Rafael França

@rmfranca.bsky.social

Rails developer

Dear gem maintainers 👋 Rails 8.1 just dropped, but many gems can’t be used because of overly strict gemspec constraints. Please don’t hard-restrict Rails versions, let us test early and report real issues sooner! ❤️ Thanks

Bild

Anyone with experience obtaining and addressing CVEs knows that it is shameful for an OSS programmer to disclose information about a security incident before sharing it with relevant parties and coordinating a response.

People jumped to conclusions about this RubyGems thing

People jumped to conclusions about this RubyGems thing

For context, last week I wrote a post bringing to light a number of things Andre Arko had said and done (/posts/why-im-not-rushing-to-take-sides-in-the-rubygems-fiasco/) in the past as a way to provide some context. Context that might explain why any of the principal actors involved in the RubyGems maintainer crisis (summarized well up to that point by Emanuel Maiberg (https://www.404media.co/how-ruby-went-off-the-rails/)) would take such otherwise inexplicable actions and then fail to even attempt to explain them. Today, Jean shed some light on Shopify's significant investments in Ruby and Rails open-source (https://byroot.github.io/opensource/ruby/2025/10/09/dear-rubyists.html), and it actually paints a picture of corporate investment in open source done right. (Disclosure: I know and am friends with several people who work at Shopify on these teams, and unless they're all lying to me, they sure seem to prioritize their work based on what Ruby and Rails need, as opposed to what Shopify wants.) Jean went a step further by contrasting Shopify's approach with the perverse incentives at play when individuals or groups receive sponsorships to do open source. He also drew a pretty clear line of those incentives playing out based on how RubyGems and Bundler maintainers reacted to Shopify's feature submissions. Read the post, it's good.

justin.searls.co

This is by far the most sensible take ever since all this mess started. Glad there are still some people capable making the difference between unsubstantiated conspiracy theories and proper reporting of facts. Thank you ❤️

Code and the Coding Coders who Code it@codingcoders.bsky.social · 10mo ago

🎙️ New (Bonus) Episode of Code and the Coding Coders who Code it, with @andrewm.codes and @chaelcodes.bsky.social podcast.drbragg.dev/episodes/rub... #ruby #Rails #code #coding #coders #podcast #rubycentral #bundler #rubygems

Hi folks, I am the president of the Ruby Central board. I don’t have time to reply to posts individually, but I do want to make clear that recent changes to permissions in our open source projects were done in collaboration with the organization’s leadership and not by one person unilaterally 🧵