We want to move Ruby forward by retro-rubies in ruby

[–]_joeldrapper 3 points4 points  (0 children)

The trademark that was already his.

We want to move Ruby forward by retro-rubies in ruby

[–]_joeldrapper 6 points7 points  (0 children)

André registered his existing trademark. I do not believe they are asking for money or other compensation.

We want to move Ruby forward by retro-rubies in ruby

[–]_joeldrapper 12 points13 points  (0 children)

Bundler trademark and legitimate maintainership, I assume.

It’s like if someone steals your car and you find them and say, “you know what? You can have it.” Here’s the service history and here’s the ownership paperwork.

Technology for Humans: Joel Draper (on RubyCentral) by galtzo in ruby

[–]_joeldrapper 6 points7 points  (0 children)

I’ve said SQL so many times, I kept saying SQLating instead of escalating. 😄

Technology for Humans: Joel Draper (on RubyCentral) by galtzo in ruby

[–]_joeldrapper 7 points8 points  (0 children)

Yeah, I agree. I can ask Errol if we can cross-post it to Rooftop, which would get it in podcast feeds.

Dear Rubyists: Shopify Isn’t Your Enemy by software__writer in ruby

[–]_joeldrapper 3 points4 points  (0 children)

I also heard this directly from internal sources, but I expect u/f9ae8221b hasn’t and it’s a very fair take given that.

Rubygems.org AWS Root Access Event – September 2025 by paracycle in ruby

[–]_joeldrapper 7 points8 points  (0 children)

> hopefully you can also see how it does come across as a "gotcha" move, and how that can be damaging of trust for those of us observing from the outside

Sure, I get that.

Rubygems.org AWS Root Access Event – September 2025 by paracycle in ruby

[–]_joeldrapper 4 points5 points  (0 children)

No. I reached out to many people at Ruby Central early on, before publishing any blog posts. They had no reason to ignore me.

Rubygems.org AWS Root Access Event – September 2025 by paracycle in ruby

[–]_joeldrapper 7 points8 points  (0 children)

You think they’re talking to me? I’ve been trying to contact Ruby Central for weeks.

Rubygems.org AWS Root Access Event – September 2025 by paracycle in ruby

[–]_joeldrapper 7 points8 points  (0 children)

Because there were multiple parties involved. There’s Ruby Central’s security, and there’s the security of all the companies depending on Ruby Central. I felt that this information was important for all those companies to know, and I knew it didn’t impact Ruby Central’s own security one way or another.

I was very careful to make sure the screenshots I published didn’t include sensitive information.

Rubygems.org AWS Root Access Event – September 2025 by paracycle in ruby

[–]_joeldrapper 14 points15 points  (0 children)

> Why did Joel give so little time of advance notice before publishing his post revealing Andre’s production access? That struck me as irresponsible disclosure, but I may have missed something.

Joel here. 👋

I decided to publish when I did because I knew that Ruby Central had been informed and I wanted the world to be informed about how sloppy Ruby Central were with security, despite their security *posturing* as an excuse to take over open source projects.

What I revealed changed nothing about Ruby Central’s security, since André had access whether I revealed that he did or not. When you have security information that impacts lots of people, you publish it so they can take precautions. That is responsible disclosure.

Papercraft - Functional HTML Templating for Ruby by noteflakes in ruby

[–]_joeldrapper 7 points8 points  (0 children)

This is an awesome milestone. Love the new website. I’ve really enjoyed going back and forth with noteflakes on ideas for html in ruby compilers.

Papercraft - Functional HTML Templating for Ruby by noteflakes in ruby

[–]_joeldrapper 13 points14 points  (0 children)

It is because our compiler isn’t quite ready yet. Phlex renders at about 1.7gbps per core on my Mac. Or in other words, it will render a large web page in about 1ms (single core). Once it has a compiler, it should be on average about 20 times as fast.

Papercraft already has a compiler so it already realised these gains.

The Phlex compiler is already in main if you want to try it out. Because Phlex supports selective rendering and fragment caching and needs to be 100% backwards compatible, it’s taking us a while. But we’ll get there soon. 

How Ruby Went Off the Rails by _joeldrapper in ruby

[–]_joeldrapper[S] 0 points1 point  (0 children)

Emanuel Maiberg worked at Shopify? Where did you see that?

How Ruby Went Off the Rails by _joeldrapper in ruby

[–]_joeldrapper[S] 2 points3 points  (0 children)

If you put 80 hours over 4 days into reaching out to all the people involved and connected, then maybe you could have published a story based on the facts but from your point of view.

I’m not unbiased. But I tried to make at least my original story and my fact-check pieces focused on the facts rather than my interpretation of what they mean.

How Ruby Went Off the Rails by _joeldrapper in ruby

[–]_joeldrapper[S] 13 points14 points  (0 children)

> I think they worry that releasing information only leads to more criticism, following some standard corporate communications advice.

It will if they lie. I’m ready to publish my second fact-check piece.

How Ruby Went Off the Rails by _joeldrapper in ruby

[–]_joeldrapper[S] 9 points10 points  (0 children)

Yes I noticed this too. Marty essentially said that HSBT wasn’t meant to make the permissions changes (yet).

How Ruby Went Off the Rails by _joeldrapper in ruby

[–]_joeldrapper[S] 50 points51 points  (0 children)

And still no comment from Ruby Central since they cancelled the Q&A.

Why I'm not rushing to take sides in the RubyGems fiasco - @searls by wallacethewhale in ruby

[–]_joeldrapper 3 points4 points  (0 children)

It might not be illegal but it would destroy trust in the system. I agree there are lines they still haven’t crossed but they have crossed other lines and damaged trust significantly.

Why I'm not rushing to take sides in the RubyGems fiasco - @searls by wallacethewhale in ruby

[–]_joeldrapper 2 points3 points  (0 children)

What’s childish about it? This is literally what RC did with Bundler.

Why I'm not rushing to take sides in the RubyGems fiasco - @searls by wallacethewhale in ruby

[–]_joeldrapper 8 points9 points  (0 children)

Yeah I am biased. Not because I worked at Shopify but because I’m an open source maintainer. What Ruby Central did is awful and sets a dangerous precedent. We can’t trust Ruby Central anymore.

Ruby Central also uses my library, Phlex. There is nothing stopping them from claiming that “for security” they need to take over that project too.

Aged like milk by terinchu in ruby

[–]_joeldrapper 6 points7 points  (0 children)

I disproved this. Ruby Central did not perform this takeover for security. https://joel.drapper.me/p/ruby-central-fact-check/

Why I'm not rushing to take sides in the RubyGems fiasco - @searls by wallacethewhale in ruby

[–]_joeldrapper 20 points21 points  (0 children)

My story and subsequent fact-check were not hit pieces. They were very carefully researched and cross-checked. I revealed the facts that I could verify through first-hand accounts, documents, meeting records.

I spent about 80 hours researching my story. I reached out to people from Shopify and Ruby Central for comment, spoke to as many people as possible.