I want to say a big thanks to Shopify and the @raeng.org.uk who graciously funded this research. I'd like to dedicate this work to the late Chris Seaton, who was an early champion of yk: he is much missed by me and many others.
My team is hiring a manager to lead one of our team of engineers working in the infrastructure for the Ruby language and the Rails framework. Come work with us! www.shopify.com/careers/engi...
Engineering Manager- Ruby and Rails Infrastructure
ARE YOU READY? Join the fully-remote rocketship. Find your next quest to make commerce better for everyone. Unlimited growth. Crafters and hard workers only. Apply within.
shopify.com
New post by Jacob about recent heap modeling optimizations in ZJIT :D railsatscale.com/2026-03-18-h...
How ZJIT removes redundant object loads and stores
ZJIT’s optimizer now removes redundant object loads and stores, improving JIT performance of CRuby’s shape system. This post explains how the optimization works.
railsatscale.com
[ENG] ⏰ It’s today! The Call for Proposals for Tropical on Rails closes today. 👉 Submit your proposal. [PT-BR] ⏰ É hoje! O Call for Proposals do Tropical on Rails encerra hoje. 👉 Envie sua proposta. cfp.tropicalonrails.com/ #TropicalOnRails #RubyOnRails #RubyCommunity #CallForProposals #CFP
Dear gem maintainers 👋 Rails 8.1 just dropped, but many gems can’t be used because of overly strict gemspec constraints. Please don’t hard-restrict Rails versions, let us test early and report real issues sooner! ❤️ Thanks
Anyone with experience obtaining and addressing CVEs knows that it is shameful for an OSS programmer to disclose information about a security incident before sharing it with relevant parties and coordinating a response.
Ruby Central dropped the ball here on securing the root account and effectively lost control of it for 11 days - however, that's nothing compared to changing the root password. If an ex-employee did that to me I'd be calling the police.
Here’s a note from our Executive Director regarding our recent security incident. rubycentral.org/news/rubygem...
Here’s a note from our Executive Director regarding our recent security incident. rubycentral.org/news/rubygem...
Rubygems.org AWS Root Access Event – September 2025
As part of standard incident-response practice, Ruby Central is publishing the following post-incident review to the public. This document summarizes the September 2025 AWS root-access event, what…
rubycentral.org
Thank you for writing this, especially: > Aaron got nerd sniped into making Bundler faster, and now he’s being called out for supposedly being part of a hostile takeover? Give me a break.
I tried to explain why I don't believe the recent accusations toward my former teammates, as well as how the Ruby and Rails Infra team at Shopify operates and why it can be trusted. byroot.github.io/opensource/r...
This is by far the most sensible take ever since all this mess started. Glad there are still some people capable making the difference between unsubstantiated conspiracy theories and proper reporting of facts. Thank you ❤️
🎙️ New (Bonus) Episode of Code and the Coding Coders who Code it, with @andrewm.codes and @chaelcodes.bsky.social podcast.drbragg.dev/episodes/rub... #ruby #Rails #code #coding #coders #podcast #rubycentral #bundler #rubygems
Hi folks, I am the president of the Ruby Central board. I don’t have time to reply to posts individually, but I do want to make clear that recent changes to permissions in our open source projects were done in collaboration with the organization’s leadership and not by one person unilaterally 🧵