Colby Swandale

@colby.fyi

Technical Lead @ RubyCentral. Making rubygems.org, bundler/rubygems & rubyapi.org

Honestly not sure what we did that was so wrong here A GitHub issue would've taken the same time as that post, and we'd have jumped straight on it. There are already follow-up PRs, for what it's worth. 😔

Bild

RubyCentral is building a small team of 3-4 engineers to hunt for vulnerabilities in the most critical packages in the Ruby ecosystem. Get in touch if this sounds like you.

Colby Swandale@colby.fyi · 3mo ago

Flying into RubyKaigi, I thought we had months to stand up AI-assisted vulnerability scanning for rubygems.org. Turns out we were out of time. We started prototyping during the conference, scanned the most critical gems, and four hours later submitted our first advisory to Nokogiri.

Flying into RubyKaigi, I thought we had months to stand up AI-assisted vulnerability scanning for rubygems.org. Turns out we were out of time. We started prototyping during the conference, scanned the most critical gems, and four hours later submitted our first advisory to Nokogiri.

Scaling Ruby's defenses with AI

On April 23rd, we submitted a vulnerability report to the Nokogiri maintainers. It was the first one our team has filed using AI-assisted scanning. The maintainers accepted the report and published...

blog.rubygems.org

I've been heads-down behind the scenes helping maintain rubygems.org and strengthen its operations. Richard's report is thorough & transparent, which the community has long deserved. rubygems.org is a pillar of the Ruby community. I'm committed to finding a path forward that works for everyone ❤️

Richard Schneeman@schneems.bsky.social · 4mo ago

I joined RubyCentral to release a postmortem, and today I'm delivering my report on what happened. The hope is to provide more transparency and closure, 194 days since the incident on September 18. I've named the incident "RubyGems Fracture." Read my report. #ruby rubycentral.org/news/rubygem...

I'm very honored to have received this year's RubyPrize from Matz's hands in Matsue last Thursday, recognizing my work on Ruby and its development tools. I can still remember how nervous I was asking Matz for a picture back in 2016 😂 Time really flies (Photo from @hsbt.org ❤️)

BildBild

However you see the recent announcement — please remember that there was an extremely passionate team of people who gave years of their lives to better the ruby community. This past month has been incredibly difficult and deeply hurtful.

Ruby community: Look, we can be angry about what's happening, we can raise our complaints, but under no circumstances should anyone _ever_ harass someone's families, coworkers, or friends. That is completely unacceptable, and wholly against the ethos of the language. We must do better.

It's so painful to spend every waking second of the past few weeks thinking and working on ways to correct a bad decision, only to just be picked up and thrown away. I'm so freaking tired 😫

I’m hurt, numb, crying, in pain, regretful of not doing more for my friends. The last few days have been a nightmare being played out in real time. No matter the original reason behind it, no one did anything that deserved how we were all treated. 😔

We’re excited to share that free #RubyGem analytics are now available to the community! 🙌 Through our partnership with ClickHouse, developers and security researchers can now query over 200 billion RubyGem download events since 2017, with new data added every hour. 👀

Announcing Ruby Gem analytics powered by ClickHouse and Ruby Central

In partnership with Ruby Central, we’re excited to announce that all RubyGems download data - over 180 billion rows - is now free to query at sql.clickhouse.com; explore trends, analyze usage, and…

clickhouse.com