp...
RubyGems.org Organizations -- now in private beta. Organizations help teams manage gems with shared ownership, multiple maintainers, and better permissions. Apply to join the beta: tinyurl.com/mr34crtf Learn more in our guides: tinyurl.com/39t3msu5
I'm very honored to have received this year's RubyPrize from Matz's hands in Matsue last Thursday, recognizing my work on Ruby and its development tools. I can still remember how nervous I was asking Matz for a picture back in 2016 😂 Time really flies (Photo from @hsbt.org ❤️)
However you see the recent announcement — please remember that there was an extremely passionate team of people who gave years of their lives to better the ruby community. This past month has been incredibly difficult and deeply hurtful.
Ruby community: Look, we can be angry about what's happening, we can raise our complaints, but under no circumstances should anyone _ever_ harass someone's families, coworkers, or friends. That is completely unacceptable, and wholly against the ethos of the language. We must do better.
It's so painful to spend every waking second of the past few weeks thinking and working on ways to correct a bad decision, only to just be picked up and thrown away. I'm so freaking tired 😫
I’m hurt, numb, crying, in pain, regretful of not doing more for my friends. The last few days have been a nightmare being played out in real time. No matter the original reason behind it, no one did anything that deserved how we were all treated. 😔
oof, what a disappointing way to end more than 15 years of open source work. (summary by @duckinator.bsky.social at pup-e.com/goodbye-ruby...). good luck to the remaining RubyGems team, and it’s time to focus my energy on new projects that I’m truly excited about, like rv.dev
I'm onboarding the very first Organization on rubygems.org in a few hours 🚀
RubyGems.org | your community gem host
rubygems.org
Ruby 3.5 Preview 1 Released @ RubyKaigi! www.ruby-lang.org/en/news/2025...
Ruby 3.5.0 preview1 Released
ruby-lang.org
We’re excited to share that free #RubyGem analytics are now available to the community! 🙌 Through our partnership with ClickHouse, developers and security researchers can now query over 200 billion RubyGem download events since 2017, with new data added every hour. 👀
Announcing Ruby Gem analytics powered by ClickHouse and Ruby Central
In partnership with Ruby Central, we’re excited to announce that all RubyGems download data - over 180 billion rows - is now free to query at sql.clickhouse.com; explore trends, analyze usage, and…
clickhouse.com
I’m still unemployed and looking for a new full time position doing Ruby, Rails, TypeScript, CSS. If you know people who are hiring, I’d really appreciate an introduction. 🙏