# Ruby Central
> Supporting the Ruby Community Since 2001
Public Ghost content for AI and LLM tooling. This file includes a bounded export of public pages first, then recent public posts.
Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`).
## Pages
### History
URL: https://rubycentral.org/history/
Last updated: 2024-03-01T23:52:24.000Z
The founders of Ruby Central, Inc. (David Alan Black and Chad Fowler) were individually involved in organizing the first annual International Ruby Conference (RubyConf), held in Tampa in 2001\. Shortly after that conference, they realized that there was enough interest in Ruby that the logistics for future events would only become more elaborate, including the search for corporate sponsors, the choice of new locations and venues, and the inclusion of a larger attendee base.
As such, Black and Fowler made the decision to establish a nonprofit organization to handle conference arrangements. Thus, Ruby Central was born. Ruby Central’s first official conference was RubyConf 2002 in Seattle, and since then, annual RubyConfs have been held every fall.
In 2006, Ruby Central added a dimension to the world of Ruby conferences when we produced the first official Ruby on Rails Conference, better known as RailsConf. Since that first RailsConf in Chicago, we have been holding RailsConf every spring. From 2007-2011, Ruby Central partnered with O’Reilly to co-produce RailsConf.
Outside of these two signature conferences, Ruby Central has partnered with organizations such as SDForum and Skills Matter (UK) to co-produce additional Ruby conferences. Through the Regional Conference Grant Program, established in 2006, we have also provided financial support and guidance to many other Ruby conferences.
Though planning and holding these conferences takes up a lot of our time, it is far from the primary goal of Ruby Central, Inc. We have always strived to become a hub for the robust support of a variety of Ruby activities. Our first non-conference project was the Ruby Codefest Grant Program, through which we offered support for local and regional groups of programmers working on Ruby library projects. Ruby Central also hosts Ruby Gems, provides support for the Ruby Summer of Code, and sponsors development of Bundler.
### Scholars and Guides Program
URL: https://rubycentral.org/scholars_guides_program/
Last updated: 2026-05-30T03:35:14.000Z
### **What is the Scholars and Guides Program?**
The Scholars and Guides Program is a mentorship program for aspiring Rubyists interested in learning more about the Ruby programming language, expanding their professional toolkits, and having help navigating the Ruby Central conferences, RubyConf.
### **How does it work?**
Scholars are paired with a Guide who will help them navigate the conference, provide guidance on their coding skills, and help them build relationships with other Rubyists. Scholars are tasked with completing a mini-project for a chance to share their work, experiences, or interests with the community.
### **Scholars and Guides timeline:**
***Applications are now open throughout the year. Please pay attention to the deadlines in order to be considered for particular events.***
- Scholar and Guide application open: **February 18**
- RubyConf Scholar and Guide Virtual Meetup: **end of June**
- Scholar mini-project presentations: **July 14- 16**
### **What is a mini-project?**
Scholars can choose any topic they are interested in and will work with their Guide to present their project as a Lightning Talk or in a format they choose (i.e., blog, program design, etc.). The program is an opportunity for aspiring and experienced programmers to work together in a fun and creative way and to create new pathways to reach their respective goals. Check out the [mini-project guidelines](https://rubycentral.org/content/files/2026/05/Scholars-Mini-Project.pdf) for more details.
### **Why apply as a "Scholar" for the Scholars and Guides program?**
If you want to get more immersed in the Ruby community and learn from experienced developers, the Scholars and Guides program provides you that and more! Scholars can gain exposure and the opportunity to connect with leaders in the field. You'll get a 1:1 mentorship that helps you tackle your different goals and challenges along with making incredible connections and friendships in the global Ruby community. Benefits of participating in the program include:
- A complimentary ticket to a Ruby or Rails conference
- Mentorship from experienced programmers and developers
- Networking with fellow Rubyists and Speakers at the *Speakers & Scholars Reception Event*
- Access to a Slack community channel to share resources and connect before, during, and even after the conference
- A professional spotlight of your headshot and socials on the conference webpage
- An opportunity to interview for our Newsletter to discuss your experience as a Ruby Central Scholar.
- Dedicated front-row seating at all the conference keynotes
### **Scholar requirements**
The program is open to community members interested in learning the Ruby programming language; however, applicants from underrepresented communities within tech are highly encouraged to apply. Scholars must meet the following requirements:
- Be 18 years or older during the time of application submission
- Complete a mandatory mini-project that will be undertaken alongside an assigned Guide. A mini-project is an opportunity to *present any subject or research to either your program peers or a larger audience at the 5-minute Lightning Talks. Ideas include community awareness, ongoing projects, passion research, or learning new coding skills. These projects facilitate skill growth and inspire others through your findings.*
- Attend 3 required meet-ups: Speakers & Scholars Receptions; Pre-conference meeting; Post-conference meeting
- Not have been a past Scholar
The program is limited to a certain number of scholars, so early application is encouraged. We encourage applicants to answer our application questions fully to help us gain insight into who you are and your goals.
[Apply Now (Scholars)](https://rubycentral.teamtailor.com/jobs/7247950-scholars-application?ref=rubycentral.org)
\*\* Scholar Alumni who successfully complete the Scholars program receive discounts at all Ruby Central conferences. If you are interested in "paying it forward" or learning more, email us at [scholarships@rubycentral.org](mailto:scholars@rubycentral.org)
### **Why apply as a "Guide" for the Scholars and Guides program?**
Volunteering as a Guide (mentor) in the Ruby community promotes growth, knowledge sharing, and inclusivity. By guiding others, especially newcomers, you help them navigate challenges, develop their skills, and boost their confidence. Being a Guide allows you to stay connected with the latest trends, refine your own expertise, and build lasting professional relationships, all while contributing to the success of others in the Ruby ecosystem. Other benefits of participating in the program include:
- 1:1 mentorship opportunity
- Networking with fellow Rubyists and Speakers at the *Speakers & Scholars Reception Event*
- Access to a Slack community channel to share resources and connect before, during, and even after the conference
- A professional spotlight of your headshot and socials on the conference webpage
- An opportunity to interview for our Newsletter to discuss your experience as a Ruby Central Guide.
- Dedicated front-row seating at all the conference keynotes
### **Guide requirements**
Guides support the Scholars through mentorship, guidance, and professional networking leading up to and during the conference. Guides should be familiar with the Ruby and/or Rails community and can create networking opportunities, and will help the Scholar navigate a professional conference. We seek Guides who can:
- Commit to supporting and actively mentoring aspiring Rubyists by offering guidance and insight throughout your Scholars' mini-project.
- Recommend conference talks based on Scholars' interests, current skill levels, and experiences.
- Make introductions between your Scholar and established developers, especially ones that might be particularly influential in their areas of interest.
- Give feedback and advice on working in the Ruby/Rails world.
- Obligation to attend 3 meet-ups: Speakers & Scholars Receptions; Pre-conference meeting; Post-conference meeting
[Apply Now (Guides)](https://rubycentral.teamtailor.com/jobs/7248113-guide-application?ref=rubycentral.org)
### **Questions?**
If there are any inquiries about the scholarship program, please reach us at scholarships@rubycentral.org.









### Freedom Dumlao
URL: https://rubycentral.org/freedom-dumlao/
Last updated: 2026-05-26T17:14:55.000Z
Treasurer
### Support Us
URL: https://rubycentral.org/support/
Last updated: 2026-01-05T15:51:29.000Z
Would you like to help support Ruby Central? Here are the ways you can help:
## Our Annual Report
Transparency and accountability are core to Ruby Central’s mission. This year, we are publishing our first comprehensive Annual Report, covering the years **2022–2024**, to provide a clear view into our work, finances, and impact across this period. The report reflects both the challenges we encountered and the progress we made together while supporting the Ruby ecosystem.
**Read the Ruby Central Annual Report (2022–2024)**
[2022-2024-RC-Annual-Report2022-2024-RC-Annual-Report.pdf17 MBdownload-circle](https://rubycentral.org/content/files/2026/01/2022-2024-RC-Annual-Report.pdf "Download")
## Consider Becoming a Major Donor
[Click here to learn more about annual sponsorship packages and get contacted by our Executive Director](https://webforms.pipedrive.com/f/6aW4k05dMuwVRUNS7cR5nhHZyJFbhc7hrhQnQ21odD5tYLNhzwTSa9Xu1bguTOzePV?ref=rubycentral.org).
## Support Our Conferences
[Buy a ticket to RubyConf 2024](rubyconf.org) or [become a sponsor](https://rubyconf.org/images/RubyConf-2024-Prospectus.pdf?ref=rubycentral.org)!
## One-off Donations
[Here is a link to pay-what-you-can donations](https://donate.stripe.com/3cs5ncgyfcAsgjC7sw?ref=rubycentral.org). We know everyone's finances vary, and not everyone can afford to donate regularly, so we created this donation link to allow anyone to support our work at any level, as a one-time gift.
## Sustaining Memberships
Individual and Corporate Ruby Central monthly memberships help support us *sustainably*. Having regular monthly support helps us plan our open source projects more effectively.
[You can sign up for a membership here.](https://rubycentral.org/#/portal/signup)
If your employer is registered with Benevity, you can get enable employer matching funds for us through your company's profile. [Our org profile is here.](https://causes.benevity.org/causes/840-300040446?ref=rubycentral.org)
These memberships started life as Ruby Together in 2015 and merged with Ruby Central in 2021\. You can read more about [Ruby Together and Ruby Central coming together](https://rubycentral.org/news/ruby-together-and-ruby-central--coming-together/) and about [Ruby Central's journey to today](https://rubycentral.org/news/the-new-ruby-central-and-how-we-got-here/).
Ruby Central’s membership program was created so that the community can come together to help us achieve our mission. We are here to create pathways for the community to come together, to maintain the software ecosystem, and enable individuals in their learning journeys.
The membership program helps the organization achieve this vision. As a member you receive a monthly newsletter on how we’ve spent the money raised and how we’re moving the ecosystem forward. You’ll also be invited to a private online space which allows you to be a bigger voice at the table.
## Volunteer
We could use volunteer help for almost everything. If you're interested in sharing your time, view our [Leadership page](https://rubycentral.org/leadership/) on all of our volunteering opportunities.
## Code
Our community is filled with developers! For cost- and time-saving reasons, we have moved away from custom software and toward hosted solutions. It's the only feasible option for a tiny non-profit like ourselves.
This marketing site is run on Ghost, which also manages our membership program (payments, account self-service, and newsletters). [The Ghost theme is open-sourced and available here](https://github.com/rubycentral/rubycentral-theme?ref=rubycentral.org) if you want to help fix problems or propose redesigns.
### Ruby Conferences
URL: https://rubycentral.org/conferences/
Last updated: 2026-03-31T19:22:07.000Z
Ruby Central had organized two annual software conferences, RubyConf and RailsConf. RubyConf has now become the official flagship annual event hosted by Ruby Central with RailsConf having its final journey in 2025.
## [RubyConf](https://rubycentral.org/volunteer/)
The Ruby community’s annual celebration of all things Ruby! Every fall, we gather Ruby enthusiasts together to enjoy detailed talks about exciting new projects; meet and network with other Ruby developers; and hear from the community’s leading minds.
[**2026 Las Vegas - Get Tickets Now!**](https://ti.to/rubyconf/rubyconf-2026?ref=rubycentral.org)
[IndexJoin RubyConf 2026 in Las Vegas, July 14–16, for three days of Ruby talks, live coding, and community events. Grab your ticket and connect with fellow developers.July 14–16, Las Vegas](https://rubyconf.org/?ref=rubycentral.org)
## [RailsConf](http://railsconf.org/?ref=rubycentral.org)
The world’s largest gathering of Rails developers, brought together to further discussion and learning about building, managing, and testing Rails applications. With a specific focus on Rails, conference topics can range from new users to administration to advanced techniques.
After nearly 20 years, RailsConf 2025 was the final gathering of its kind—a tribute to the legacy and future of Rails and the community members who have been part of this journey with us.
Here's a recap video of what made this event so special. You can view all talks from RailsConf 2025 on our YouTube channel. We hope to see you again at [RubyConf 2026 in Las Vegas](https://rubyconf.org/?ref=rubycentral.org)!
## The Video Showcases
- [RailsConf 2025 Philadelphia](https://www.youtube.com/watch?v=vG3v%5FFHcbSE&list=PLbHJudTY1K0fOQPBF0uTwFIGuMVEKnV1p&ref=rubycentral.org)
- [RubyConf 2024 Chicago](https://www.youtube.com/watch?v=rbGe9oWcV0k&list=PLbHJudTY1K0fFsGc9a2tBFR-iUulnMJM7&ref=rubycentral.org)
- RailsConf [2024 Detroit](https://www.youtube.com/playlist?list=PLbHJudTY1K0chrs%5FE%5FXFz2pOJ3d8jCayh&ref=rubycentral.org)
- [RubyConf 2023 San Diego](https://www.youtube.com/watch?v=4MM5b2F9zrM&ref=rubycentral.org) (with Matz's Keynote)
- RailsConf [2023 Atlanta](https://www.youtube.com/watch?v=3ndcqh9fTGA&list=PLbHJudTY1K0cOM1jfOsQLYPTLxQf1Ui1C&ref=rubycentral.org)
To view our full video catalog, watch our [Youtube channel](https://youtube.com/rubycentral?ref=rubycentral.org).
[Ruby CentralRuby Central is a non-profit organization that supports and advances the Ruby programming language and a welcoming and diverse worldwide Ruby community. We organize the annual software conferences, RubyConf and RailsConf, to which this video channel is dedicated. Learn more | www.rubycentral.org RubyConf is the Ruby community’s Fall celebration of all things Ruby! Ruby enthusiasts gather to enjoy detailed talks about exciting new projects; meet and network with other Ruby developers; and hear from the community’s leading minds, including Yukihiro Matsumoto (“Matz”), the creator of the Ruby language. RailsConf is the world’s largest gathering of Rails developers, brought together in the Spring to further discuss and learn about building, managing, and testing Rails applications. With a specific focus on Rails, conference topics can range from new users to administration to advanced techniques.YouTube](https://www.youtube.com/@RubyCentral?ref=rubycentral.org)
## Volunteer at our Conferences
[Learn More](https://rubycentral.org/volunteer/)
## Regional US and International
[Ruby ConferencesA curated calendar of Ruby conferences worldwide, including speaking opportunities and registration info.](https://rubyconferences.org/?ref=rubycentral.org)
For feedback on this page, [contact us](mailto:irene@rubycentral.org).
### Volunteer
URL: https://rubycentral.org/volunteer/
Last updated: 2026-04-08T23:34:22.000Z
## Volunteer with Ruby Central
---
If you are interested in donating your time to Ruby Central and the community, we have several opportunities for you to consider. Please fill out our interest form, and we will be in touch!
[Apply to Volunteer](https://docs.google.com/forms/d/e/1FAIpQLSf5EZXRHmcdGw0QTXte9osX3lMY2cI8%5FChh7RK4o93iDLi9Pg/viewform?ref=rubycentral.org)
## Volunteer at the Conference
---
### Conference Volunteer
Conference volunteers play an essential role in the operations of the conference. Volunteers will assist in checking in attendees, troubleshooting, answering questions, and being cheerful faces for the conference. Volunteers are expected to be familiar with the conference schedule, events, and other areas that will create a positive conference experience. To learn more about the Conference Volunteer opportunity, [please review our Volunteer Factsheet](https://tinyurl.com/4536brkd?ref=rubycentral.org).
[Apply to Volunteer](https://forms.gle/a8fPyvaKQQprK3VY7?ref=rubycentral.org)
### Guides (as part of the Scholars and Guides program)
Guides are volunteer mentors who support the conference Scholars through mentorship, guidance, and professional networking leading up to and during a Ruby or Rails conference. Guides should be familiar with the Ruby and/or Rails community and can create networking opportunities, and will help the Scholar navigate a professional conference.
[Learn More](https://rubycentral.org/scholars%5Fguides%5Fprogram/)
### **Program Committee Member**
We seek dedicated community members to actively contribute to the conference planning process. The overall time commitment is approximately 2-6 hours per week from July - November. With roughly 1 hour every month to meet virtually as a committee.
[Learn More](https://forms.gle/nvUdMFjPb2XpXCqq6?ref=rubycentral.org)
### **Speaker Mentors**
We are seeking previous conference speakers to mentor our incoming speakers. Our new speakers seek guidance on developing an exciting conference talk and what they can do to prepare. Mentors are only assigned upon speakers' request. This is NOT a full-time commitment.
[Apply to Volunteer](https://forms.gle/8fBS67Yrd1rGUrgF6?ref=rubycentral.org)
### **Ruby Central Committees**
We are creating a *new* set of committees, each comprising some Ruby Central folks and some community members. As an organization that works for the Ruby community, we want to include community members in guiding the direction of our work and leading us all forward.
Some committees we are thinking of starting might be focused on: Conferences (both Ruby Central and partnering with others), Membership, Local Meetups, DEI, Scholarship and Education, New Developer Experience, and Documentation.
[Learn More](mailto:adarsh@rubycentral.org)
### Scholarships
URL: https://rubycentral.org/scholarships/
Last updated: 2025-06-27T15:21:00.000Z

**Scholars and Guides Program - RailsConf 2023*
Ruby Central works with our fantastic sponsors and supporters to provide financial assistance and support for our community. Contact us at [sponsors@rubycentral.org](mailto:sponsors@rubycentral.org) if you are interested in becoming a sponsor or supporter.
## **Scholars (as part as the Scholars and Guides program)**
Scholars are new to the Ruby and Rails community and looking to make professional connections. While the Scholars application is open to everyone, we encourage students, women, BIPOC communities, and other underrepresented groups in the technology sector to apply. Those accepted to the program will receive a complimentary ticket to the conference and can receive travel reimbursement.
[Learn More](https://rubycentral.org/scholars%5Fguides%5Fprogram/)
### About Us
URL: https://rubycentral.org/about/
Last updated: 2026-05-26T18:06:28.000Z
## Our Vision
We are a non-profit organization dedicated to supporting and advancing the Ruby programming language and a welcoming and diverse worldwide Ruby community. We create spaces and events, online and offline, for the community to come together to connect, engage, and educate each other. We provide a support ecosystem for Ruby development to thrive by operating services and maintaining software for the good of the community.
##
Our Values
#### Continuous Learning
We are lifelong learners with a growth mindset. We lead with curiosity and intentionally improve as we learn.
#### Impact
We prioritize actions that serve the Ruby community such that individuals can say “that community, they helped make me who I am today” and "thank goodness these services and software have been maintained \[well\]."
#### Trust
We value trust and transparency because it is these factors that allow developers to use our services and software to build their own reliable software. As professionals, we operate with integrity to our community and vendors.
#### Inclusive
We truly believe that those spaces are better if they are diverse and inclusive. More viewpoints make us stronger, not weaker. We prioritize those who have been historically marginalized and listen to them when we get something wrong.
#### Collaboration
None of us is as good as all of us together. We work hard to make sure all voices are heard.
#### Empathetic
We act with consideration of the perspective of others while not making too many assumptions. We lead with appreciation and gratitude. We have a duty of care to people in our conference and community spaces.
#### Fun!
We create events and spaces where people have a good time and look forward to returning
---
## Our History
Ruby Central, Inc. was established by David Alan Black and Chad Fowler after organizing the inaugural International Ruby Conference in 2001\. They recognized the growing interest in Ruby and formed the nonprofit organization to handle future conferences. The first Ruby Central-hosted RubyConf took place in Seattle in 2002.
[Learn More](https://rubycentral.org/history/)
### David Corson-Knowles
URL: https://rubycentral.org/david-corson-knowles/
Last updated: 2025-07-03T21:19:43.000Z
Board Member
### Thank You!
URL: https://rubycentral.org/thankyou/
Last updated: 2025-06-18T22:17:05.000Z
_This page is for paying subscribers only._
### Major Donor Prospectus
URL: https://rubycentral.org/prospectus/
Last updated: 2024-06-10T04:13:53.000Z
[2024\_06\_06\_rubycentral\_donor\_prospectus\_v22024\_06\_06\_rubycentral\_donor\_prospectus\_v2.pdf75 MBdownload-circle](https://rubycentral.org/content/files/2024/06/2024%5F06%5F06%5Frubycentral%5Fdonor%5Fprospectus%5Fv2.pdf "Download")
### Program Support
URL: https://rubycentral.org/open-source-program-support/
Last updated: 2024-11-13T02:17:43.000Z
### Our program is funded by several sources
As part of our sustainability initiative, we are seeking corporate sponsors to build up our foundation of support.
### Open Source Program
URL: https://rubycentral.org/open-source/
Last updated: 2024-11-13T02:16:09.000Z
### Serving our community
Ruby Central's Open Source Program focuses on maintaining and improving critical infrastructure and tools for the Ruby ecosystem. The program aims to ensure these fundamental components are secure, reliable, scalable, and fast, enabling developers to effectively package, share, and use Ruby software.
Ruby Central recognizes the importance of sustainable, high-quality tooling and infrastructure for both short-term business success and the long-term vitality of the Ruby community. Through this program, Ruby Central fulfills its unique position and obligation to coordinate, fund, develop, and operate shared resources that benefit the entire Ruby ecosystem.
### Program News
URL: https://rubycentral.org/program-news/
Last updated: 2024-11-07T01:58:36.000Z
_No content available._
### Our Mission
URL: https://rubycentral.org/our-mission/
Last updated: 2024-11-07T02:03:16.000Z
To sustainably provide high-quality and secure infrastructure through RubyGems to reliably build Ruby software that enables businesses and our community to thrive. We are dedicated to supporting impactful open source projects on behalf of the Ruby community and fostering the growth of open source contributors to ensure the continuity of the Ruby ecosystem.
### Our Vision
URL: https://rubycentral.org/our-vision/
Last updated: 2026-01-07T16:27:47.000Z
Our vision for 2026 focuses on three pillars: Security, Stability, and Sustainability. Security is our top focus continuing our work on addressing supply chain security and improving our cloud infrastructure controls. Our Stability efforts center on disaster recovery planning and improving operations documentation. Sustainability looks at providing stable funding for maintenance and crucial projects and paving the way for expanding team contributions.
### Contribute
URL: https://rubycentral.org/contribute/
Last updated: 2024-11-07T02:06:43.000Z
There are numerous ways to get involved.
- Contribute code to [rubygems](https://github.com/rubygems/rubygems?ref=rubycentral.org)
- Join the conversation in [the Bundler Slack](https://join.slack.com/t/bundler/shared%5Finvite/zt-1rrsuuv3m-OmXKWQf8K6iSla4~F1DBjQ?ref=rubycentral.org)
- Read our RFCS and provide feedback: [github.com/rubygems/rfcs](https://github.com/rubygems/rfcs?ref=rubycentral.org)
If you think you've found a security issue, please report it via [HackerOne](https://hackerone.com/rubygems?ref=rubycentral.org).
### Bundler
URL: https://rubycentral.org/oss-project-bundler/
Last updated: 2024-11-07T02:09:22.000Z
[Bundler](https://bundler.io/?ref=rubycentral.org) is an essential tool in the Ruby ecosystem that simplifies dependency management. It provides a consistent environment for Ruby projects by tracking and installing the exact gems and versions that are needed.
### Gemstash
URL: https://rubycentral.org/oss-project-gemstash/
Last updated: 2024-11-07T02:10:52.000Z
[Gemstash](https://github.com/rubygems/gemstash?ref=rubycentral.org) serves as a versatile tool for rubygem management within organizations. It functions as both a cache for remote servers like RubyGems.org and a private gem source.
### RubyAPI
URL: https://rubycentral.org/oss-project-rubyapi/
Last updated: 2024-11-07T02:11:58.000Z
[RubyAPI](https://rubyapi.org/?ref=rubycentral.org) provides comprehensive documentation through its website for the Ruby programming language. It serves as a valuable resource for Ruby developers, offering advanced search & detailed information on various aspects of the language.
## Posts
### Ruby Shield: A Reflection on Four Years of Securing the Ruby Supply Chain
URL: https://rubycentral.org/news/ruby-shield-a-reflection-on-four-years-of-securing-the-ruby-supply-chain/
Last updated: 2026-09-12T18:00:59.000Z
In July 2022, Ruby Central and Shopify launched [Ruby Shield](https://rubycentral.org/news/ruby-shield/), a four-year partnership built around a single goal: giving the tools at the heart of the Ruby ecosystem the sustained investment they need to stay secure and reliable. Shopify committed $1 million over four years, along with dedicated engineering time from its Ruby and Rails Infrastructure team, and left it to Ruby Central to direct that support wherever it would do the most good for the community.
Software supply chain attacks are climbing sharply across every major package ecosystem, and RubyGems.org, the registry that nearly every Ruby application depends on, was being maintained on a shoestring. Ruby Shield gave us the ability to plan security and reliability work on a timescale of years rather than days.
After four years, this June, Ruby Shield came to a close. Ruby Shield helped move RubyGems.org from best-effort, volunteer-maintained project toward a professionally operated service with modern authentication, verifiable publishing, and around-the-clock coverage. Along the way, the ecosystem it protects has served tens of billions of gem downloads a year with almost no interruption. This post is our final reflection on the program: what it funded, what changed because of it, and where the work goes from here.
## The First Three Years
Ruby Shield existed to strengthen and secure Ruby's software supply chain, and that meant investing on two fronts at once. The first was operational: keeping RubyGems.org reliably online for developers worldwide and automated systems that reach for it every day. The second was security: closing the gaps that attackers most often exploit to compromise open source packages. We shared progress along the way, most notably in our [Ruby Shield update in early 2023](https://rubycentral.org/news/ruby-shield-update-winter-2023/) and our [first Annual Open Source Report](https://rubycentral.org/news/ruby-centrals-first-annual-oss-report-2024/), and the highlights below trace the through-line across all three years.
### On-call rotation
Before Ruby Shield, RubyGems.org was maintained mostly by a small team of unpaid volunteers. Ruby Shield funded a shift to a follow-the-sun on-call rotation, with engineers awake and responsible for the service somewhere in the world at every hour of the day. This helped the sustainability of operations immensely. Reliability is easy to overlook, because it is invisible when it works. But every one of those downloads is a developer, a deploy, or a CI run that would have stalled if the registry had been down. When RubyGems.org goes down, a human is already aware, communicating, and working to resolve the incident.
### MFA improvements
Account takeover is one of the most common ways attackers compromise a package: steal or guess a maintainer's credentials, then publish a malicious version of a gem that thousands of projects already trust. A large share of Ruby Shield's security work went into making that far harder.
Building on the multi-factor authentication RubyGems.org already offered, we made it mandatory for the maintainers of the most-downloaded gems, starting with owners of gems above 180 million total downloads and expanding coverage from there. You can read the original policy in [Requiring MFA on popular gem maintainers](https://blog.rubygems.org/2022/08/15/requiring-mfa-on-popular-gems.html?ref=rubycentral.org). We then added [hardware security key and passkey (WebAuthn) support](https://blog.rubygems.org/2022/12/21/introducing-hardware-security-token-and-passkey-support.html?ref=rubycentral.org), giving maintainers phishing-resistant options that are dramatically harder to steal than a password or a one-time code.
Together these changes hardened the accounts that matter most, the ones whose compromise would ripple out across the largest share of the ecosystem. Raising the bar on authentication for popular gems directly reduces the risk of the account takeovers that so often begin a supply chain attack.
### Trusted publishing
Even with strong authentication, long-lived API tokens are a liability. They sit in CI configurations and on developer machines, and a single leaked token can be replayed by anyone who finds it. [Trusted Publishing](https://blog.rubygems.org/2023/12/14/trusted-publishing.html?ref=rubycentral.org), one of the program's signature deliverables, addressed this directly. Instead of storing a permanent token, a gem author connects their gem to a trusted environment such as a GitHub Actions workflow, and each publish uses a short-lived credential exchanged automatically over OpenID Connect.
The security gain is substantial. There is no long-lived secret to leak, credentials expire almost immediately, and the provenance of a release becomes transparent: what gets published can be tied back to the repository and workflow that produced it. Trusted Publishing brought RubyGems.org in line with the strongest publishing practices across the packaging world and gave the Ruby community a safer default for automated releases.
### Bundler Lockfile Checksums
Security at the registry only goes so far if the software installing gems cannot verify what it receives. [Bundler Lockfile Checksums](https://blog.rubygems.org/2024/12/19/bundler-v2-6?ref=rubycentral.org), a nearly two-year effort involving four engineers, closed that gap on the client side. When enabled, Bundler records the checksum of every gem version in the lockfile and verifies it before installation, so a tampered or substituted package is caught before it ever reaches a developer's machine or a production deploy. With Bundler 4, we set this as the default.
This protects against attacks that authentication and authorization cannot see, such as a package being altered somewhere between publication and installation. It gives teams a way to guarantee that the gems running in production are exactly the ones they locked during development.
Ruby Shield did not accomplish all of this on its own. It worked alongside support from AWS, the Sovereign Tech Agency, Alpha-Omega, and Ruby Central's individual and corporate members. What Ruby Shield uniquely provided was multi-year stability: the confidence to start ambitious work, staff it properly, and see it through to release.
## The Final Year
If the first three years were about building new capabilities, the final year was about maturing them into durable practice. The headline features were largely in place; the work that Ruby Shield funded in its last stretch went into the less visible layer underneath, the processes, tooling, and hardening that turn a set of features into a service an ecosystem can rely on. The same two fronts held: keeping the service running well, and closing the gaps attackers look for.
### Prohibiting Reused Passwords
Reused passwords are a persistent avenue for account takeover: a credential leaked in an unrelated breach can be replayed against a package registry. RubyGems.org now checks user passwords against the Have I Been Pwned database at login. When a compromised password is detected, the user is shown an explanation and automatically sent a reset link, after which they can carry on as normal. The check is done privately, without ever sending the full password or its full hash to a third party. You can read the details in [Protecting rubygems.org from the outside in](https://blog.rubygems.org/2026/04/09/protecting-rubygems-from-the-outside-in.html?ref=rubycentral.org).
### Detecting and defending against abuse
Some of the year's most valuable work went into catching bad actors earlier and giving the team the visibility to respond. Previously, validating a published gem meant unpacking its metadata into a Ruby object, an approach a crafted malicious gem could abuse to mount a denial-of-service attack against the push process itself. We merged new validation rules that detect these gems much earlier, without parsing the metadata at all, described alongside the password work in [the same post above](https://blog.rubygems.org/2026/04/09/protecting-rubygems-from-the-outside-in.html?ref=rubycentral.org).
Around that, we built out a broader set of abuse-response tools: protections on reserved gem names, blocks on disposable email domains, webhook rate limits, spam-account cleanup, and temporary registration controls we can switch on during an active abuse event. We also wired monitoring into login, signup, and gem-push behavior, so the team now has real signal for detection and triage. Investigating suspicious activity used to be a one-off scramble; it is now an observable, repeatable workflow. For a fuller picture of how this layered defense works in practice, see [How RubyGems.org Protects Our Community's Critical OSS Infrastructure](https://blog.rubygems.org/2025/08/25/rubygems-security-response.html?ref=rubycentral.org).
### Dependency Cooldowns
Attackers who compromise a maintainer's account are betting that projects will pull in their poisoned release before anyone spots it. Dependency cooldowns call that bet, refusing any version until it has been public for a configured period of time so new releases can be vetted before Bundler resolves to them. Cooldowns required some foundational work underneath it: RubyGems.org's Compact Index was rebuilt to serve each version's time of publish for Bundler to read. More more information, please read [Cool down before you install: give new gems a few days to be vetted](https://blog.rubygems.org/2026/06/03/cooldown-let-new-gems-be-vetted.html?ref=rubycentral.org).
### Maturing how we operate
For much of its history, access to RubyGems.org was managed informally, which was workable with a handful of long-tenured volunteers but risky as the team grows and changes. This year we replaced that with a documented operating model: a defined set of team roles, a written PII policy, an offboarding checklist that catalogues every access point to revoke when someone leaves, and a standard onboarding session that walks every new engineer, security hire, or rotating contributor through the stack and how it is run. Access is now something we grant and revoke deliberately, which shrinks the window an attacker could exploit through a stale or forgotten credential.
We also rebuilt the on-call program itself. Expanding the roster to allow a sustainable rotation while keeping a follow-the-sun model. We drafted comprehensive runbooks covering our monitors and the common operational tasks. The practical effect is that any on-call engineer can now respond to an incident without prior hands-on experience with that specific system, which makes coverage both broader and more resilient.
## How Ruby Shield Transformed Our Program
Ruby Shield's most lasting effect is not any single feature. It is the way it changed how Ruby Central thinks about its role.
When the program began, Ruby Central's open source work was closer to a series of funded tasks than a program with a strategy. Four years of stable investment let us plan, hire, and commit to multi-year efforts, and in doing so it pushed us to start thinking and behaving like a software foundation: formalizing governance, writing down policies, defining roles, maturing our operations, and treating RubyGems.org as critical infrastructure that deserves professional stewardship rather than best-effort volunteering. The maturation described in the last year is, in many ways, the visible result of that shift in mindset.
It also changed how we think about who should sustain this work. Ruby Shield brought to light a question that had been easy to avoid: why were the tools that nearly every Ruby company depends on being kept alive by a small number of people and a thin, uncertain funding base? If this infrastructure is truly critical, then supporting it should not rest on the generosity of a single company or the spare time of volunteers. It should be a shared responsibility of the companies that build their businesses on Ruby.
That thinking is what led us to the Ruby Alliance. Rather than depending on one company to carry this load, we want to bring together a core group of Ruby companies to sustain RubyGems.org and the Ruby toolchain collectively. Ruby Shield proved the model works when a company invests with vision and without strings; the Ruby Alliance is our effort to broaden that from a single partnership into a durable coalition, so the security and reliability gains of the last four years continue and compound rather than depending on any one sponsor.
## Closing
None of this would have happened without Shopify. Committing $1 million over four years, along with the time of its own engineers, and then trusting Ruby Central to direct that support wherever it would help the community most, took real vision. Shopify saw that the health of the Ruby supply chain was worth investing in for its own sake, and the entire ecosystem is more secure for it. We are deeply grateful for their partnership.
It is hard to overstate how much this program shaped Ruby Central. Ruby Shield did more than fund a list of features. It gave us the stability to grow into a more capable steward of RubyGems, RubyGems.org, and Bundler, and it reset our expectations for what this infrastructure can and should be. The work it started, from modern authentication and verifiable publishing to a professionally operated, well-monitored service, is now part of how we run things every day.
The work does not end here, and it cannot be carried by one company alone. Shopify is continuing to support these efforts by [joining the Ruby Alliance](https://rubycentral.org/news/shopify-joins-the-ruby-alliance/). If your business is built on Ruby, RubyGems.org is part of your supply chain, and its security and reliability are worth protecting. We encourage the companies that depend on this ecosystem to join us in sustaining it, through the [Ruby Alliance](https://rubycentral.org/sponsors/#ruby-alliance) and [our supporter programs](https://rubygems.org/pages/supporters?ref=rubycentral.org), so that we can build on this foundation. Ruby Shield showed what is possible when a company invests in the commons. Now we would like to make that investment something the whole community shares.
*Updated: September 12, 2026 - removed duplicated clause.*
### Software Foundation Musings
URL: https://rubycentral.org/news/software-foundation-musings/
Last updated: 2026-08-31T21:43:52.000Z
For the last several months, I've been incredibly busy. With our former executive director's departure, I've picked up extra work supporting the board and staff, especially in preparing for RubyConf.
Two years ago, when I stepped into this role, I started by observing where we stood as operators of RubyGems. A few gaps jumped out at me: lack of governance, no formal policies, and thin internal documentation. These weren't just nice to haves; I flagged them as critical from the start. What I didn't see yet was that they were also the backbone of a strong software foundation. That realization led me to a bigger question: what would it take to close the gaps standing between us and becoming one?
## Learning from other ecosystems
Fortunately, this role introduced me to peers from other ecosystems, including Python, Rust, and JavaScript, among others. There were working groups that met regularly to discuss these kinds of topics. This was unexpected and a major boost. I could talk to people who had already traveled this path, share my challenges, hear their perspectives, and pull in their hard-won expertise. The more conversations I had, the more I realized how much further we had to go.
## Sustainability became the focus
In the fall of 2024, one of my first conclusions was that we weren't sustainable. In our [State of RubyGems talk](https://youtu.be/UH56pZs%5FNP0?si=DLW1rSPhvviJk9-h&t=1632&ref=rubycentral.org) at RubyConf that year, I named sustainability as one of our pillars. It became my focus because this mission-critical service has to be sustainable. For years, it had relied purely on volunteers and conference revenue, and it’s not reasonable to expect either of those to hold up over time. [Since 2022](https://rubycentral.org/news/ruby-centrals-first-annual-oss-report-2024/), generous donations and grants have brought in all-time highs in financial support, but that funding was based on one-time grants. This brings us no closer to having recurring revenue to cover the cost of operating RubyGems.
## What’s coming next?
Now that RubyConf 2026 is behind us, more of my attention is going toward defining what it actually means for Ruby Central to become a software foundation. My peers across other ecosystems are already helping to guide that thinking, though every ecosystem is different, so there's no version of this we can simply copy.
Which brings us to today. Later in September, I'll be in Nova Scotia for the [Open Source Congress](https://opensourcecongress.org/?ref=rubycentral.org), an invite-only event for leaders across the open source ecosystem. I'll be on a panel about sustainability in open source, sharing what we’ve done to move our package registry toward a sustainable model. I’m excited to talk shop with so many experts in the field, and to see what I can bring back to Ruby Central.
I'm still exploring what this means for Ruby Central. Though I don't have the details yet, it will be a shift for our organization. We have a lot of work to do, but Ruby's package ecosystem needs it, and it's work we're eager to take on. We'll come back with more concrete thoughts about what this means after I return from the Open Source Congress and after we have a little more time internally to work through everything.
### Meet RubyConf 2026 Scholar: Shuveksha Tuladhar
URL: https://rubycentral.org/news/meet-rubyconf-2026-scholar-shuveksha-tuladhar/
Last updated: 2026-08-27T17:00:43.000Z
Thinking of applying to next year's RubyConf Scholars and Guides program? Read on to hear from this year's Scholars about what it was like and why you should take the leap and apply!

### Name:
Shuveksha Tuladhar
### Professional Title:
Software Developer Apprentice
### How did you get into Ruby? What's your Ruby story?
I started learning Ruby and Ruby on Rails through Code the Dream as part of my journey into software development. I enjoyed learning Ruby so much that it quickly became my natural language.
### Are there any Ruby projects you're working on that you're excited about? Tell us all about it!
I am currently working on several Ruby projects, both at work and through personal projects. Ruby has become a big part of my daily life. I really enjoy being able to take an idea, turn it into an application, and actually use it myself. It's really rewarding to see something that started as a simple idea become something useful in my everyday life.
### Why did you decide to apply and join the Scholars & Guides program?
Because this was going to be my first RubyConf, and I wanted to make the most of the opportunity. I hoped to meet people in the Ruby community, learn from their experiences, and make friends, and build network. The program gave me a supportive way to do all of that while feeling more connected to the Ruby community.
### What was the impact or highlight from the Scholars & Guides program experience, and how has it affected your Ruby journey or career after you completed the program?
One of the biggest highlights of the program was giving my first-ever lightning talk. Sharing a project I built and getting on stage gave me a lot of confidence. It encouraged me to keep sharing what I build.
### What surprised you, if anything, about your experience in the Scholars & Guides program or with attending the conference?
I was surprised by how welcoming everyone was. Before the conference, I wasn't sure what to expect as a first-time attendee. But it was easy to start conversations and meet people.
### How did you feel attending your first RubyConf or RailsConf?
It was my first RubyConf and my first tech conference, so it felt like a big milestone for me. By the end of the conference, I felt more confident, inspired, and connected. Another unforgettable moment was meeting Matz. As someone who loves Ruby, meeting the person who created the language was genuinely a bucket-list moment for me.
### Any advice for first-time guides or first-time scholars?
For Scholars, my biggest advice is to take advantage of every opportunity to connect with people. Don't be afraid to introduce yourself, ask questions, or join a conversation.
### Any advice for first-time conference attendees?
Don't feel like you have to attend everything. Pick a few talks that interest you, but also leave time to talk to people and enjoy the experience. And don't be afraid to say hello to someone. Most people are there because they enjoy the community, and you may be surprised by how easy it is to connect.
### *Thank you Shuveksha for sharing your story! Feeling ready to apply to be a RubyConf 2027 Scholar or Guide? Sign up* [*here*](https://rubycentral.org/scholars%5Fguides%5Fprogram/) *today!*
### The Scholars & Guides Program: Community, Mentorship, and the Spirit of Ruby
URL: https://rubycentral.org/news/community-mentorship-and-the-spirit-of-ruby/
Last updated: 2026-08-20T17:00:22.000Z
The [Scholars & Guides Program](https://rubycentral.org/scholars%5Fguides%5Fprogram/) is one of Ruby Central's most direct expressions of what this community is built on. The program pairs aspiring Rubyists from underrepresented communities with experienced mentors, called Guides, to help them navigate RubyConf, grow as developers, and find their footing in a community that genuinely wants to see them thrive.
Rubyists know by heart: Matz is nice and so we are nice, or MINASWAN. It flows directly from the philosophy Yukihiro "Matz" Matsumoto embedded into Ruby itself. Ruby exists to make developers as productive as possible, and that productivity is only possible when the community surrounding it keeps bringing in fresh minds, new perspectives, and people who are given the support they need to take their talents and break barriers in the industry. The Scholars & Guides Program is how that philosophy stays alive beyond the language itself.
---
## What It Means to Be a Scholar
For many participants, the Scholars & Guides Program is their entry point into a world that can feel intimidating from the outside. First-time conference attendees, bootcamp graduates, career changers, and early-career developers all find their way into the program carrying some combination of excitement and nerves.
Sunjay Armstead, a UX Engineer who attended RubyConf 2024 as a Scholar, put it plainly:
> "I was very intimidated by attending my first RubyConf. It was also my first ever technical conference. I had no clue what to expect, and was unsure of how to set goals and expectations. I needed a guide; someone to show me the ropes and help me make the most of my three days away." -- Sunjay Armstead, Scholar
What he found was something he did not quite expect.
> "Wait a minute... People are interested in the work I do? People want to talk to me? People want to help me build my network? I certainly couldn't believe it at first, but the Scholars & Guides program showed me just how great Rubyists are." -- Sunjay Armstead, Scholar
Salomon Charabati, a Software Engineer with eight years of Ruby experience, came to the program looking to plug into the community in a more meaningful way.
> "I wanted to meet the community and be involved in it. The power of the Ruby community surprised me." -- Salomon Charabati, Scholar
His advice to anyone on the fence is simple: "Have fun and enjoy every moment of it. Go and talk to people. That's the best part of it."
Looking to get your head start as a Scholar? Apply as a Scholar today.
[Become a Scholar](https://rubycentral.teamtailor.com/jobs/7247950-scholars-application?ref=rubycentral.org)
---
## The Hallway Track and What Happens In Between
One of the program's most repeated pieces of wisdom is about the unofficial part of the conference: the conversations before the first talk, between sessions, over coffee, and well into the evening. Scholars and Guides alike refer to this as the hallway track, and many credit it as the most transformative part of their experience.
Sunjay describes it this way:
> "The hallway track is not usually on the official schedule, but it exists. It's that time before talks, between tracks, and after each day wraps up. And it's in these in-between times that you'll grow the most by connecting with others. I am where I am today because of a conversation in the hallway." – Sunjay Armstead, Scholar
---
## What It Means to Be a Guide
The Scholars & Guides Program is not a one-way exchange. Guides consistently describe their experience as one of the most rewarding things they do at any conference, and often, in their professional lives more broadly.
Andy Andrea, a Lead Software Engineer who has been a Guide at multiple Ruby Central conferences, was initially uncertain whether he was the right fit.
> "I was a little worried that I wouldn't be a good fit. I hadn't really interacted with the community much before and didn't have too much experience going to conferences. That said, I did really love and value mentorship, so I figured I'd leave it in the hands of the scholars committee." -- Andy Andrea, Guide
After that first year, he knew he would keep coming back. And the reason goes beyond generosity.
> "I learn so much from getting to chat with people who are relatively new to software development or even just to Ruby. The types of questions that scholars ask are often completely different from what I chat about with more veteran Rubyists. In many cases, I feel like they're the questions that many of us have forgotten to ask over the years." -- Andy Andrea, Guide
He goes further in describing what witnessing scholars' growth actually feels like:
> "Seeing scholars give their first lightning talks, make their first open-source contributions, come back as guides for later conferences or even get hired at a new job can feel borderline indulgent, especially when you get to celebrate alongside the rest of the scholars and guides in the program. It's certainly extremely energizing -- like a triple shot of espresso to the soul." -- Andy Andrea, Guide
Chris Oliver, Founder and long-time community contributor, joined the program because he remembered what it felt like to be new.
> "I was that awkward person at my first handful of conferences, so I wanted to help give a warm welcome to new people. We're all here to share our love for the same thing, so we should do what it takes to make people feel welcome." -- Chris Oliver, Guide
And Frederick Cheung, a Senior Software Engineer, found that the impact of being a Guide extends well beyond the conference itself.
> "One of my scholars got in touch a few months later asking for tips about CFPs, so I felt so proud when I saw that he got a speaker slot at Euruko. I'm sure he would have done just fine without me!" -- Frederick Cheung, Guide
His broader advice to anyone considering volunteering: "Approach it with an open mind. You won't know what help someone needs, or what help they can give you, until you get to know them."
Thinking about becoming a Guide? Check out the application here.
[Become a Guide](https://rubycentral.teamtailor.com/jobs/7248113-guide-application?ref=rubycentral.org)
---
## Why This Program Matters
The Ruby community is not immune to the pressures facing the broader tech industry. Layoffs, hiring slowdowns for early-career developers, and ongoing questions about the language's future are real conversations happening in real communities. The Scholars & Guides Program does not pretend otherwise.
What it does is offer something concrete in response: a structured, human, community-driven investment in the people who will carry Ruby forward. Every Scholar who finds their footing, every Guide who rediscovers their own love for the language through a fresh set of eyes, every connection made in a hotel lobby or conference hallway is a small but real act of building the future this community wants to have.
As Andy Andrea put it, the program was one of the biggest factors in his own decision to stick with Ruby when he was looking for a new job. That is the kind of return on investment no balance sheet can fully capture.
---
## How to Get Involved
Applications are open and will remain open throughout the year for future conferences. Whether you are an aspiring Rubyist looking for mentorship and community, or an experienced developer ready to give back, there is a place for you in this program.
Learn more and apply: [Scholars & Guides Program](https://rubycentral.org/scholars%5Fguides%5Fprogram/)
---
## Support the Program
Programs like Scholars & Guides do not sustain themselves. They exist because people in this community choose to invest in them, financially and otherwise. If the stories in this piece resonated with you, here are a few ways to put that feeling into action:
**Supporter Ticket:** The most direct way to fund programs like Scholars & Guides is by purchasing a Supporter ticket to our events. Your contribution goes directly toward supporting our Scholars scholarship support or also providing opportunities for students to attend these events.
**Additional Support:** Ruby Central also accepts [one-time donations](https://givebutter.com/RCGeneral%5FDonations?ref=rubycentral.org), [monthly membership opportunities](https://rubycentral.org/community/#membership), and offers opportunities through our [Sponsorship program](https://rubycentral.org/sponsors/#sponsorship-paths) for organizations that want to make a larger impact on the community.
Matz built Ruby to serve the people who use it, putting human productivity and experience at the center of every design decision. The Scholars & Guides Program is that same philosophy applied to community: an investment in people first, with the belief that everything else follows from there. Supporting it is one of the most Ruby things you can do.
### Meet RubyConf 2026 Scholar: KJ Loving
URL: https://rubycentral.org/news/meet-rubyconf-2026-scholar-kj-loving/
Last updated: 2026-08-13T17:23:28.000Z
*Thinking of applying to next year's RubyConf Scholars and Guides program? Read on to hear from this year's Scholars about what it was like and why you should take the leap and apply!*

### Name:
KJ Loving
### Professional Title:
Junior Developer
### How did you get into Ruby? What's your Ruby story?
I got into Ruby through Code the Dream and learned on The Odin Project curriculum. I had zero background in programming but I wanted to try the backend program because it seemed a bit intimidating to me. I quickly found a loving, kind and supportive community. I couldn't have picked a better place to land.
### Are there any Ruby projects you're working on that you're excited about? Tell us all about it!
Too many to list, haha!
### Why did you decide to apply and join the Scholars & Guides program?
I had a bad experience at my first conference and I wanted guidance and support on my second one. I really wanted to get immersed in the community and I had heard good things about the program from previous scholars.
### What was the impact or highlight from the Scholars & Guides program experience, and how has it affected your Ruby journey or career after you completed the program?
I met so many amazing people that I will be connected with for the rest of my life, and I gained a stronger local community since I met so many people from my area.
### What surprised you, if anything, about your experience in the Scholars & Guides program or with attending the conference?
It felt so much like a team and supportive environment from the jump, and as the conference went on it felt more like a family. Full of people that just wanted the absolute best for you. Everyone was so nice.
### How did you feel attending your first RubyConf or RailsConf?
Nerve-wracking and exhilarating. I left feeling so much more connected to this community.
### Any advice for first-time guides or first-time scholars?
Take advantage of the opportunity. Everyone is excited for you to be there, so use that to make connections and conversation.
### Any advice for first-time conference attendees?
Take advantage of every conversation. Savor the moment and go with the flow. The best things that happened were the unplanned ones.
### *Thank you KJ for sharing your story! Feeling ready to apply to be a RubyConf Scholar or Guide? Sign up* [*here*](https://rubycentral.org/scholars%5Fguides%5Fprogram/) *today!*
### Ruby Runway Spotlight: Adam Dalton, Andy Davis, and Larissa Dalton of Stowzilla
URL: https://rubycentral.org/news/ruby-runway-spotlight-stowzilla/
Last updated: 2026-08-11T17:00:38.000Z
This is part of an ongoing series of Ruby Runway Spotlights, celebrating the founders who took part in the inaugural Ruby Runway Showcase at RubyConf 2026\. Each spotlight is a chance to hear directly from the builders turning Ruby into real, live businesses, and to cheer them on as they keep going.
---

**Tell us your name, your startup, and what it does in one or two sentences.**
Stowzilla is your personal warehouse service. Know what you have, and get value from the things you no longer need.
**What problem are you solving, and who feels it most? How does your Ruby-powered solution change things for them?**
We're solving the problem of getting valuable stuff to people who can use it, and giving space back to the people who don't need it anymore. People can face decision paralysis when they have too much stuff. They know it has value, but they don't know what to do with it.
We remove it from their physical space and give them a searchable digital inventory. Decisions become clicks. We handle the storage, inventory, and selling, and return anything they want back.
We used Ruby to build Brainiac, our agent orchestration platform, which keeps multiple projects in context so we can develop effectively in a service-oriented environment. We've also built several tools that make Ruby work better on AWS.
Conveyor Belt is a Terraform provider that uses familiar conventions to quickly build reliable, secure web services. Belt is a serverless application development framework. S3arch is a low-cost alternative to full-text search services like OpenSearch.
**Ruby has a reputation for developer happiness and elegant code. How has building with Ruby shaped the way you think about your product?**
We believe Ruby's focus on making programmers happy is one of the main reasons AI agents are so effective with it. The community has contributed decades of thought, conventions, and infrastructure, so the agents are standing on the shoulders of giants.
Convention over configuration. YAGNI. DRY. These ideas are deeply embedded in the training data agents learn their Ruby knowledge from. They're basically part of their artificial DNA.
**What would you say to another Ruby developer sitting on a startup idea right now, wondering if they should go for it?**
There's never been a better time to build. The time from recognizing a problem to developing a workable solution has never been shorter. It's not easy, but the tools exist to get the job done, and the Ruby community will support you the whole way.
**What's your origin story? Tell us who you are, what your startup does, and the moment you knew Ruby was the right foundation to build it on.**
Adam Dalton and Andy Davis met in 2009 at NASA's Kennedy Space Center while building ground-support software for launch services using Ruby. Adam left in 2012 to work in AI and cloud computing, while Andy stayed to see the project through as it eventually became Artemis, the first crewed lunar mission in more than 50 years.
They always wanted to work together again. In 2021, Adam and Larissa Dalton faced an unexpected and stressful move and couldn't believe there weren't better ways to deal with all their stuff. The seed for Stowzilla was planted: there had to be a better way.
The stars aligned in 2026, and Andy and Adam started programming together again, in Ruby, of course. Larissa finds efficient storage space, while Stowzilla helps valuable items find new homes where they can be useful.
---
**Find Stowzilla:**
Website: [stowzilla.com](http://www.stowzilla.com/?ref=rubycentral.org) GitHub: [stowzilla](https://github.com/stowzilla?ref=rubycentral.org) X: [@stowzilla](https://x.com/stowzilla?ref=rubycentral.org) TikTok: [@stowzilla](https://tiktok.com/@stowzilla?ref=rubycentral.org)
*Stowzilla was one of the founding companies featured in the Ruby Runway Showcase at RubyConf 2026\. Stay tuned for more spotlights from this inaugural cohort of Ruby-built startups.*
### Welcome Rubyroid Labs!
URL: https://rubycentral.org/news/welcome-rubyroid-labs/
Last updated: 2026-08-05T17:00:56.000Z
We're excited to welcome **Rubyroid Labs** as a **Ruby Alliance Supporter**, joining a growing group of organizations investing in the long-term health of Ruby and its open source ecosystem.
Every day, millions of developers rely on [RubyGems.org](https://rubygems.org/?ref=rubycentral.org) without thinking twice about it. That's exactly how great infrastructure should work—reliable, secure, and always there when you need it.
Keeping it that way takes a community.
Since 2013, [Rubyroid Labs](https://rubyroidlabs.com/services/ror%5Fdevelopment?utm%5Fsource=rubycentral&utm%5Fmedium=website&utm%5Fcampaign=partnership) has helped startups and enterprises build and scale Ruby on Rails applications while actively giving back to the Ruby community through conferences, education, and technical content. Now they're expanding that commitment by contributing engineering resources to help maintain and improve RubyGems.org.
Support like this is essential. RubyGems.org powers billions of gem downloads every year, and its long-term success depends on organizations that invest their time and expertise in the infrastructure the entire Ruby ecosystem relies on.
**About the Ruby Alliance**
The Ruby Alliance brings organizations together to support the open-source infrastructure behind Ruby, including RubyGems.org and Bundler. Through funding and engineering contributions, members help ensure Ruby remains a thriving platform for developers around the world.
Interested in becoming a Ruby Alliance Supporter? We'd love to start the conversation.
### Ruby Runway Spotlight: Joe Masilotti of Ruby Native
URL: https://rubycentral.org/news/ruby-runway-spotlight-ruby-native/
Last updated: 2026-08-04T17:00:48.000Z
*This is part of an ongoing series of Ruby Runway Spotlights, celebrating the founders who took part in the inaugural Ruby Runway Showcase at RubyConf 2026\. Each spotlight is a chance to hear directly from the builders turning Ruby into real, live businesses, and to cheer them on as they keep going.*
---

**Tell us your name, your startup, and what it does in one or two sentences.**
I'm Joe Masilotti, and I help Rails developers deploy to the mobile app stores. Ruby Native builds real iOS and Android apps from the HTML and ERB you already have, without writing Swift or Kotlin.
**What problem are you solving, and who feels it most? How does your Ruby-powered solution change things for them?**
Your customers want an app. The usual way to give them one is a separate native build in Swift and Kotlin, often a mobile developer or two, and another codebase to keep in sync with your Rails app. Ruby Native skips all of that. You write the same HTML and ERB you always have, and it renders as real native components: tab bars, navigation, forms, dropdowns, you name it. One command ships to the App Store and Google Play, still powered by the Ruby you write all day. It helps solo founders and small teams the most, the folks who can't justify a mobile hire but are quietly losing users who expect an app in the stores.
**Ruby has a reputation for developer happiness and elegant code. How has building with Ruby shaped the way you think about your product?**
Ruby taught me to optimize for developer experience above almost everything else. Matz designed the language to make programmers happy, and you feel it in the sensible defaults, the escape hatches, and ceremony that isn't there. Ruby Native is built the same way: the common path is a single command and a few view helpers, not a ton of config files. You scan a QR code and your app is running on your phone. It follows the expectation Ruby sets that one person can ship something real, backed by a community generous enough that good ideas spread fast.
**What would you say to another Ruby developer sitting on a startup idea right now, wondering if they should go for it?**
Ship the smallest version that solves one real problem, talk to the people using it, and charge real money as soon as you can. Nothing proves you have traction like a customer reaching for their credit card. I've done this many times, and charging early is how I've killed weak ideas fast. When nobody wants to pay, you learn the idea wasn't as good as you hoped, and you can move on in a week, instead of wasting years building the wrong thing.
**What's your origin story? Tell us who you are, what your startup does, and the moment you knew Ruby was the right foundation to build it on.**
Over the past decade building native apps for iOS and Android, I wrote a book on Hotwire Native and shipped more than 25 mobile apps on top of Rails. Along the way I kept doing the same native plumbing for every client: the same Xcode and Android Studio projects, the same web view wrapper, the same deploy dance. Ruby Native came out of automating all of it. My goal is to get Rails developers into the App Store and Google Play while they keep doing what they love, writing Ruby and building web-powered businesses. Rails is where these apps already live, so instead of wrangling Xcode and Android Studio yourself, you get a gem, a CLI, and a cloud build pipeline that fit the way you already work.
---
**Find Ruby Native:**
Website: [rubynative.com](http://rubynative.com/?ref=rubycentral.org) GitHub: [ruby-native](http://github.com/ruby-native?ref=rubycentral.org) X: [@joemasilotti](http://x.com/joemasilotti?ref=rubycentral.org)
*Ruby Native was one of the founding companies featured in the Ruby Runway Showcase at RubyConf 2026\. Stay tuned for more spotlights from this inaugural cohort of Ruby-built startups.*
### Ruby Runway Spotlight: Michael Carroll of Coolhand Labs
URL: https://rubycentral.org/news/ruby-runway-spotlight-coolhand-labs/
Last updated: 2026-07-30T17:00:10.000Z
*This is part of an ongoing series of Ruby Runway Spotlights, celebrating the founders who took part in the inaugural Ruby Runway Showcase at RubyConf 2026\. Each spotlight is a chance to hear directly from the builders turning Ruby into real, live businesses, and to cheer them on as they keep going.*
---

**Tell us your name, your startup, and what it does in one or two sentences.**
I'm Michael Carroll, founder of Coolhand Labs. Coolhand Labs is a COO for your AI agents. Whether they run on your computer or in prod, we use log traces and human feedback to keep an eye on them and optimize for efficiency and quality, often cutting costs over 50% in the process.
**What problem are you solving, and who feels it most? How does your Ruby-powered solution change things for them?**
After RubiconMD was acquired in 2021, I decided to take a beat and build something for myself. I drew on my youthful passion for Dungeons & Dragons to create an AI-driven multiplayer storytelling game called innori. A huge chunk of my time building innori was spent adjusting the AI based on human feedback, and I thought "I'll just build a simple AI service to take this work off my plate."
Unsurprising twist: it wasn't simple. I also found out that a lot of great engineers I've worked with in the past were struggling with the same problem. They were using AI observability options like LangSmith and Langfuse, but finding that the observability paradigm wasn't getting them far.
The problem with dashboards, besides the fact that nobody ever looks at them, is that you need a deep knowledge of the system they are observing to obtain meaningful results. AI tools are changing so fast that almost nobody can do that!
So I started spending more and more time on Coolhand and opened it up to others, and realized that "an AI service to help engineers constantly improve AI services" was something I really wanted to spend my time on. I asked a few early users to pay to use it, and they pretty quickly agreed, so Coolhand Labs was profitable almost from the moment we launched.
One thing I didn't expect early on was the interest in our Ruby gem. The AI observability solutions have basically abandoned direct support for all platforms that aren't Python or NodeJS-based. I had built a Coolhand Ruby gem ([please give it a GitHub star!](https://github.com/Coolhand-Labs?ref=rubycentral.org)) to collect LLM traces for my own internal use, and people kept reaching out to me about it. They wanted to use it to collect traces for their own tools. Some even became early Coolhand Labs customers.
Building for the Ruby community always compounds in value, and I'm happy to keep that mission at the core of the company! To my knowledge we are still the only AI dev tools company that maintains a Ruby gem.
**Ruby has a reputation for developer happiness and elegant code. How has building with Ruby shaped the way you think about your product?**
One thing people seem to have forgotten is that Ruby (and Rails) were the original "vibe coding" platforms, and that is a big part of what makes building with it so much fun: Ruby has its own comic strips, core maintainers who wear wigs, and superstar personalities who drive race cars.
At Ruby meetups ten years ago, you'd meet a person who knew nothing about coding, give them advice on turning the Twitter clone they'd forked from a tutorial into their "uber for leftovers" app idea (true pitch I heard), and then next time you saw them it was years later at a meetup where they were giving deep technical perspectives on a gem they'd built. People would start with a Rails app from a generator and get sucked into engineering. I truly believe many "vibe coders" building apps today will end up doing the same, and hope the Ruby community will continue to embrace all such newcomers.
That Ruby philosophy of ease-of-use and inclusion really influences how we build at Coolhand Labs. Sure, Coolhand is an agent that "does the AI dredge work for you," but it also is an agent that has an evolving opinion on how to build AI agents in a way that's clean, fun to follow, and aims to include you in the journey: "structured outputs are better here because of X" or "try giving your agents this no-op tool, and you can trick them into telling you when they are failing." This all draws inspiration from the Ruby ecosystem.
**What would you say to another Ruby developer sitting on a startup idea right now, wondering if they should go for it?**
One thing I love about Ruby is that the goal is to enjoy the journey (building the thing) as much as the destination. I'd apply the same paradigm to starting a startup. If you know you would enjoy the full experience (searching for your first users, experimenting with monetization pathways, questioning everything you are doing every single day) then definitely do it. That way, even if you wind up as a garbage collector again at the end, you will be satisfied that you had a great run of it.
**What's your origin story? Tell us who you are, what your startup does, and the moment you knew Ruby was the right foundation to build it on.**
Elephant in the room: I'm not the Michael Carroll who won 9 million pounds in the UK lottery and spent it all on banger racing and bling, before returning to being a garbage collector. Kind of hard to top that guy: gotta give him credit for pursuing what he loves.
No: I'm the Michael Carroll who studied Medieval Chinese Buddhist Philosophy at the University of Hong Kong, realized there was no job market for it (common mistake), and pivoted into engineering and startups. If you think coding and B2B sales are difficult, try inferring the double-entendres and verbal puns in an extinct Chinese dialect.
My origin myth is that I learned C++ in high school, found it tedious, and then only much later found out that "tedious" was just a language feature of C++. Discovering Ruby gave me back that excitement I got from my very first "Hello World," but the difference was that I got that joy every time I wrote with Ruby. When I built RubiconMD, a health tech startup that connected doctors to improve patient care, I knew that I wanted to hire people who found the same passion for writing code in Ruby as I did. We ended up putting together a really amazing, international team all joined with that shared love of Ruby.
So Ruby has always been my default choice. I've programmed in a lot of other languages, JavaScript (and CoffeeScript, remember CoffeeScript?!), Python, Elixir, Java, ObjectiveC, but none of them gave me the same anticipation to open the IDE that Ruby does.
---
**Find Coolhand Labs:**
Website: [coolhandlabs.com](https://coolhandlabs.com/?ref=rubycentral.org) GitHub: [Coolhand-Labs](https://github.com/Coolhand-Labs?ref=rubycentral.org) X: [@coolhand\_labs](https://x.com/coolhand%5Flabs?ref=rubycentral.org) LinkedIn: [Coolhand Labs](http://linkedin.com/company/coolhand-labs?ref=rubycentral.org)
*Coolhand Labs was one of the founding companies featured in the Ruby Runway Showcase at RubyConf 2026\. Stay tuned for more spotlights from this inaugural cohort of Ruby-built startups.*
### Scholars & Guides Spotlight: Madeline Caples on Learning to Code Alongside AI
URL: https://rubycentral.org/news/scholars-guides-spotlight-madeline-caples/
Last updated: 2026-07-27T17:00:58.000Z
Every year, Ruby Central's Scholars & Guides Program pairs aspiring Rubyists with experienced mentors for a week of learning, connection, and growth at RubyConf. Scholars get a Guide to help them navigate the conference, build their coding skills, and meet other Rubyists face to face. Alongside that mentorship, Scholars are also invited to take on a mini-project, an open opportunity (not a requirement of the program) to share their own unicorn, whatever makes them uniquely them, with a community that's wonderfully diverse in thought, interests, skills, and talents. This year's theme was "Ruby for funsies: using Ruby and Rails to enhance a hobby," and Scholars could present however felt right to them, whether that meant a blog post, a webpage, a video, or a Lightning Talk on stage.
We want to spotlight one Scholar's project in particular, because we think it says something important about where our community is headed.
## Meet Madeline Caples
Madeline Caples is a frontend developer who came to RubyConf 2026 as a Scholar and left with a new project, a Notes app built in Ruby on Rails, and a lot to say about how they got there. For their mini-project, they wrote a thoughtful blog post called ["Learning at Ruby Conf: A Workflow For AI Assisted Study,"](https://madelinecaples.hashnode.dev/learning-at-ruby-conf-a-workflow-for-ai-assisted-study?ref=rubycentral.org) which tackles a question a lot of developers are quietly wrestling with right now: how do we keep learning and growing as programmers when AI can write working code from a single prompt?
Madeline has written about this tension before. Earlier this year, they published a piece explaining why they were hesitant to lean on AI while learning, worried it would shortcut the hard-earned understanding that makes someone a confident developer. RubyConf gave them a reason to revisit that stance, not to abandon it, but to refine it.
## A workflow built for real understanding
Working on their Notes app during the conference, Madeline developed a five-step study flow they now use whenever they sit down to learn something new with AI tools like Claude and Cursor by their side:
- **Define** a clear goal and a realistic time frame before starting
- **Attempt** the problem on their own first, taking notes and connecting new ideas to what they already know
- **Correct** their work with AI feedback, but pause to understand *why* something was wrong
- **Refine** their understanding by exploring edge cases
- **Iterate**, repeating the cycle for each new goal
The result is a simple, structured way to use AI as a study partner rather than a shortcut, one that keeps the learner doing the actual learning. It's a generous, honest piece of writing, and it's worth reading in full.
You can find Madeline's full write-up on their blog, [
ersions
](https://madelinecaples.hashnode.dev/learning-at-ruby-conf-a-workflow-for-ai-assisted-study?ref=rubycentral.org), where they regularly write about machine learning and software engineering topics in plain, accessible language.
## Why this program matters
Madeline's project is exactly what the Scholars & Guides Program is meant to make possible: a space for someone to bring a real question they're wrestling with, spend a week surrounded by a community that takes that question seriously, and walk away with something worth sharing. That's true whether a Scholar's mini-project takes the form of a blog post, a Lightning Talk, or something else entirely. There's no requirement to get on stage. The point is simply to share who you are and what you're working through with a community that wants to hear it.
If you're curious about applying as a Scholar, or becoming a Guide yourself, keep an eye on Ruby Central's announcements for the next cycle. And in the meantime, go give Madeline's post a read. It might just change how you think about your next study session too.
[Learn More: Scholars & Guides](https://rubycentral.org/scholars%5Fguides%5Fprogram/)
### Ruby Runway Spotlight: Paresh Sharma of Viveture
URL: https://rubycentral.org/news/ruby-runway-spotlight-viveture/
Last updated: 2026-07-21T17:00:00.000Z
*This is the first in a series of Ruby Runway Spotlights, celebrating the founders who took part in the inaugural Ruby Runway Showcase at RubyConf 2026\. Each spotlight is a chance to hear directly from the builders turning Ruby into real, live businesses, and to cheer them on as they keep going.*
---

**Tell us your name, your startup, and what it does in one or two sentences.**
I am Paresh Sharma, founder of Viveture. Viveture connects pet owners with local sitters for pet care services.
**What problem are you solving, and who feels it most? How does your Ruby-powered solution change things for them?**
Both sides feel the pain, just differently.
Pet owners search for a sitter and get results sorted by who charges the most, because the platform takes a percentage of every booking. A more expensive sitter means a bigger cut for the platform. The incentive has nothing to do with who is actually the best fit for your pet.
Sitters feel it on every single booking. They lose 20 to 40% of their earnings to the platform on every transaction, no exceptions. They can lower their prices to stay competitive, but that just means earning less while the platform still takes its cut. There is no way to win inside that model.
Viveture has no skin in that game. We do not take a cut from any booking, so we have no reason to surface expensive sitters over good ones. Sitters keep everything they earn. Rankings reflect what actually matters: quality and fit. Both sides finally have a platform that is working for them, not against them.
**Ruby has a reputation for developer happiness and elegant code. How has building with Ruby shaped the way you think about your product?**
Rails pushed me toward opinions, and that turned out to be a product advantage. Convention over configuration is not just a development principle, it shapes how you approach product decisions too. You stop over-engineering and start shipping things that work. I found myself making cleaner calls because Rails made the technical path obvious, which freed up mental space for the harder questions: what does the sitter actually need on this screen? What creates trust between a pet owner and someone they have never met?
There is also something about the Ruby community that attracts builders who care about craft. That ethos shaped how I approached the product. I wanted every interaction to feel considered, not just functional.
**What would you say to another Ruby developer sitting on a startup idea right now, wondering if they should go for it?**
Just ship that idea you have been sitting on. What you are embarrassed to show people is still better than the idea that never launched. I built Viveture as a solo founder with no co-founder and no outside funding, and it is live on the App Store today. Not because I had some unfair advantage, but because Rails made it possible for one person to build something real.
The Ruby community will help. RubyConf, local meetups, open source maintainers who actually respond to issues. That does not exist everywhere. If you have an idea and you know Rails, you are already more equipped than you think.
**What's your origin story? Tell us who you are, what your startup does, and the moment you knew Ruby was the right foundation to build it on.**
I started Viveture because I was genuinely fed up using existing pet care apps. When I searched for a sitter, the results were sorted by who charged the most, not who was the best fit for my dog. The whole experience felt broken, and I wanted to build something that actually put the right sitter in front of the right pet owner.
I chose Rails because I was building alone and needed to move fast. Booking flows, real-time messaging, background check integrations, Stripe billing, push notifications, all as a single developer. Rails let me ship a production-ready marketplace in under a year. The ecosystem just works: Stripe has a gem, SendGrid has a gem, Sidekiq is battle-tested, Heroku deploys are trivial. Ruby got out of my way and let me focus on the product.
---
**Find Viveture:**
Website: [viveture.com](https://viveture.com/?ref=rubycentral.org) Instagram: [@viveture](https://www.instagram.com/viveture/?ref=rubycentral.org) TikTok: [@viveture](https://www.tiktok.com/@viveture?ref=rubycentral.org)
*Viveture was one of the founding companies featured in the Ruby Runway Showcase at RubyConf 2026\. Stay tuned for more spotlights from this inaugural cohort of Ruby-built startups.*
### Announcing the RubyGems.org Supporters Program in Japan
URL: https://rubycentral.org/news/announcing-the-rubygems-org-supporters-program-in-japan/
Last updated: 2026-09-08T15:31:52.000Z
We're excited to share some big news from our partners at the Ruby Association: the launch of the RubyGems.org Supporters Program in Japan.
Starting this October, the Ruby Association will serve as a local liaison for Japanese companies who wish to support RubyGems.org. This means their domestic sponsors can now contribute in Japanese Yen through a familiar organization, removing a real barrier that has kept many companies in Japan from supporting the infrastructure their teams rely on every day.
## **What This Means**
RubyGems.org is critical infrastructure for the global Ruby community, and its long term sustainability depends on broad, diverse support. This partnership opens the door for Japanese companies, many of whom have used Ruby and Rails for years, to formally invest in the ecosystem that powers their work.
The program offers two tiers, **RubyGems.org Supporters** and **RubyGems.org Supporters Plus**, with fees payable in JPY. The inaugural period runs from October 2026 through March 2027, aligned with the Ruby Association's fiscal year, and includes an adjusted rate for that first partial cycle.
Funds raised through the program, minus a small administrative fee retained by the Ruby Association, will come directly to Ruby Central and go toward RubyGems.org's operations, infrastructure, and security. We're committed to sharing regular, transparent updates on how these funds are used.
## **Our Thanks**
This program is the result of months of collaboration between our two organizations, and we're grateful to everyone at the Ruby Association who made this a reality. It reflects something we believe deeply: that RubyGems.org belongs to the whole global Ruby community, and its future should be supported by that whole community too.
If you're a company in Japan interested in joining, full details on benefits and how to apply will be available on the Ruby Association's website ahead of the October launch. You can read their full announcement[ here](https://www.ruby.or.jp/en/news/20260715?ref=rubycentral.org).
## **About the Ruby Association**
The Ruby Association is a Japanese nonprofit that supports the growth and development of the Ruby language and its community. Based in Matsue, Japan, the birthplace of Ruby, the organization works closely with Ruby's creator, Yukihiro "Matz" Matsumoto, and runs programs spanning certification, grants, and community outreach both in Japan and internationally.
Thank you for supporting Ruby, wherever in the world you're building with it.
### Recharge at RubyConf with Fullscript
URL: https://rubycentral.org/news/recharge-at-rubyconf-with-fullscript/
Last updated: 2026-07-07T16:00:43.000Z
[Fullscript ](https://fullscript.com/?ref=rubycentral.org)is sponsoring the Relax Lounge at [RubyConf](https://rubyconf.org/?ref=rubycentral.org) this year; it’s the conference experience that felt like the right fit.
The Ruby community has given us a lot; not just the tools we build on, but the people and community who've shaped how we work. Our folks attended Ruby conferences in five countries last year, and we continue to support meetups across North America. We keep showing up because we've seen what happens when devs actually get in the same room. Things click differently in person. There's something about face-to-face that you can't replicate over Slack.
So when RubyConf came around we asked ourselves what we could contribute that felt like *us*. We're a healthcare company: rest isn't optional, it's an integral part of wellness.
And conference days are a lot. Talks, networking, travel, trying to absorb everything at once. It's easy to just push through, exhausted and dead on your feet. So we're sponsoring a space to **not** do that: massage chairs, snacks, supplements, somewhere to actually sit down for a few minutes.
No pitch, no agenda, just a break.
If you’re at RubyConf, stop by and make yourself at home. That’s kind of the whole point!
### An Anonymous Donation to Help More Rubyists Get to RubyConf 2026
URL: https://rubycentral.org/news/rubyists-get-to-rubyconf-2026/
Last updated: 2026-07-03T00:30:46.000Z
One of the things that makes our community special is the way people keep showing up for each other.
Recently, a member of our community found themselves unable to attend RubyConf 2026 and generously offered to donate their ticket so that someone else could have the opportunity to join us in Las Vegas.
That act of generosity sparked a bigger idea among another community member.
We know there are Rubyists who would love to attend RubyConf this year but are facing budget constraints. Whether it's competing conference budgets, travel costs, or simply a challenging year financially, we don't want cost to be the only thing standing between someone and the people, ideas, and opportunities waiting for them at RubyConf.
Thanks to the generosity of an anonymous community member, we have a limited number of complimentary RubyConf 2026 tickets available for Rubyists who otherwise would not be able to attend.
If attending RubyConf would be meaningful for you, but the ticket price has been the primary obstacle, this donation may help get you there.
## **How It Works**
Please fill out the short form below and tell us a little about yourself and why you'd like to attend RubyConf 2026.
Three recipients will receive a complimentary conference ticket. Recipients will be responsible for their own travel and lodging expenses.
Applications will remain open until **July 6, 2026**, after which recipients will be notified directly.
[Apply Here](https://forms.gle/Vr49LDnWVhnaadAQ6?ref=rubycentral.org)
## **Why We're Doing This**
RubyConf has always been more than a conference. For me, it’s how I fell in love with this community. These conferences and our community are unlike any other I’ve attended in my career across industries.
It's where new contributors find mentors. It's where longtime friends reconnect. It's where career-changing conversations happen in hallways, over meals, between sessions, and at the hotel bar. It's where our community gathers to learn, collaborate, and shape the future of Ruby together.
If a complimentary ticket can help even a few more Rubyists be part of that experience, we think that's worth doing.
And if you don’t win one of the donated tickets, we still encourage you to apply. Understanding who wants to attend, and what barriers might be standing in the way, will help us continue finding new ways to make RubyConf accessible to more members of our community.
We're incredibly grateful to the generous community member who made this grant possible, and we're looking forward to welcoming as many Rubyists as we can to Las Vegas.
See you at RubyConf.
*\~Ran Craycraft & Ruby Central Staff*
### Announcing the RubyConf VIP Raffle
URL: https://rubycentral.org/news/announcing-the-rubyconf-vip-raffle/
Last updated: 2026-06-24T16:30:48.000Z
At RubyConf 2026, anyone who [buys a ticket](https://rubyconf.org/?ref=rubycentral.org) before **July 1st** is entered into a raffle for an exclusive RubyConf VIP experience. What exactly is a RubyConf VIP experience?
Five lucky winners, drawn at random, will:
- Get a ticket for you and a plus-one to the world-famous RubyConf speakers' Dinner, where you'll meet your real-world Ruby Heroes. Get exclusive behind-the-scenes access to the people who make Ruby and make RubyConf while you eat like royalty.
- VIP reserved seating for all keynote talks so you won't miss a thing. No fighting for a free seat or squeezing in the middle of a row of strangers. Walk right up and take a load off.
- A personal "thank you" from the board and staff. Because we really couldn't do this without you, all the attendees who make this conference possible.
But that's not all, everyone who enters by buying a ticket by July 1st will receive a **limited edition RubyConf 2026 pin**! If you were on the fence before, don't let this chance of a lifetime pass you by. When the clock strikes midnight on July 1st (PST), this door will officially be closed. Anyone who buys a ticket after that will still get a great conference at the [Red Rock Resort](https://rubyconf.org/location/?ref=rubycentral.org), but you won't get a limited edition pin and won't be entered in the raffle for the VIP experience. Don't miss out, [buy today](https://rubyconf.org/?ref=rubycentral.org).
## FAQ
- **Q: If I win, can I get Matz's autograph?**
- **A**: Matz, along with [\~50 amazing Rubyists](https://rubyconf.org/schedule/?ref=rubycentral.org), including Dave Thomas, Jessica Kerr, and Obie Fernandez, have all been invited to the speaker dinner. You can use that time to ask for selfies, promote your [pet idea for the Ruby language](https://bugs.ruby-lang.org/?ref=rubycentral.org), or just get to know the people behind the code we all love and depend on.
- **Q: I already bought a ticket, but I really want to go to that dinner. Am I out of luck?**
- **A**: Not at all, everyone who has purchased before July 1st, 2026, is automatically entered. Plus, you can collect your limited edition RubyConf 2026 pin when you check into the conference.
- **Q: What if I can't make the dinner? Can I transfer my ticket to someone else?**
- **A**: If you cannot attend the dinner, your dinner ticket (and plus-one) is transferable to another registered RubyConf attendee. However, your VIP dinner ticket carries no cash value and cannot be refunded.
- **Q: When will winners be notified?**
- **A**: We will draw raffle winners shortly after Midnight on July 1st. Winners will be notified by email at the email address they used to register for the conference.
- **Q: I missed the deadline for the hotel conference rate, but I want a chance to be a VIP, can you help me out?**
- **A**: Potential VIPs deserve the best, which includes the best rooms at the best prices. We've worked with the venue to extend conference room pricing to **July 1st**. Don't wait, [book your room today](https://rubyconf.org/location/?ref=rubycentral.org).
### SmartFinancial Is Coming to RubyConf 2026 and They're Hiring!
URL: https://rubycentral.org/news/smartfinancial-is-coming-to-rubyconf-2026-and-theyre-hiring/
Last updated: 2026-07-09T22:38:44.000Z
If you're heading to RubyConf this July, make sure to stop by and meet the team from SmartFinancial.
[SmartFinancial](https://smartfinancial.com/?ref=rubycentral.org) is a technology-driven insurance marketplace that helps people find and compare insurance options across all 50 states. Their goal is simple: make buying insurance easier, more transparent, and less frustrating for consumers.
Ruby plays a major role in making that happen.
The SmartFinancial engineering team has been building and operating Ruby on Rails applications for years, and they're excited to be part of the RubyConf community in Las Vegas this July 14–16 at Red Rock Casino Resort. Like many of us, they're coming to learn, share ideas, meet fellow Rubyists, and stay connected to the ecosystem that powers so much of their work.
They're also growing their team.
If you're an experienced Ruby engineer looking for your next opportunity, SmartFinancial would love to meet you. They value Ruby, invest in Rails, and are building products that have a real impact on the people who use them every day.
Whether you're actively looking for a new role or just curious about what they're working on, stop by their booth, say hello, and start a conversation. You might discover your next opportunity along the way.
### RubyConf 2026 Is Where Ruby's Next Chapter Begins
URL: https://rubycentral.org/news/rubyconf-2026-is-where-rubys-next-chapter-begins/
Last updated: 2026-07-10T14:28:40.000Z
We’ve talked a lot lately about governance, sustainability, accountability, and the future of Ruby Central. Those conversations were necessary, but they were largely conversations about the past.
This year’s RubyConf feels different.
This [RubyConf](https://rubyconf.org/?ref=rubycentral.org) is going to be a conversation about the future.

For the first time, we will be inducting the inaugural class of Ruby Fellows. Leaders from Ruby Alliance companies will gather to discuss how they will be collectively investing in Ruby's future. We'll officially launch Steering Committees that create new opportunities for community members to get directly involved. We'll host Ruby Runway and showcase founders building exciting new businesses on Ruby.
None of those things, by themselves, is revolutionary. Taken together, though, they represent that people are investing in Ruby again.
We'll also have one of the strongest programs we've seen in years. Matz will open the conference. Dave Thomas will close it. Between them are speakers and maintainers who have helped shape Ruby, Rails, open source, and software development for decades. The schedule is packed with the kind of deeply technical content RubyConf has always been known for, from Ruby internals and performance to AI, security, concurrency, accessibility, and the future of programming itself.
I also want to address something that may surprise people. While RubyConf is technically in Las Vegas, it isn't really a *Vegas* conference. We're at Red Rock Resort, a short car ride from the action, but surrounded by mountains just outside of the city. Everything is in one place, the talks, the meals, the hallway conversations, game night, evening events, and the people you came to spend time with. Our goal is for this to feel more like a retreat than a convention.
And that's important because the best parts of RubyConf probably won’t happen on stage. They’ll happen over breakfast, after a talk, during game night, or while sitting outside talking with someone who shares your passion for building great software.
A lot of people have asked how they can help Ruby Central and the Ruby community. There are many answers to that question. You can contribute to open source. You can mentor new developers. You can volunteer. You can support ecosystem projects.
But right now, one of the most meaningful things you can do **is show up**.
Because five years from now, I suspect many of us will look back and realize that RubyConf 2026 was a transformational event. These changes will help launch new companies. Welcome new contributors. Form new partnerships. Inspire new ideas. And kick off new initiatives.
If you've been waiting for the right year to attend RubyConf, I think this is it.
Join us in Las Vegas. Bring a coworker. [Book a room](https://book.passkey.com/e/51129655?ref=rubycentral.org) at the conference hotel.
Be part of the new beginning.
[Get Your Ticket Here](https://ti.to/rubyconf/rubyconf-2026?ref=rubycentral.org)
Ran, Jey, Brandon, Freedom, and David
*Ruby Central Board of Directors*
### Shopify Joins the Ruby Alliance
URL: https://rubycentral.org/news/shopify-joins-the-ruby-alliance/
Last updated: 2026-06-15T16:00:19.000Z
#
We’re excited to share that Shopify has joined the Ruby Alliance.
Shopify is a leader in the Ruby ecosystem, powering millions of businesses around the world and demonstrating what is possible when Ruby is trusted at global scale.
For years, Shopify has invested in Ruby through engineering leadership, open source contributions, performance improvements, and a deep commitment to the technologies that help power the community. Their work has benefited not only Shopify, but Ruby developers everywhere.
Their participation in the Ruby Alliance represents a meaningful investment in the long-term health, resilience, and sustainability of the Ruby ecosystem and the critical infrastructure it depends on.
As the Ruby Alliance continues to grow, Shopify’s experience building and operating one of the largest Ruby applications in the world will provide valuable perspective and leadership as Alliance members work together to strengthen the future of Ruby.
Ruby has always thrived because companies and individuals choose to invest back into the community that supports them. Shopify’s commitment reflects that tradition and helps ensure the ecosystem remains strong for the next generation of developers, maintainers, and organizations.
We’re incredibly grateful for Shopify’s partnership and excited about what we’ll build together.
If your company is interested in learning more about the Ruby Alliance, please contact [tom@rubycentral.org](mailto:tom@rubycentral.org).
### Strengthening Security for the Ruby Ecosystem: A Team of Security Engineers in Residence
URL: https://rubycentral.org/news/strengthening-security-for-the-ruby-ecosystem-2-2/
Last updated: 2026-06-10T23:32:08.000Z
**We’re excited to announce that** [**Ruby Central**](https://rubycentral.org/) **has been awarded a grant from** [**Alpha-Omega**](https://alpha-omega.dev/?ref=rubycentral.org) **to help improve the security of the Ruby open source ecosystem. With this support, Ruby Central is funding a team of Security Engineers in Residence to find real vulnerabilities in the gems the community depends on most, verify them, and bring maintainers reports worth their time.**
The same AI tooling that helps developers ship faster has made finding vulnerabilities cheap. An attacker can act on a raw signal the moment a tool surfaces it. A responsible reporter cannot. Someone has to confirm the vulnerability is real, work out what it means in practice, and decide it is worth a maintainer's time. That work falls on people, and people are the scarce part.
That scarcity is the whole reason this program exists, and it is what Alpha-Omega's support pays for. With their backing, Ruby Central, which runs [RubyGems.org](https://rubygems.org/?ref=rubycentral.org), is funding a security program for the Ruby open source ecosystem built around a single idea: every report that reaches a maintainer should be the work of a person who understood the gem first. AI helps us find candidates faster, but nothing reaches a maintainer until a person has confirmed the report is real, assessed what it means in practice, and decided it is worth that maintainer's time.
Ruby sits at the heart of much of the modern web. Keeping its core, RubyGems, Bundler, and the most widely depended-on gems secure is essential, and the pace of newly discovered, exploitable vulnerabilities risks outrunning the community's capacity to respond. Maintainers are already feeling one side of this: a rising tide of low-quality, AI-generated vulnerability reports that consume time and bury the issues that genuinely matter. This program is built to be the opposite of that. We are glad to be taking it on alongside peer ecosystems facing the same challenge, including the [Python Software Foundation](https://www.python.org/psf-landing/?ref=rubycentral.org), [Rust Foundation](https://rustfoundation.org/?ref=rubycentral.org), [PHP Foundation](https://thephp.foundation/?ref=rubycentral.org), and others. We expect to learn a great deal from one another.
In practice, that means we scan prioritized Ruby projects for vulnerabilities, verify what we find so maintainers do not receive noise, assess real-world severity using Ruby-specific deployment context rather than a generic score, and coordinate responsible disclosure directly with maintainers. Where it helps, we produce Ruby-specific security guidance maintainers can use on their own.
This is not an outside team scanning from a distance. The people doing the work are embedded in the ecosystem they are securing. Dushan Karovich-Wynne, Ruby Central's Security Engineer, leads the hands-on scanning, verification, and disclosure, with Colby Swandale on the technical work and Marty Haught, Ruby Central's Director of Open Source, steering the program. They are joined by security consultants Matt Mongeau and Patrick Linnane, the latter a Homebrew maintainer and senior security operations leader, by Maciej Mensfeld, a contributor whose research focuses on the Ruby supply chain, and by Mike Dalessio, our Rails Security team rep, who makes sure findings in Rails and the code beneath it reach Rails Core quickly. The team draws on[ @kou](https://github.com/kou?ref=rubycentral.org) for the Ruby Core perspective and[ Andrew Nesbitt](https://nesbitt.io/?ref=rubycentral.org) for years of work on the structure and security of package ecosystems. That range is the point. It is what lets us judge whether a finding is real, and what it means in practice, before it ever reaches a maintainer.
This is the beginning, and we are still proving the workflow. The first several engagements are deliberately small. Our first was a report of a ReDoS vulnerability in the CSS query tokenizer to the [Nokogiri](https://github.com/sparklemotion/nokogiri?ref=rubycentral.org) maintainers, which was quickly validated and [fixed](https://github.com/sparklemotion/nokogiri/commit/52feb613161c647a425777fdc4ebcfb771016aa5?ref=rubycentral.org). This gave us a real case to pressure-test how we scan, verify, and disclose before widening the work. The purpose of these early engagements is to validate how we triage and work with maintainers, and to turn what we learn into a repeatable playbook that future contributors can follow. We would rather earn trust with a process that works than promise broad coverage we cannot responsibly deliver yet.
None of this is about CVE counts, bounties, or building a name. The people doing the work depend on these libraries too. With Alpha-Omega's support, the program answers to the health of the ecosystem, not to a metric or a paying customer. That is what the funding buys: not a number that looks good in a report, but the scarce human judgment that turns a raw signal into a report a maintainer can act on.
You do not have to maintain a gem to be part of this. If you maintain a Ruby project, you can put it forward for review. If you research security and want to bring us a finding, we will work it through with you. And if you have feedback that would make this work better, we want to hear that too. We will launch the program page on [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) with all these details, a FAQ, and contact information in the next two weeks.
The libraries at the heart of Ruby are kept running by people, often just a few of them, and the rest of the ecosystem builds on that work every day. Looking after it is something we can do for each other, and doing it well means starting small, moving carefully, and earning trust one solid report at a time. That is the work we are starting now.
### Governance: Expanding Participation in Ruby Central
URL: https://rubycentral.org/news/governance-expanding-participation-in-ruby-central/
Last updated: 2026-07-10T13:55:20.000Z
As part of our recent [bylaw modernization](https://rubycentral.org/news/modernizing-ruby-centrals-bylaws-and-officer-updates/), the Ruby Central Board has been exploring new ways to increase participation across the Ruby ecosystem while maintaining the accountability required to effectively operate a nonprofit organization.
Our goal in 2026 is to create more opportunities for contributors, community members, sponsors, and ecosystem leaders to help shape Ruby Central's future while preserving the Board's responsibility for stewarding the organization. And to do this as quickly as possible.
Ruby Central governs its own suite of voluntary programs, infrastructure, education, and initiatives that support the Ruby ecosystem. It does not govern the Ruby language itself.
## **Guiding Principles**
As we've explored new models for participation, these principles have guided our thinking:
### **Board Accountability**
The Ruby Central Board is responsible for the governance and operation of the organization.
This includes fiduciary oversight, budgeting, legal compliance, staffing, strategic planning, and stewardship of Ruby Central's mission and resources.
### **Meaningful Participation**
We believe that the people and organizations who contribute to the Ruby ecosystem should have meaningful opportunities to provide input, share their expertise, and help inform the direction of Ruby Central.
### **Distributed Influence**
Ruby Central must never become overly dependent on any single company, funding source, contributor group, or broader constituency. A healthy ecosystem benefits from diverse perspectives and broad participation.
### **Focused Execution**
Participation is important, but so is execution. Any governance model we adopt should allow Ruby Central and its committees to move quickly, thoughtfully, make decisions efficiently, and remain focused on delivering results.
## **Three Perspectives**
Opening the doors on major decisions means holding space for three distinct community facets. As we set the future direction of Ruby Central, each facet is a lens through which program priorities and goals should be set and measured.
### **The Board**
The Board provides organizational oversight, fiduciary responsibility, and long-term stewardship of Ruby Central.
### **Sponsors**
Sponsors invest significant financial resources into the infrastructure, programs, and events that support the Ruby ecosystem and on which their businesses depend.
Their perspective helps ensure that Ruby Central remains sustainable and understands the real needs of organizations building with Ruby.
### **The Community**
Contributors, maintainers, conference attendees, educators, open source contributors, and supporting members represent the broader Ruby ecosystem.
The unique perspectives from our community will help ensure Ruby Central remains aligned with the needs of the community we serve.
For significant ecosystem decisions, Ruby Central will incorporate structured participation from the Board, sponsors, and the community. Sponsors and community members will each select a representative to gather input, communicate priorities, and help shape major decisions affecting the future of the ecosystem alongside the Board.
Our intent is to create more structured and transparent pathways for diverse participation while still ensuring we’re working within our legal structure and maintaining a model for sustainable governance.
## **Operational Steering Committees**
One of the most important additions to our updated bylaws is the formal recognition of operational steering committees.
While our governance model creates opportunities for sponsors, members, contributors, and other stakeholders to help inform Ruby Central's direction, steering committees help turn that participation into action.
These committees will be small, highly specialized working groups focused on areas where Ruby Central benefits from deep community expertise and active involvement. Unlike advisory committees, steering committees are expected to contribute directly to the execution of initiatives, development of recommendations, and delivery of programs within their area of responsibility.
Our initial steering committees are expected to include:
- Open Source and Infrastructure
- Ruby Alliance and Fundraising
- Community, Conferences, and Governance
- Apprenticeships and Education
- DREAM and the Future of Ruby
Community members will be able to apply for steering committee positions as openings become available. Because these groups are intended to be hands-on and execution-oriented, membership will be limited based on the needs of the work, relevant experience, and demonstrated commitment.
We also recognize that many people want to contribute without the significant time commitment committee service requires. In addition to steering committees, there will be opportunities to support committee initiatives through volunteering, working groups, feedback sessions, and other forms of participation.
The Board remains responsible for organizational oversight, budgeting, and overall strategic direction, but steering committees help ensure that more of Ruby Central's work is informed and advanced by the people closest to it.
We'll share additional details about steering committees, participation opportunities, and application processes in an upcoming dedicated update.
## **Transparency**
We also believe meaningful participation requires transparency.
As we continue developing these programs, we're exploring ways to provide greater visibility into Board activities, committee work, organizational priorities, and major decisions while respecting any security and confidentiality requirements that come with operating a technical nonprofit organization.
We are prioritizing ways for the community to better understand what decisions are being made, as well as how they were made.
## **Looking Ahead**
This is an overview of the direction we're heading as we work to make Ruby Central more participatory, transparent, and sustainable. It may evolve, but in an effort to be transparent and make progress, this is the plan.
In the coming weeks, we'll share additional details about membership, steering committees, sponsorships, and other programs designed to strengthen Ruby Central and the broader Ruby ecosystem.
We'll also be discussing many of these ideas at [RubyConf](https://ti.to/rubyconf/rubyconf-2026?ref=rubycentral.org) and look forward to hearing feedback from the community to get this right.
We strongly believe that the future of Ruby Central should reflect the people and organizations who care most about Ruby's success, and we're excited to continue building that bright future together.
Ran, Jey, and David
*Ruby Central Board of Directors*
### A Heartfelt Thank You to GitLab: Our Longtime Coffee & Lanyard Sponsor
URL: https://rubycentral.org/news/a-heartfelt-thank-you-to-gitlab-our-longtime-coffee-lanyard-sponsor/
Last updated: 2026-07-10T13:56:29.000Z
There's a moment at every RubyConf that we quietly look forward to: the smell of fresh coffee drifting through the venue as attendees start their mornings, and the sight of a room full of name badges swaying from lanyards as people connect, collaborate, and find their people. For years, that moment has been made possible by GitLab.
GitLab has been a steadfast supporter of the Ruby community as both our coffee sponsor and name badge lanyard sponsor, and we don't take that for granted. Sponsorships like these are easy to overlook; they don't come with a keynote slot or a giant booth, but they are woven into the fabric of the conference experience in ways that matter deeply.
Every cup of coffee shared between a first-time attendee and a seasoned contributor. Every lanyard that helped someone find the courage to walk up to a stranger and say "I love your project." GitLab plays a part in that.
What makes GitLab's support especially meaningful is its sustained support for the community. GitLab builds tools that developers, including so many Rubyists, rely on every day, and their support for Ruby Central reflects a genuine understanding that open source communities need nurturing, not just tooling.
To the team at GitLab: thank you. Thank you for showing up year after year. Thank you for keeping us caffeinated and connected. The Ruby community is stronger because of partners like you, and we are grateful.
If you haven't already, we encourage you to explore what GitLab is building at [about.gitlab.com](http://about.gitlab.com/?ref=rubycentral.org), and if you see them at the conference, stop by and say thank you. They've earned it
### Modernizing Ruby Central's Bylaws and Officer Updates
URL: https://rubycentral.org/news/modernizing-ruby-centrals-bylaws-and-officer-updates/
Last updated: 2026-06-05T18:22:47.000Z
Since our last Board message that announced the launch of [Steering Committees](https://rubycentral.org/news/a-new-chapter-for-ruby-central/) and making an open call for volunteer leadership, we have spent a significant amount of time discussing the future of our organization.
Those conversations covered sustainability, governance, infrastructure stewardship, community participation, membership, sponsorship, and the role Ruby Central should play in supporting the Ruby ecosystem for years to come.
As those discussions evolved, it became clear that our bylaws no longer reflected how Ruby Central operates today, nor how we want it to operate in the future.
Many of the governing documents that served Ruby Central well in the past were written for a smaller organization operating in a very different environment. Over the past 22 years since Chad Fowler, Jim Weirich, David Alan Black, Paul Brannan and Richard Kilmer launched RubyGems at RubyConf , the RubyGems.org service has become critical infrastructure for the global Ruby community, Ruby Central's responsibilities have grown, and the ecosystem itself has evolved considerably.
What started as a conversation about ideas for the future of Ruby Central ultimately led us to an important realization that, before we could build what comes next, we needed to modernize the foundation we were building on.
Today, we're sharing a comprehensive update to Ruby Central's bylaws aimed at modernizing our governance, improving transparency, clarifying responsibilities, and supporting the long-term sustainability of the organization.
You can read the [full bylaws here](https://rubycentral.org/content/files/2026/06/Ruby-Central-Bylaws--2026.06.05-.pdf).
## **Why Now?**
Interestingly, we didn't originally set out to rewrite the bylaws.
Our initial goal was to share updates around governance, membership, steering committees, and new ways for the community to participate in shaping Ruby Central's future. As we worked through our ideas, we repeatedly found ourselves running into limitations, ambiguities, or missing structures within our existing framework.
The more we explored new approaches to community participation, committee structures, and organizational sustainability, the clearer it became that our bylaws were no longer providing the framework we needed.
What began as planning for future initiatives became a broader review of how Ruby Central operates and how we want it to evolve in the years ahead. This bylaw update is the result of that work by our Board.
## **What Changed**
While many of the updates are administrative or clarifying in nature, several themes guided the revision. For those interested in the complete document, the updated bylaws are available [here](https://rubycentral.org/content/files/2026/06/Ruby-Central-Bylaws--2026.06.05-.pdf).
### **Clearer Governance**
The updated bylaws more clearly define the roles and responsibilities of the Board of Directors, officers, committees, and participants in Ruby Central's governance processes.
We've clarified decision-making authority, delegation of responsibilities, conflict-of-interest expectations, and accountability throughout the organization.
### **Support for Participatory Governance**
One of the most significant additions is the introduction of a formal framework for participatory governance.
Ruby Central remains legally governed by its Board of Directors, which is required to retain full fiduciary responsibility for the organization. At the same time, we believe the broader ecosystem should have meaningful opportunities to help inform decisions that affect Ruby's future.
The updated bylaws establish a structure that will allow contributors, supporting members, sponsors, and other stakeholders to participate in a more organized and sustainable way while preserving the Board's responsibilities.
### **Stronger Committee Structure**
The bylaws now formally recognize both operational steering committees and advisory committees.
These groups will create opportunities for more members of the community to contribute their expertise and help advance Ruby Central's mission while maintaining clear legal boundaries around authority, accountability, and financial oversight. We need your help, and this is the first step we needed to take to more formally accept it.
Committees can support initiatives, provide guidance, and help execute important work, while ultimate responsibility remains with the Board.
### **Transparency and Financial Stewardship**
The revised bylaws place greater emphasis on transparency, financial reporting, governance documentation, and responsible stewardship of community resources. This may result in more work for us, but we believe it will be an improvement for transparency and trust.
As an organization responsible for shared infrastructure relied upon globally, we believe openness and accountability should be reflected not only in our actions but also in our governing documents.
### **Reducing Concentrated Influence**
We also introduced governance safeguards intended to reduce the concentration of influence within the organization.
The updated bylaws include provisions designed to limit excessive representation from any single company or organization and reinforce the principle that Ruby Central exists to serve the broader Ruby ecosystem.
### **Long-Term Organizational Stability**
The revised bylaws introduce staggered board terms, clearer participation expectations, continuity provisions, vacancy procedures, and more clearly defined leadership responsibilities.
We also clarified how organizational assets will be stewarded in the future, helping ensure that Ruby Central's resources remain dedicated to open source and community-focused purposes aligned with our mission.
Together, these changes are intended to help Ruby Central remain stable, resilient, and effective for the long term.
## **Looking Ahead**
We see this bylaw update as a foundation for our work ahead.
While bylaws may not be the most visible part of a nonprofit, modernizing them removed a number of obstacles that were standing in the way of initiatives we're eager to share with the community.
We have [published the new bylaws](https://rubycentral.org/content/files/2026/06/Ruby-Central-Bylaws--2026.06.05-.pdf) on our page for you to review in your own time.
In the coming weeks, we'll be publishing updates on membership, sponsorships, steering committees, governance participation, and other efforts designed to strengthen both Ruby Central and our broader Ruby ecosystem.
Shout out to Jim Remsik for keeping us honest in taking much longer than the two weeks Jey and I expected to provide another update. We'll do better now that our Board is unblocked.
We'd also like to share an update to Ruby Central's officer roles. To better align responsibilities with individual strengths and availability, the Board has reorganized its officer positions:
- Ran Craycraft, President
- Jey Flores, Vice President
- Freedom Dumlao, Treasurer
- Brandon Weaver, Secretary
- David Corson-Knowles, Board Member
Our goal is to build a Ruby Central that is more participatory, more transparent, more nimble, and more sustainable while becoming less dependent on concentrated sources of funding and more reflective of the broader Ruby ecosystem itself.
We're grateful to everyone who has reached out about joining and leading a Steering Committee, contributed feedback, ideas, and perspective throughout this process, and we're looking forward to continuing this work together. With this groundwork in place, we’re excited for the formal launch of all 5 steering committees at [RubyConf](https://rubyconf.org/?ref=rubycentral.org) Tuesday, July 14th – Thursday, July 16th, 2026\. Reach out to us to engage.
[Read the Ruby Central Bylaws](https://rubycentral.org/content/files/2026/06/Ruby-Central-Bylaws--2026.06.05-.pdf)
Ran Craycraft
*Ruby Central Board of Directors President*
---
*Update (June 5, 2026): Added additional access links to the bylaws throughout the document for easier access.*
### Gem Packed with Gratitude: Thank You, 84codes
URL: https://rubycentral.org/news/gem-packed-with-gratitude-thank-you-84codes/
Last updated: 2026-07-10T13:57:22.000Z
[RubyGems.org](https://rubygems.org/?ref=rubycentral.org) is the quiet backbone of the Ruby world. It processes over 1,500 gem requests per second, serves billions of downloads every month, and keeps the tools developers rely on available, secure, and free. It's the kind of infrastructure you only notice when something goes wrong. Which, thanks to supporters like 84codes, it rarely does.
[84codes](https://www.84codes.com/?ref=rubycentral.org) has long believed that great developer tools deserve to be sustained. As a company built around making infrastructure invisible, whether through CloudAMQP (their managed service) or LavinMQ (their open-source message broker), 84codes knows firsthand how much trust gets placed in shared services every single day. Supporting RubyGems.org isn't a marketing move for them. It's a reflection of who they are. They care about the ecosystem, and they've put real, ongoing commitment behind that care as a Supporter Plus member.
That kind of long-term support means Ruby Central can keep the lights on, ship security improvements, and ensure RubyGems.org remains reliable for every developer who depends on it, from solo hobbyists to large engineering teams shipping critical software.
To everyone at 84codes: thank you. Thank you for seeing the value in shared infrastructure and choosing to invest in it. The Ruby community is stronger because you're in it.
*If you'd like to join partners like 84codes in supporting shared Ruby infrastructure, I'd love to hear from you — tom@rubycentral.org*
### Welcome Back, Typesense!
URL: https://rubycentral.org/news/welcome-back-typesense/
Last updated: 2026-07-10T13:57:57.000Z
Two years in a row, we love to see it. A huge thank you to Jason Bosco and the [Typesense](https://typesense.org/?ref=rubycentral.org) team for coming back and continuing to invest in this community. It genuinely means a lot to us.
You might not know their name yet, but trust me you're about to. Typesense is an open-source search engine that's blazing fast, typo-tolerant, and actually a joy to work with. Think of it as everything you wished Algolia was (including open source), without the Elasticsearch therapy bills. They're self-funded and building for developers, not investors, and it shows in every line of their docs.
Oh, and one more thing: Typesense is your **WiFi sponsor** this year. That's right every Slack message you send from the conference floor, every "can everyone see my screen?", every frantic Google search for that method name you blanked on mid-talk... brought to you by Typesense. Maybe give their site a visit while you've got such a great connection.
Go check them out on Github and hope to see you in Vegas!
### Welcome Back, Mudflap!
URL: https://rubycentral.org/news/welcome-back-mudflap/
Last updated: 2026-07-10T13:58:34.000Z
We’re thrilled to announce that [Mudflap](http://mudflapinc.com/?ref=rubycentral.org) is returning as a sponsor of RubyConf for the second year in a row. Their continued investment in the Ruby community means a lot to us, and we couldn’t be more excited to have them back.
If you’re not familiar with Mudflap, they serve the $800B trucking industry — the backbone of the U.S. economy. Their market-leading payments and marketplace platform helps truckers save thousands of dollars on fuel (their #1 business expense), while giving fuel stop partners access to new, hard-to-reach customers. It’s a powerful example of technology bringing transparency and efficiency to a historically fragmented space.
Mudflap is also expanding beyond fuel into the broader freight ecosystem, building products that match carriers and brokers around freight loads.
And they’re doing it all with Ruby. From payments infrastructure and marketplace dynamics to partner integrations and customer-facing products used every day across the country, Mudflap is a great example of Ruby powering meaningful, real-world systems at scale.
**And they’re hiring!** Mudflap is actively growing their engineering, data, and customer-facing teams, and they’re looking for people who care about craftsmanship, ownership, and building products with tangible impact in an underserved industry. [Check out their open roles →](https://www.mudflapinc.com/open-positions?ref=rubycentral.org)
**Meet them in person at RubyConf 2026.** Mudflap will have a booth on-site at the Red Rock Resort in Las Vegas — stop by to learn more about what they’re building, chat with their team, and get a feel for how they operate. They’ll also be participating in the **RubyConf Career Fair on July 14–15**, where you can have real conversations with a team that’s actively hiring.
RubyConf 2026 runs **July 14–16 in Las Vegas**. Grab your ticket at [rubyconf.org](http://rubyconf.org/?ref=rubycentral.org) and make sure to add Mudflap to your list of must-visit booths.
### Welcome Back, Judoscale!
URL: https://rubycentral.org/news/welcome-back-judoscale/
Last updated: 2026-07-10T13:59:02.000Z
**Welcome Back, Judoscale!** We're excited to welcome [Judoscale ](https://judoscale.com/?ref=rubycentral.org)back as a **Silver Sponsor** of [RubyConf](https://rubyconf.org/?ref=rubycentral.org) for the second year in a row. If you've ever lost sleep wondering whether your Rails app could handle a sudden traffic spike, Judoscale is probably already on your radar and if it's not, it should be.
Judoscale is a dedicated autoscaler for Rails apps (and beyond), purpose-built around request queue time rather than blunt metrics like CPU or memory. That distinction matters: queue time tells you when your app is actually struggling, not just busy. The result is smarter, faster scaling up when you need it, down when you don't without the overprovisioning tax most teams quietly pay every month. It works across Heroku, Render, Fly.io, Railway, and Amazon ECS, with deep support for Sidekiq, Solid Queue, Good Job, and more.
The Ruby community clearly agrees Judoscale has been a fixture at Ruby conferences precisely because it's built *by* developers, *for* developers, and it shows in the quality of their gems, docs, and support.
**Come say hi in Las Vegas.** Judoscale will be at [RubyConf 2026 July 14–16](https://rubyconf.org/?ref=rubycentral.org) at the Red Rock Resort. Stop by their booth to chat with the team, ask your toughest autoscaling questions, or just thank them for helping you sleep at night.
Thank you, Judoscale, for your Silver Sponsorship and for being part of the community again this year. We're glad you're back.
### thoughtbot Joins the Ruby Alliance
URL: https://rubycentral.org/news/thoughtbot-joins-the-ruby-alliance/
Last updated: 2026-07-10T13:59:31.000Z
We’re excited to share that [thoughtbot ](http://thoughtbot.com/?ref=rubycentral.org)has become the second company to join the Ruby Alliance.
For 23 years, thoughtbot has helped shape the Ruby ecosystem through thoughtful engineering practices, trusted guidance on large-scale application development, and some of the most respected educational resources in the community.
Their participation in the Ruby Alliance brings experienced leadership, operational perspective, and a strong commitment to helping support the long-term health of Ruby and the infrastructure the community depends on.
As the Ruby Alliance continues to take shape, thoughtbot’s consulting experience and community perspective will help inform how Alliance companies can work together to sustainably invest back into the ecosystem.
Ruby has supported generations of developers, teams, and businesses. Partnerships like this will help ensure that support continues well into the future.
We’re incredibly grateful for thoughtbot’s partnership and excited for what we’ll build together.
If your company is interested in learning more about the Ruby Alliance, please contact [tom@rubycentral.org](mailto:tom@rubycentral.org).
### Gusto Joins the Ruby Alliance
URL: https://rubycentral.org/news/gusto-joins-the-ruby-alliance/
Last updated: 2026-05-11T20:22:38.000Z
We’re excited to share that Gusto has become the first company to join the Ruby Alliance.
The Ruby Alliance is a small coalition of companies that are choosing to make a significant investment in the long-term health, resilience, and sustainability of the Ruby ecosystem and the infrastructure it depends on.
We are honored and humbled by how quickly and decisively Gusto moved to join us. They didn’t wait to see what other companies would step forward. They recognized the importance of this moment and chose to lead the way.
Ruby has always thrived because individuals and companies invested back into the ecosystem that supports their teams and businesses every day. Gusto’s leadership is a meaningful example of that spirit in action, and we are very grateful to their team.
Thank you, Gusto, for your partnership, and we’re excited about what we’re going to build together.
If your company is interested in learning more about the Ruby Alliance, please contact [tom@rubycentral.org](mailto:tom@rubycentral.org).
### RubyConf Updates
URL: https://rubycentral.org/news/rubyconf-updates/
Last updated: 2026-04-22T19:30:49.000Z
If you haven't yet seen [the statement from the Ruby Central Board](https://rubycentral.org/news/a-new-chapter-for-ruby-central/), the organization has been preparing for some significant changes. RubyConf, our flagship annual event, is also moving and adapting with these transitions.
This year, we ambitiously envisioned several exciting new programs designed to reimagine RubyConf and bring new energy, new voices, and new opportunities to the conference. We took a step back, reevaluated each of these programs, and took fresh creative approaches to bringing a clearer vision for what RubyConf can and should be.
Here’s what some of the new programming will look like going forward.
## Steering Committees and Town Hall Sessions
This year, we want to try something at RubyConf that we think the community will find valuable: working sessions with the Ruby Central board to help shape what comes next. These Town Hall Sessions will focus on the early stages of building out the governance and structure of steering committees across the organization. If you're thinking about getting involved in this massive project, being in-person at RubyConf and working directly with the board is a great place to start.
More details will be shared in a future update.
## Ruby Runway — From Competition to Showcase
Ruby Runway was envisioned as a pitch competition celebrating the startups in our community. As we developed it, we realized a showcase or demo format is a better fit for what RubyConf does well: creating genuine connection, support, and visibility for builders doing interesting things with Ruby.
Ruby Runway will become a fast-pitch startup showcase where founders take the stage, share their work, and connect with a room full of brilliant Rubyists. We think this format is more fun, more personal, and more in the spirit of what Ruby has always been about: developer happiness and community.
We'll be sharing more about the participating startups soon, so you can seek them out and connect while you're at RubyConf.
## Ruby in the Real World Showcase — Folded Into the Main Program
This concept is still alive, just finding a new home. Rather than running as a separate event, we will weave the Ruby in the Real World Showcase into the regular conference program.
The purpose remains the same: a curated showcase of Ruby-powered technology in real-world businesses, welcoming both companies that build with Ruby and those that build for Ruby developers. The timing and communications around this new program didn't land the way we hoped this year, and we own that. But the idea is sound, and we're committed to giving it the space it deserves.
If you're interested in being represented with a table booth, we'd love to talk. Reach out to [**Tom Chambers**](https://calendly.com/tom-rubyconf%5Fsponsors?ref=rubycentral.org)to learn more.
## On the Career Fair and Fundraising Gala
Two programs we had planned for this year will not be moving forward as originally intended.
The Career Fair as a standalone event is on pause. Hiring across most of the tech industry has slowed down considerably, and the feedback we received from our outreach was consistent. That said, RubyConf has always been a hub to meet talented and inspirational Ruby developers. If you or your organization is hiring for any position, RubyConf is a place to be! Reach out to [**Tom Chambers**](https://calendly.com/tom-rubyconf%5Fsponsors?ref=rubycentral.org) to discuss options.
The Fundraising Gala has been canceled. Ultimately, we made the call to step back and reimagine what fundraising looks like for Ruby Central going forward, built on grassroots support and grounded in community.
Both of these events represented something we care deeply about: bringing people together in a meaningful way while investing in the future of this community. That intention isn't going anywhere, and we're committed to finding the right ways to bring both back when the time is right.
## A Note of Gratitude and an Ask
RubyConf exists because of you. Every attendee, speaker, sponsor, and volunteer is what makes this event worth fighting for, and we are fighting for it. We still plan on putting on one hell of an experience! The Program Committee has been pouring their full hearts and creativity into making this a genuinely fantastic event, and the full program and schedule will be going live in the coming days.
If you believe in what Ruby Central is building, there are ways to help: [attend RubyConf](https://ti.to/rubyconf/rubyconf-2026?ref=rubycentral.org), spread the word, [sponsor if your organization is able](https://rubyconf.org/sponsors/?ref=rubycentral.org), and stay engaged. If you haven't grabbed your ticket yet, **early bird pricing ends April 30th** (*or until sold out*), so now is a great time to lock in your spot.
The Ruby community has been beyond gracious, patient, and supportive. Thank you!
We can't wait to see you at RubyConf!
Ally Vogel
Operations Manager
### A New Chapter for Ruby Central
URL: https://rubycentral.org/news/a-new-chapter-for-ruby-central/
Last updated: 2026-04-17T03:30:55.000Z
We have made recent and significant changes to how Ruby Central operates.
We have parted ways with our Executive Director, our PR agency, our CFO, and concluded several contractor engagements. These were not easy decisions, but they were necessary to ensure the long-term sustainability of Ruby Central. Since joining the Board at the beginning of the year, we have seen the organization's finances become overly dependent on the optimistic timing of when funds may be received against fixed timelines for when our expenses are due.
As a result, Ruby Central has found itself in real financial jeopardy. This is a situation we've been working toward resolving by reducing our expenses, renegotiating contracts, increasing and diversifying our fundraising outreach, and pursuing big ideas we believe will create a stronger, more inclusive Ruby Central community for tomorrow.
We voted this month to begin restructuring from being a governing board to a volunteer working board. That means instead of the board advising a full-time Executive Director, our board members have taken on direct roles and responsibilities alongside our hardworking team of staff and volunteers. We voted for some difficult personnel cuts and to reduce discretionary spending. We voted to preserve RubyConf.
As a non-profit, Ruby Central's work has always been driven by an outpouring of generosity from amazing volunteers and community members. Our role, which we take very seriously, is to facilitate that going forward, as we move with focus and urgency.
## Where We Are Now
Ruby Central has gone through a difficult period, and some of that has been visible to all of you. Some of it has been structural and behind-the-scenes. The gap between how we've been operating and what this ecosystem needs has been growing for some time, coming to a head in the past few months.
We are choosing to move forward.
We do not have an appetite for any ongoing conflict, and we believe our community doesn't either. We believe in Ruby. We believe in MINASWAN. And we believe our community is still reaching its full potential.
As a board, we've spent countless volunteer hours untangling the past and stabilizing the present. Now we are focused on building what comes next.
Our priorities are clear, and we know this will take time:
- Open up how big decisions are made and who participates
- Strengthen the security and reliability of RubyGems
- Invest in the future of Ruby, so it continues to grow
- Repair and rebuild trust across the community, and earn that trust with patience and results
## What We're Building
We are launching a set of initiatives designed to stabilize the ecosystem and move it forward.
**Now: Ruby Alliance**
The Ruby Alliance brings companies together to directly support RubyGems and the broader ecosystem. Member companies will contribute engineering time and financial support. In return, their developers will help shape priorities and ensure the infrastructure they rely on remains strong, secure, and evolving.
This will be shared responsibility in practice.
**Next: Project DREAM**
Project DREAM is our investment in Ruby's future.
DREAM stands for Driving Ruby's Evolution to AI Maturity.
AI is rapidly moving into production. Teams are already rebuilding the same infrastructure over and over to make these systems usable, testable, and reliable.
If we do nothing, that work will continue to fragment across companies and ecosystems behind closed doors, and Ruby risks falling behind as modern development shifts. We are seeing Ruby show up less often in API and SDK support across the industry. Part of this work is making sure Ruby is represented in the tools and standards developers rely on every day.
Project DREAM focuses on building a foundation together:
- Making it easier to integrate AI tools and workflows into Ruby applications
- Improving evaluation, observability, and developer experience
- Identifying and closing gaps that limit adoption in modern stacks
- Ensuring RubyGems and related tools support these new patterns
- Advocating for and expanding Ruby support in APIs, SDKs, and emerging community standards
This is about making sure Ruby is not just stable, but actively supported, competitive, and compelling for the next generation of applications.
**Soon: Apprenticeship Program**
We will be building a structured apprenticeship program focused on developers from underrepresented groups.
Apprentices will work within the Ruby Alliance alongside maintainers and experienced contributors on real projects, including Project DREAM. The goal is to grow the next generation of Ruby contributors while expanding access to the ecosystem.
We know how lofty a goal this is, but there's no investment more important to the future of Ruby than introducing a new generation of software developers to these tools and this community.
## How We're Opening This Up
We are introducing steering committees led by our board members to bring more voices into how this work will happen.
These will be focused working groups made up of maintainers, contributors, and community members. They will help shape priorities and guide execution across key areas:
- Open Source and Infrastructure
- Ruby Alliance and Funding
- Community, Conferences, and Governance
- Apprenticeships and Education
- DREAM and the Future of Ruby
This is an open invitation.
If you care about Ruby, there is a place for you to contribute. That includes people who have been deeply involved for years as well as those who may have felt pushed away. We want to move forward together.
## Looking Ahead
We are intentionally building a leaner Ruby Central, modeled more closely on organizations like the Python Software Foundation, Linux Foundation, and Rails Foundation — with clear purpose, transparent governance, and broad participation.
We are grateful to the many members of the community who have shared their perspectives and guidance, including Mike Perham, David Heinemeier Hansson, Evan Phoenix, Matz, Obie Fernandez, Alan Ridlehoover, and Chad Fowler, along with many others.
### To the maintainers
RubyGems is what it is today because of the time, care, and expertise that many of you have given to it over the years.
That work matters, and it is deeply appreciated.
As we move into this next chapter, we want to extend an open invitation to re-engage in whatever way feels right to you. There is meaningful work ahead, and there is space for those who want to help shape what's next.
## How You Can Get Involved
**Join a steering committee**
Help shape the direction of Ruby Central and contribute to the areas you care about most.
**Companies**
Join the Ruby Alliance and take an active role in sustaining and evolving the ecosystem. Interested? Connect with [Tom Chambers](mailto:sponsors@rubycentral.org), our Sponsors Manager.
**Individuals**
Contribute to open source, [become a monthly supporter](https://rubycentral.org/#/portal/signup), and participate in the apprenticeship program.
If you're interested, [reach out to us](mailto:board@rubycentral.org).
Keep us honest. We've said that change is necessary, and that we'll be looking to our community to help shape what comes next. That promise doesn't mean much behind closed doors. We'll be back within two weeks with more details on RubyConf, the Ruby Alliance, and the bigger questions about governance and what we believe Ruby Central can become.
This is our chance to build the next version of it together.
*With appreciation,*
*— Jey Flores and Ran Craycraft*
*Board Members, Ruby Central*
### RubyGems Fracture Incident Report
URL: https://rubycentral.org/news/rubygems-fracture-incident-report/
Last updated: 2026-09-03T14:56:31.000Z
By: Richard Schneeman
This document attempts to give closure to the Ruby community about the events that led to the incident, September 10-18, 2025, which I’ve named “RubyGems Fracture.”
## Preamble
I joined Ruby Central’s Open Source Committee on October 22nd, 2025, after the GitHub access changes. I was adamant internally and externally from day one about performing a retrospective to try to wrap my head around the full, true picture of what happened and why.
In the pursuit of this task, I’ve spent 20+ hours interviewing and chasing up leads, easily quadrupling that time spent reviewing other artifacts such as chats and raw GitHub access logs. For any fact learned verbally, I’ve cross-referenced it with either another independent (important) account or hard evidence, such as a document or video, etc. This incident involved many people over a rather long time scale, and it was important to detangle how people perceived events from how they actually unfolded. The subject matter is deeply subjective, and multiple failed attempts at writing this doc came as a result of aiming for objectivity, for blameless representation. Therefore, those named in this report are:
- Full-time employees of Ruby Central
- Part-time consultants who were involved in access discussions
- Anyone who made an access change from September 10th-18th, 2025
- Those who have already been publicly identified in the discourse
Volunteer groups, including the Ruby Central Board and the Open Source Software (OSS) Committee, are listed, but their actions are represented as a group. Individual quotes from the OSS Committee are used without direct attribution when they represent a general consensus.
This document attempts to paint an accurate representation of what Ruby Central (staff and members, especially in the OSS Committee) experienced and did in the events leading up to and including GitHub access removal. It is not the only lens to view these events, and it’s not exhaustive, but the hope is that it will provide transparency and hopefully closure.
## Summary
Two engineers, André Arko and Samuel Giddins, were working on RV together. Each announced that they were leaving Ruby Central. Ruby Central, in turn, wanted to cleanly offboard them and sever ties with RubyGems.org production access, which was tightly coupled to GitHub access. However, Ruby Central lacked the structural ability to make this change directly (did not have admin controls on the GitHub Business/Enterprise). The resulting process was drawn out and poorly communicated internally and to the general public.
This led to the GitHub access changes between September 10th-18th, 2025, that resulted in the walkout of paid contributors: André Arko (`indirect`), David Rodríguez (`deivid-rodriguez`), Ellen Dash (`duckinator`), Josef Šimánek (`simi`), Martin Emde (`martinemde`), and Samuel Giddins (`segiddins`). A group that refers to itself as **the maintainers**.
This group asserted that they controlled administrative access to the `github.com/rubygems` organization via the Business/Enterprise permissions and that Ruby Central, the operator of the RubyGems.org service, does not have a right to those abilities or access. When Ruby Central's Open Source Director, Marty Haught, gained access to the GitHub Business/Enterprise and would not relinquish this control, they quit in protest.
## Incident Lessons
Here are some of the lessons from the timeline below:
**Policies and procedures are important**: Runbooks and other operational documents, technical and non-technical, were neglected for a long time. Efforts to document and standardize these efforts began shortly before this incident in July/August 2025\. At the time of the incident, there were no documented offboarding policies or checklists. There are now.
Many companies have an “Outside Business Activities” declaration process for full-time employees to formally let their employer know when they’re working with a foundation or pursuing an activity with compensation, such as writing a technical book. Ruby Central does not have a policy like this in place, but I’ve suggested we add one.
**Distinguish remarks from requests**: The initial access loss timing was accidental. This could have been prevented by clearly labeling requests for action.
**Access changes should always come with explanations**: When an access change event happens, the person affected should always know:
- What access was changed?
- Why?
- What can they do about it going forward? Is it permanent or temporary? Who can they talk to if they have questions or problems?
Ruby Central has reached out to some of the developers who were removed due to inactivity to let them know why. We will reach out to all of them.
Platforms with permissions management, such as GitHub and RubyGems.org, should consider adding an option for users to include messages when access changes occur.
**Teams need to know why access is changing:** Beyond letting the people affected know, those who work with them need to know. This is important not just for access removals but additions as well.
- Whose access changed?
- What is it now?
- Who should they talk to if they have questions or problems? It's not always appropriate to share specifics with everyone, but say as much as you can.
**Impacts of access changes should be clear:** Platforms with Role-Based Access Control (RBAC, such as team membership) and hierarchical access systems (such as a GitHub Business/Enterprise containing many Organizations) make it harder for the user making access changes to know the end result of their change. It is better to place the burden of understanding the impact on the system than on the user.
I suggest that these platforms consider adding the ability to preview the effect of access changes to reduce mistakes. A preview could help ensure that the Principle of Least Privilege (PoLP) is being followed without accidentally removing too much.
**Perform sensitive operations "out loud"**: The Japanese have a concept translated to "[pointing and calling](https://en.wikipedia.org/wiki/Pointing%5Fand%5Fcalling?ref=rubycentral.org)" for avoiding and recognizing mistakes. This can be repurposed for many contexts, such as access changes.
An example could be announcing "I'm going to change access now" in a new Slack thread, then following up with how you plan on changing it (such as posting a screenshot, hovering over the new status) before actually making the change. This gives a log so the person can remember individual actions and when they were taken. This is useful even if the system has a log to separate intentions from actions. Done in front of others, it also gives them time to react if the planned action is not desired. It won't stop every mistake, but it will stop some and make doing a retro on others easier.
**Decouple access from personal identity**: Access changes in open source are especially emotional experiences. Beyond losing capabilities, access reduction can affect perceived credit for and earned positions. For example, removing ownership on [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) has the side effect of removing gem download metrics from a user’s profile page.
Platforms that couple metrics with permissions management should consider ways to extend attribution that are decoupled from direct access. For example, preserving gem downloads for “alumni” of package owners even after they’re removed.
**Access shouldn't gatekeep contributions or getting paid**: The way that **the maintainers** explained financial compensation came from early days of paid work on Bundler and Ruby Gems, where someone would make good contributions, be recognized with commit access, eventually promoted to “maintainer” status, and this would open the door for getting paid for maintenance or operations. The implication is that if commit access is taken away, it is perceived as removing both status and income. This pipeline also introduced an incentive problem where new members gaining status would be perceived as possible income competition.
**Public work and funding require public accountability**: The business of open source is not just doing the work, but making sure it’s done in a clear and appropriate way. That means more time and care need to be spent on drafting appropriate policies and communicating them internally and externally. It also means that foundations need to be fluent in engaging with their communities and communicating clearly.
## Timeline leading up to the Incident
**January 13, 2025**
- Marty Haught, the Ruby Central Open Source (OSS) Director, created a 2025 Roadmap document with funding ideas, including “Ruby one-line installer” and “Make RubyGems faster” proposals, both of which referenced UV, the Python package manager written in Rust.
**January 17, 2025**
- André Arko edited the 2025 Roadmap to add detail and change the title to “Ruby one-line installer/manager”.
Ultimately, neither project received funding (no grants or sponsors were found to directly hire for the project through Ruby Central), but the item was still in the foundation's technical roadmap of projects it was interested in.
**February 28, 2025 6:15:12 UTC** Taken by `indirect`
- business.remove\_admin: 5 members including `evanphx`
- org.update\_member: 8 members including `evanphx` before: admin, after: read
Evan Phoenix `evanphx` helped run Ruby Central as a volunteer, along with Marty Haught, for many years. He held GitHub business/enterprise admin access since it was created, and has been an admin on the organization for many years prior. He held this access as a Ruby Central stakeholder. André did not contact any of those removed with a reason or information on what they should do if they needed or wanted access again. When asked in \~March 2026, over a year later, the stated reason given for the removal was "inactivity." This removal, with no replacement, left Ruby Central without any representation of GitHub business/enterprise access.
**March 5, 2025**
- Marty Haught [introduced policy pages to RubyGems.org](https://github.com/rubygems/rubygems.org/pull/5497?ref=rubycentral.org), including Acceptable Use Policy (AUP), Copyright Policy, Privacy Notice, and Terms of Service (TOS). This included policies such as how RubyGems.org [shared personal information with 3rd parties](https://rubygems.org/policies/privacy?ref=rubycentral.org) and what personal information (PII) it collects.
**June 3, 2025**
- André Arko announced he was leaving Ruby Central with a message to the `#general` channel:
> *“After sitting with the DHH news for a few days, I’m sorry to say that I’m not going to be able to attend RailsConf, and I am resigning from my advisory role at Ruby Central.*
>
> *I plan to continue participating in and advising the RubyGems open source projects, but platforming DHH at RailsConf means I cannot continue as an official member or representative of Ruby Central. \[...\]”*
André announced that he is leaving his paid, part-time advisory role with Ruby Central. The OSS Committee read this post as indicating he desired to cut all financial ties with Ruby Central. However, that was not the case. Andre did not leave his secondary on-call rotation, which is also a paid part-time position.
The Ruby Central OSS Committee is a group of volunteers who have oversight of Ruby Central's OSS budget, as proposed by the Ruby Central OSS Director, Marty Haught. At the time, the committee consisted of Gabi Stefanini, Mike Dalessio, and Ufuk Kayserilioglu (who was also a board member). These members have since moved on, and today the committee is composed of one member, Richard Schneeman, the author of this document.
**June 27, 2025**
- Ruby Central OSS Committee meeting program updates. Raw notes from the meeting:
> - *Maintenance budget*
> - *Cutting back from $22k to $12k per month to extend maintenance budget*
> - *Eliminates secondary on call ($4k per mo)*
> - *Cuts back maintenance 50% ($6k)*
> - *RubyGems.org supporter membership*
> - *$2-5k per year for businesses*
> - *All goes to maintenance and on call (after admin cut)*
> - *Criteria*
> - *Allows easy credit card signup with recurring monthly payments.*
> - *Fully self-service for managing their subscriptions.*
> - *Internationally friendly*
> - *No contract to sign*
> - *Minimal sign up data collected: name, email, organization, payment info.*
> - *API so we can programmatically generate a list of members on RubyGems*
> *and RubyCentral websites.*
> - *New contractor: \[...\]*
> - *Former \[...\] - Used to work with \[Ruby Central paid bundler maintainer\]*
In this meeting, they discussed [balancing the maintenance budget](https://speakerdeck.com/mghaught/baltic-ruby-keynote-2025?slide=20&ref=rubycentral.org) given a sponsorship gap by eliminating secondary on-call, as well as onboarding a new contractor. They planned to use this new contractor to support initiatives that can bring in more revenue to fund OSS maintenance, as spelled out in the middle bullet.
**July 7, 2025**
- Ruby Central published a blog post, [RubyGems.org Funding Model & A New Path For Community-Led Growth](https://rubycentral.org/news/rubygems-org-funding-model-a-new-path-for-community-led-growth/).
This blog post tried to drum up additional funds and diversify sponsors:
> **“With roughly 110 supporters,* we would be able to fully fund our annual goals for operations and maintenance. In addition to our other funding sources, such as corporate sponsors, this level of community funding would enable us to expand beyond maintenance and focus on new features and enhancements that will benefit developers and gem creators.”*
**July 8, 2025**
- First day of ["The last RailsConf"](https://web.archive.org/web/20250703102317/https://railsconf.org/).
**July 9, 2025**
- First commit on Ruby Central "runbooks" (private) repository by the new contractor.
There was no documentation on how to run the RubyGems.org service (a.k.a "runbooks”), so in addition to doing scoped work, the new contractor was also tasked with documenting their onboarding process. This also means there was no documentation on how to revoke someone's access or offboard them from the RubyGems.org service.
**July 10th, 2025**
- The last day of “The last RailsConf”.
**July 11, 2025**
- Ruby Central "RubyGems maintainer offsite" was held in the same city as RailsConf, at a different venue. Travel for Marty Haught, Samuel Giddins (the full-time Security Engineer on staff for Ruby Central), André Arko, and one more were covered by Ruby Central.
- The [first commit on RV](https://github.com/spinel-coop/rv/commit/2fce7dd6a6659d16146672a3eab9871899203b91?ref=rubycentral.org), a Rust tool for managing Ruby dependencies, was created by André Arko and Samuel Giddins.
**July 20, 2025**
- The [spinel-coop org](https://github.com/spinel-coop/.github/commit/10c4951376598a3745d9be1fca7c5fab31ec9524?ref=rubycentral.org) where the RV project lives got a description:
```
Spinel maintains the Ruby language packaging ecosystem, and acts as maintainer of last resort for the Ruby ecosystem. Our portfolio includes:
- rv, the ultimate Ruby version manager and gem tool
A Spinel retainer offers organizations the opportunity to ensure the sustainability of their foundational Ruby dependencies, and direct access to the expertise of the maintainers.
If you’re betting your business on a critical open source technology, you
1. want it to be sustainably and predictably maintained; and
2. need occasional access to expertise that would be blisteringly expensive to acquire and retain.
Getting maintainers on retainer solves both problems for a fraction of the cost of a fully-loaded full-time engineer. From the maintainers’ point of view, it’s steady income to keep doing what they do best. It’s a great deal for both sides.
```
Ruby Central was not aware of RV or either Sam or André's participation in this new Co-Op at this time. When they learned of it, the structure seemed similar to RubyTogether, which was created in 2015 by André Arko and merged with Ruby Central in 2021\. RubyTogether funded bundler and later [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) codebase maintenance and merged with Ruby Central in October 2021\. In the merger, the Ruby Central OSS Director position was created, and André Arko became the first acting director.
While he was only paid part-time to work with Ruby Central, he had intimate knowledge of the foundation roadmap and knew Ruby Central was interested in undertaking a similar project. He did not tell anyone in Ruby Central about this work until it launched later, on August 26, 2025.
**July 28, 2025**
- André registers [Spinel Cooperative Corporation](https://www.bizprofile.net/ca/san-francisco/spinel-cooperative-corporation?ref=rubycentral.org) in the state of California.
**August 1, 2025**
- Shan Cureton, Ruby Central's Executive Director, had a meeting with the Ruby Central board. Board members are: Ben Greenberg, David Corson-Knowles, Freedom Dumlao, Kinsey Ann Durham, Naijeria Toweett, Ufuk Kayserilioglu, and Valerie Woolard.
- Shan shared that a pledge to fund OSS at Ruby Central for $250,000 was withdrawn. Contributed Systems (Sidekiq) later publicly shared that they withdrew a pledge due to DHH speaking at the last RailsConf.
The forecast from **June 27, 2025**, included this pledge, meaning an already tight OSS budget got tighter. However, there was already a declared interest in reducing secondary on-call to slow the burn rate.
**August 4-22, 2025**
- OSS Committee Slack message from Marty in Slack regarding making money from the RubyGems.org server logs:
> *“André suggested a way that his consultancy could cover the cost of secondary on call by analyzing gem download access logs to provide usage data by companies. Here's a quick write-up of the proposal in this thread. \[...\]”*
The proposal has André acting as a middleman between Ruby Central and a third party who would pay for the logs. It is unclear at that time who that third party was, how they would make money from the logs, or how much money those logs would be worth to them.
A OSS Committee member responds:
> *“\[...\] Do we really, truly need a secondary shift? I think I remember Marty saying that in that last few years, the secondary shift has never been escalated to. \[...\] It's not stated explicitly in André's message, but my understanding is that he will want to own any derived works based on the HTTP logs. If that's the case, then we need to make sure we're comfortable losing control of community PII in a way that may be unpleasantly surprising down the road. \[...\] Let's please make sure we're imagining the worst-case scenarios before going much further.”*
The cost of secondary on-call is $48,000 USD annually.
Marty responds:
> *“\[...\] Legally, we'll need to investigate this to be clear on what we can do here. It is PII. We do care about GDPR. Our Privacy Policy specifically mentions this data:*
> *\[...\]*
> *The transparency and ownership points you bring up are the biggest in my mind. In the end, it may not be worth allowing a third party to do this sort of thing. RC may want to provide more visibility in how gems are consumed to publishers but that is separate from this discussion.*
> *\[...\]*
> *Though I am still keen to \[hear\] the committee's thoughts. I don't think we can proceed with this. Long-term, we are better off not involving André with the operation of the platform. Signing a deal with his consultancy to build a product with PII from the service isn't worth all the reputational risk we are likely to incur regardless if legal signs off on it. While the short-term gains are attractive when we're tight on funding, it's not worth it in many aspects.”*
**August 18, 2025**
- Samuel Giddins gives Ruby Central his two-week notice that he will be terminating his full-time security position.
- André Arko creates an access token named `rubygems-github-backup` with access to all repos in the [github.com/rubygems](http://github.com/rubygems?ref=rubycentral.org) organization, including private repos. This is the only access token of its kind.
**August 25, 2025**
- André releases RV, and it is [announced to the public](https://web.archive.org/web/20250826103745/https://andre.arko.net/2025/08/25/rv-a-new-kind-of-ruby-management-tool/). The post mentions Samuel Giddins as a team member.
- André follows up with Marty on his proposal to cover secondary on-call with access to the RubyGems.org logs.
**August 26, 2025 18:26 UTC**
- OSS Committee Slack message by Marty:
> *“I'm back and catching up after my mountain trip. I'd love to hear any updates from the committee meeting.*
> *So the other new thing is [André's post about RV](https://andre.arko.net/2025/08/25/rv-a-new-kind-of-ruby-management-tool/?ref=rubycentral.org). I saw this mentioned in two slack channels. I did not know of this until I read the post, which is disappointing. Looks like Sam is leaving to work on that. Both of which I learned through the post and not directly from either of them. I'd love your thoughts on how we should respond.*
> *I had debated internally if we should make a public announcement about Sam's departure. Does this push us more in a direction?*
> *I was already planning on accelerating removing André but this seems to put that at a higher priority for when I'm back from Rails World. It would be easier if I had another 2 engineers to help with on call.”*
This message is the first recorded artifact that mentions a desire to offboard *André*. The framing “accelerating removing” also shows that the intent came prior to this message and the RV announcement.
**August 26, 2025 (follow-up)**
- OSS Committee Slack, a member responds:
> *“yes, agreed. we can add \[a previous RubyGems contributor\] to the rotation if \[they are\] ready for it, and i think we should accelerate the adoption of people from other companies that can do similar work (like \[another contributor from a different company\]).”*
Another member responds:
> *“I'd cut Sam and André's ties with the organization as soon as possible, announce the departures, and wish them the best of luck on their next endeavor.”*
The conversation quickly turns to operations of the RubyGems.org service, where on-call staffing is a concern. Previously, Samuel Giddins was part of the rotation; with his departure, they would need time to find a replacement.
**August 27, 2025**
- RV adds a license. It is now dual MIT/Apache-2 open source licensed.
**August 29, 2025**
- Message from Marty in the OSS Slack
> *“To follow up on the on call, the team discussed how to handle on call with Sam's departure. We'll have André cover that in September. We're going to put together onboarding and improved documentation in September to train up several folks to be on call ready. \[new consultant\] and \[another developer\] has volunteered to be part of that group. I'm looking to get 3-4 total people per time zone block (emea, americas, apac) so we can have a sustainable rotation.”*
At this point, the path to offboarding everyone cleanly was uncertain. The new consultant made progress on some runbook documentation, but still did not have server access.
At this time, Marty, as the Ruby Central OSS Director, did not have admin permissions on GitHub. Those permissions are held by Colby Swandale, Hiroshi Shibata, André Arko, Samuel Giddins, and Martin Emde. That means in order to offboard anyone, he needs to ask someone else to make a change.
**September 4, 2025**
- First day of RailsWorld conference.
There was a meeting at RailsWorld between Rails Core, including David Henimier Hanson (DHH), and Ruby Central representatives at the conference. I've interviewed five of the attendees independently. I believe the intent to offboard came from Marty, prior to this meeting on August 26th. Coordinating operators to take over on-call also started on August 26th.
I believe that if this meeting hadn't happened, some details may have changed, but the outcome would have been the same. However, not all present at the meeting would have known all of those pieces or come to the same conclusion.
Hiroshi was not at that meeting, but spoke to Marty at the conference. Marty did not request GitHub access at RailsWorld.
Overall, RV and André's involvement was a very popular "hallway track" topic, as it was released so recently. I had not yet joined Ruby Central, but I saw Marty, and I asked him about RV at the conference. Marty confirmed that RV was not a Ruby Central project. He didn't share any information regarding André's resignation from Ruby Central or access to RubyGems.org.
**September 5, 2025**
- Samuel Giddins' employment notice took effect, and he was no longer employed at Ruby Central.
- Last day of RailsWorld conference.
**September 8, 2025**
- André follows up with Marty on his proposal to cover secondary on-call with access to the RubyGems.org logs.
**September 9, 2025**
- Marty talked to Colby Swandale and Deivid Rodriguez about Sam and André leaving Ruby Central and their access permissions.
Both Colby and Deivid were paid part-time by Ruby Central. Colby is a paid part-time contractor who primarily works on the RubyGems.org service and codebase, while Deivid was the number one contributor to Bundler by commits. All of the self-described **the maintainers** have a financial relationship with Ruby Central in addition to their unpaid volunteer contributions.
Marty reported back to the committee:
> *“I have a quick update. Both Colby and David are not supportive of pushing André out on the OSS side of RubyGems without his consent. Removing André's access to the service does not seem to be an issue, so I'm proceeding with that planning.”*
A committee member clarified on the "pushing out" framing:
> *“We are not "pushing André out on the OSS side of RubyGems". I think that framing is wrong. André can continue to be a maintainer of RubyGems/Bundler as an open source contributor/committer, I have no problems about that. However, him having ownership of the organization and repos is not acceptable for the organization that is ultimately responsible for the security and reliability of those tools. In that sense, we are trying to make sure the repos have better homes in `ruby` and `rubycentral` orgs respectively. \[September 10, 17:01 UTC out of order, but wanted to mention it in case people stopped reading too soon\]*
> *The risk of handling operations in a world where André and Samuel don't have access to our ops is a risk I am willing to take, considering we can bring in people like \[contributor\], \[another contributor\], etc, into the fold if/when necessary. IMO, it is more important to swiftly and publicly cut ties with the folks that have already committed (semi-)publicly that they want to have nothing to do with RC, than worry about incidents.”*
The link between GitHub access and production access is not enumerated. As Deivid Rodriguez does not operate the RubyGems.org service, he wouldn't have known about the link between GitHub access controls and production server admin. Colby is more familiar with the service and would have known.
Another OSS Committee member responds:
> *“Now that you have already discussed with Colby & David \[...\], I can guarantee you that André & Samuel already know. You should expect and be prepared for retaliation, be it a blog post that might post or that they remove your access from the repos. \[September 9, 2025\].”*
At this point, it was clear to the OSS Committee that even though André and Sam had "left Ruby Central," they did not want to reduce their permission levels. A sentiment that is consistent with most Ruby Open Source projects, where access is granted and rarely revoked. For example, [https://rubygems.org/gems/resque](https://rubygems.org/gems/resque?ref=rubycentral.org) still has the founders of GitHub as gem owners on it, even though they've not pushed a new release for a very long time. For a community library, access is usually considered a "reward" and "earned."
RubyGems.org and other package registries are faced with an increased surface area of supply chain attacks. An extremely public [NPM supply chain attack](https://www.trendmicro.com/en%5Fus/research/25/i/npm-supply-chain-attack.html?ref=rubycentral.org) happened at roughly the same time as these access changes were happening (September 15, 2025). While this attack was not known to Ruby Central when the first access change occurred, the attack vector is one they were worried about: A targeted phishing campaign compromised a maintainer's access tokens. Ruby Central is actively engaged with [openssf.org](https://openssf.org/?ref=rubycentral.org) and specifically their [Principles for Package Repository Security](https://repos.openssf.org/principles-for-package-repository-security.html?ref=rubycentral.org), and is currently working towards level 3 security maturity.
With that context, Ruby Central (OSS Committee and Director) desired an access model closer to that of a professional organization, like the one I work for at my day job. I hold admin rights of a repository that I maintain, but do not have admin rights over the whole organization. With this strategy, the foundation can audit access and fully own completing offboarding from the RubyGems.org service. This strategy was a change from how things previously worked under other directors. The OSS committee believed that reducing Sam and Andre's access levels (at all, even temporarily) would be perceived as a demotion that risks retaliation.
The timeline of access changes is below, but to understand them fully, you need to understand what a GitHub Business/Enterprise is.
## GitHub Business/Enterprise explanation
Most GitHub repositories live under an organization. For example, `github.com/zombocom/rack-timeout` is the `rack-timeout` repository that lives in the `zombocom` organization. There is another hierarchical level that can contain many organizations, which is known as either a Business or an Enterprise. Most GitHub users aren't familiar with this level. I've been writing Ruby code since 2006, and I've never encountered it. It looks like this:
```
GitHub Business/Enterprise
└── Organization(s)
└── Repositorie(s)
```
For the RubyGems GitHub Business/Enterprise, it holds a nearly empty `bundler` organization and the `rubygems` organization with many codebases:
```
RubyGems GitHub Business/Enterprise
└── github.com/bundler [Organization]
| └── github.com/bundler/.github
└── github.com/rubygems [Organization]
├── github.com/rubygems/rubygems.org
├── github.com/rubygems/shipit
├── github.com/rubygems/terraform
├── github.com/rubygems/rubygems-mirror
├── [...]
└── github.com/rubygems/bundler-site
```
The RubyGems Business/Enterprise account was created by Hiroshi Shibata, `hsbt`, who promoted the then current admins on the RubyGems organization to admins on the enterprise.
Confusingly, GitHub has another product called "GitHub Enterprise," which is different; that's a product that allows you to run a self-hosted version of GitHub on your own infrastructure. When "Enterprise" is used, it is in the "Business" context. These changes will show up in access logs with a prefix of `business`.
In addition to these levels, organizations also have teams as a way to control permissions.
## Incident timeline
This section was reconstructed based on [audit logs from the enterprise account](https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/audit-log-events-for-your-enterprise?ref=rubycentral.org). The ability to audit access logs was not previously available for the OSS Director and the OSS committee. This was resolved when Marty gained access to the enterprise/business account.
**September 9, 2025** (continued)
- Marty requested Hiroshi Shibata `hsbt` make GitHub access changes on behalf of Ruby Central.
**September 10, 2:23:49 UTC** by `hsbt`
- business.remove\_admin: `indirect, segiddins, martinemde`
- business.invite\_admin: `mghaught`
**September 10, 2025, 3:32:27 UTC** by `hsbt`
- org.update\_member: `indirect`, `segiddins, martinemde` before: admin, after: read
- org.update\_member: `deivid-rodriguez`, before: read, after: admin (note that access increased)
André and Samuel were removed from the business, and their organization permissions were downgraded at the request of Ruby Central. Marty (OSS Director) was added to the business.
Hiroshi stated that Martin was granted this permission in 2023 by André, but he didn’t know why at the time. So, he reverted Martin’s Business/Enterprise owner status.
At this time, they could not transfer repositories outside of the organization, but they still had admin access to the RubyGems and Bundler repositories. They also still had the capacity to run [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) operations (such as deploying the service) through their team access.
Hiroshi believed that Deivid Rodriguez's access level was too low for the level of work he was performing, and increased his organization's access to admin.
This removal of `indirect`, `segiddins`, and `martinemde` was characterized externally as “a mistake,” but the only mistake was the timing, which was not properly communicated by Marty to Hiroshi.
**September 10, 2025**
- Message shared in Slack by Hiroshi with the RubyGems developers:
> *“I’m reviewing account permissions for rubygems now. I’ve assigned enterprise and org owner roles to only Marty, Colby, Deivid and me. The repository admin roles remains unchanged. Please let me know if you encounter any problems.”*
André asked why his permissions were downgraded in a DM, and Hiroshi shares:
> *“\[...\] Because you are \[leaving\] Ruby Central now. Owner can access billing and account control. I would like to align to minimum permission around that.”*
**September 11, 2025**
- OSS Committee Slack, Marty shared an update:
> *“\[...\], Colby, David Rodriguez, and hsbt are the owners in RubyGems. hsbt, Colby, and me are the enterprise owners. Team access is still the same but with a quick check André only has member access in the places I've checked.”*
Committee members asked for clarification on the commit status. Marty responds:
> *“Let's discuss this tomorrow. Forcing André out is likely to cause the team to defect. Removing his administrative abilities less so. I can share my thoughts on ways to keep him from blocking changes.”*
**September 11, 2025**
- André follows up with Marty on his proposal to cover secondary on-call with logs.
**September 14, 2025**
- Martin proposes a Governance RFC via PR [https://github.com/rubygems/rfcs/pull/61](https://github.com/rubygems/rfcs/pull/61?ref=rubycentral.org) aimed at restoring access.
That RFC creates an “owner” definition, described as “A person with enterprise or organization owner permissions on GitHub for RubyGems/Bundler projects,” which would mirror the GitHub enterprise/billing owner. The high-level idea was to leave permissions as they were, but create a voting mechanism for removing permissions outside of “inactivity.”
While they didn’t know all the specifics of what Ruby Central desired (when they first drafted the RFC), they knew it had something to do with limiting access and thought this document would afford them the ability to have an official way to ask for permission/access removal, such that the OSS Director wouldn't need it directly.
Ruby Central wanted to make access control finer-grained and split [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) production server access controls out from the rest of the repositories. The top suggestion within the OSS committee was to move bundler/rubygems into the `github.com/ruby` organization.
**September 14, 2025**
- Andre stated he would seek someone else to restore his permissions, whether Ruby Central approved it or not.
- Upon hearing this ultimatum, the OSS director was alarmed. He expressed concerns internally about the possibility of not knowing who had access, or being removed in retaliation (or both). Ruby Central was not told who Andre expected to restore his access. This left a lingering doubt on all who held that structural access of whether or not they would assist Andre.
- For lack of a better word, there was a "truce" between the parties.
- Those who had been previously removed were asked not to remove Marty or Hiroshi.
**September 15, 2025, 8:59:39 UTC** by `hsbt`
- The ability for enterprise members to delete repositories was turned off. Members cannot delete or transfer repositories in any organization in an enterprise at this time.
**September 16, 2025, 1:51:29 UTC** by `hsbt` at the request of Ruby Central
- org.update\_member: `indirect`, `martinemde, segiddins` before: read, after: admin
- business.invite\_admin: `indirect, martinemde, segiddins`
- business.invite\_admin: `deivid-rodriguez`
All access was returned to `indirect`, `segiddins`, and `martinemde`. Permissions for `mghaught`, the current OSS Director, and `deivid-rodriguez` gained on September 10, 2025, remained.
A meeting was scheduled.
**September 17, 2025**
- There was a Zoom meeting with Marty.
- The meeting was recorded by Ruby Central, a practice consistent with other "maintainer sync" meetings, for the purpose of privately sharing with maintainers who could not be present.
- André and Martin produced a list of thirteen developers who were invited. Five attend, and four speak: André (`indirect)`, Josef (`simi)`, Ellen (`duckinator)`, Martin (`martinemde)`.
- Two of these five had access changed (`indirect` and `martinemde`).
- Sam Giddins and Deivid Rodriguez did not attend.
- These four developers make it clear that they reject a Ruby Central employee retaining any access to the [github.com/rubygems](http://github.com/rubygems?ref=rubycentral.org) GitHub organization or enterprise.
- They state their expectation that someone must gain administrative control via performing code contribution, and then, based on an internal selection criterion, only those who already have it will decide whose individual merit deserves administrative access to the `github.com/rubygems` organization or not.
- They express that they’re unhappy that Ruby Central hired a new contractor instead of offering work to one of them.
- Many alternatives are floated, and the developers acknowledge that private code and controls are intertwined in the public GitHub organization. They suggest that Ruby Central can fork the Ruby Gems repos that are needed for private control and access.
- Overall, the conversation is awkward and strained.
Context not present in the meeting: André and Martin were former acting OSS Directors and had `github.com/rubygems` organization and enterprise controls at the time. Prior to that, it was held by Evan Phoenix on behalf of Ruby Central until February 28, 2025 when it was removed by André Arko. So, they are not opposed to “Ruby Central” or the OSS Director having that control; they are opposed to someone getting that control without their input or buy-in as current Business/Enterprise admins.
**September 17, 2025** (cont.)
- After the public call, André met with Marty one-on-one and stated that he would quietly leave in exchange for a license to access and resell the RubyGems.org logs.
**September 17, 2025** (cont.)
- Marty released the video of the developer call to the OSS Committee members.
- The RFC from Martin was shared with the OSS Committee members.
- An OSS Committee member responded to the video privately in Slack:
> *“This call is mind-boggling to me. The lines between open-source work and paid work are blurry as hell and we need to fix this ASAP. \[...\]”*
**September 18, 2025**
- Ruby Central Board meeting
On September 18th, there was a board meeting where an official decision was made on offboarding Sam and André. They decided to remove production access, including control of the `github.com/rubygems` organization, and their ability to commit. At the time, Ruby Central lacked legal agreements with all operators regarding their access to production servers and data.
It was thought that after offboarding efforts were finalized, they could work together to disentangle GitHub access. Ruby Central’s plan was to eventually present them with legal “operator agreements,” which would be enough to alleviate Ruby Central’s concerns and restore commit access. Followed by resolving proper homes for all repositories.
Internally in Ruby Central, the decision to remove commit access was met with dissension and debate. GitHub team access and Shipit access were explicitly talked about in the September 18th board session, but the full implication of that access (that it effectively meant that GitHub access and production infrastructure access were connected) was not fully spelled out.
This would mean that those with prior knowledge of those systems believe everyone understood the full links between access changes to `github.com/rubygems` and the RubyGems.org server, while those who were new to the information wouldn’t have intuitively understood all of the connections. Some felt that this was clearly a line too far, and some argued that their concerns merited an extended loss of access.
Due to the lack of a prior documented onboarding or offboarding procedure (runbooks), there was uncertainty around the minimum acceptable access changes to remove all [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) production server access.
**September 18, 2025, 17:56:19 UTC** by `mghaught`
- business.remove\_member: `indirect`, `segiddins, martinemde, deivid-rodriguez`
André and Sam are removed from the business again. From prior conversations, there was a worry that others would add their permissions back without warning, so while Martin is not being offboarded, his access is reduced. Deivid did not have business admin access prior to September 10th, and this change was an attempt to revert to that state.
When I came to Ruby Central, I was unfamiliar with the business/enterprise access level. So I did not know, as Marty didn't, that this action of removing a member here would remove them entirely. This total loss of access included all teams and repositories. This was a mistake. This action cannot be undone. Someone removed from a business must be invited back, and that person must accept.
While Ruby Central intended to remove commit access from André and Samuel temporarily, they did not intend to remove them completely from the business. Now, before any access can be given back, they need to be invited back to the org and accept. Their complete removal from the org was a mistake.
Further, Deivid was not supposed to have his access reduced below the September 10, 2025, levels. This was a mistake.
**September 18, 2025 18:04 UTC**
- Off-boarding emails sent to André and Sam from Marty.
- Both are similar. Here is the body of one:
> *“After consultation with the OSS Committee and the Ruby Central board, we have removed your RubyGems.org production access, given your departure from Ruby Central. We’re also pausing the on call rotations while we work through this transition. Please send a prorated invoice for on call services.*
> *I believe there are two remaining service accounts I never transferred, PagerDuty and HelpScout. I’d appreciate it if you’d transfer ownership to my email at your convenience.*
> *I’m deeply grateful for all you’ve done for the RubyGems and our community. I will be meeting with the OSS Committee shortly so I can resolve any open conversations.”*
Both emails contained a rationale for the access loss, but it was limited. Neither message acknowledged the GitHub access changes. Changes to commit access should have been listed along with the intention that those changes were intended to be temporary.
A strong concern from the start was that Ruby Central would lose developers beyond the two who were offboarded, due to a walkout. Rather than being direct and clear with actions and their motivations, Ruby Central tried to avoid the impression of conflict in hopes that others of **the maintainers** would not resign.
No other emails were prepared or sent to the other developers whose access was affected or their peers who still retained access. There were messages in Slack, but this communication was not pre-prepared.
**September 18, 2025 18:47 UTC**
- Email sent to `indirect`, `martinemde`, `segiddins`, `deivid-rodriguez`, by Marty:
> *“I'm terribly sorry about the GitHub removal. I messed up, and I accidentally removed all org access instead of downgrading. This is temporary as I work to fix the permissions structure. Martin's been helping me with this.*
> *I was forced by the board to take this action due to legal risk to Ruby Central. We're actively exploring how to move the specific repos (terraform, shipit, GitHub team control) out and adjust team control so that RubyGems, the code base, and GitHub organization can be controlled by least privilege by the agreed governance.*
> *I'll follow up more on this and engage with the governance rfc in good faith.”*
An email was sent apologizing for the mistake of removing developers from the GitHub organization. This apology was for the mechanics of the access removal, but not the intent.
Martin requested that Marty restore his permissions, and he would assist with restoring the rest. Marty inexplicably didn't see the controls he expected to invite someone to the `github.com/rubygems` organization. Martin was unable to identify the problem either. While being removed from a business/enterprise is inherited by the organization, being added as an admin is not. The issue was that he had to grant himself organization access, which he had not done.
**September 18, 2025, 21:45 UTC**
- A message from Marty to Colby asking for help restoring access to Samuel, Martin, and Deivid.
Colby was not directly involved in any of the GitHub removals and received the same communications as other team members. He was asked to help correct the accidental removal from the GitHub Business/Enterprise. Colby is in the AEST (Australia) time zone, so this was very early in his day (7:45 am). This request took some time to respond to.
**September 18, 2025, 23:17:32 UTC** taken by `hsbt`
- business.invite\_admin: `paracycle`
A Ruby Central board and OSS Committee member, Ufuk, was granted enterprise and organization access. He was asked to assist with access changes. This occurred roughly five hours after the `business.remove_member` changes went into effect.
**September 18, 2025, 23:19:49 UTC** taken by `mghaught`
- org.update\_member: `mghaught` before: read, after: admin
The permissions issue with the Enterprise/Business was diagnosed and resolved. With this change, Marty could send out invites to the organization. However, communication in this time period between `business.remove_member`, and now could be described as a [conflict cycle](https://www.chadleyzobolastherapy.com/blog/the-cycle-why-couples-fight-from-an-eft-lens?ref=rubycentral.org) where attempts to avoid conflict by one side have the opposite reaction and can perpetuate the cycle. While both sides share some similar goals and objectives, the built-up tension, lack of trust, and unclear communications prevented closure or repair.
Various grievances around how things unfolded would be added. The talks for resolution were counterproductive, and they ultimately pushed both parties further apart.
From this point forward, communication or requests/attempts to “restore all access” are interpreted by Ruby Central as including production access and therefore as attempts to reverse off-boarding measures and effectively take control of the service. From the point of view of those removed, Ruby Central had just kicked them out for a second time; whether the specific mechanics involved were intended or not wasn’t important, or wasn’t even believable, given the earlier hiding of motivations.
**September 18, 2025, 23:21:19 UTC** taken by `colby-swandale`
- org.invite\_member: `martinemde`
Colby responded to Marty’s earlier message by inviting Martin back to the organization. He then requested more details from Marty and was asked to pause the task. Martin would have received the invitation at 4:21 pm (16:21) his local time.
**September 18, 2025, 23:31:42 UTC** taken by `paracycle`
- team.remove\_member(s): `rubygems/maintainers`
These changes were based on the previously stated risk that someone would add offboarded members back unexpectedly. Other changes were made based on inactivity.
Ellen Dash, `duckinator`, lost admin access to repositories in the `github.com/rubygems` organization due to removal from `rubygems/maintainers`. In addition, four other members were removed from the `rubygems/maintainers` team with the most recent commits to the `github.com/rubygems` organization in 2022, 2021, 2018, and 2016 (due to inactivity).
Notably, Josef Šimánek, `simi,` retained `rubygems/maintainers` team membership at this time.
**September 18, 2025 23:35:15 UTC** by `hsbt`
- org.cancel\_invitation: `martinemde`
**September 18, 2025, 23:38:02 UTC** by `paracycle`
- team.remove\_member(s): `rubygems/infrastructure`
- team.remove\_member(s): `rubygems/rubygems-org`
- team.remove\_member(s): `rubygems/rubygems-org-deployers`
- team.remove\_member(s): `rubygems/security`
The `rubygems/rubygems-org-deployers` team gates access to deploy RubyGems.org via Shipit. The `rubygems/rubygems-org` team gates access to the [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) admin panel. Users with admin access to that panel have significant capabilities such as: modifying owners on gems, blocking users, yanking gems, resetting credentials, managing feature flags, running arbitrary SQL queries, and running maintenance tasks.
All of these team-level access changes affected a total of fifteen developers, including `duckinator`. Aside from `duckinator,` who had been recently active in 2025, most changes were made due to inactivity. The remaining fourteen developers last contributed to `github.com/rubygems` in the year:
- 2022 (3 developers)
- 2021 (3 developers)
- 2019 (1 developer)
- 2018 (1 developer)
- 2016 (3 developers)
- 2015 (1 developer)
- Never, zero commits (2 developers)
You can see a list of the [github.com/rubygems](http://github.com/rubygems?ref=rubycentral.org) organization members and their activity levels in Mike McQuaid’s post, [RubyGems Contribution Data with Homebrew's Tooling](https://mikemcquaid.com/rubygems-contribution-data-with-homebrews-tooling/?ref=rubycentral.org) (September 24, 2025).
**September 19th, 2025 1:53:25 UTC** by `hsbt`
- org.invite\_member: `deivid-rodriguez`
While most access changes have been about removal, the access of `deivid-rodriguez` has been consistently increased. However, removal from an organization cannot be reversed; you must re-invite them, and they must accept. Deivid was invited back again.
**September 19, 2025, 5:01:10 UTC** by `hsbt`
- repo.remove\_member `rubygems/bundler-site`
This included one bot and three developers who last contributed to the bundler site in 2023, 2020, and 2016.
**September 19, 2025, 8:59:40 UTC** by `hsbt`
- org.remove\_member: `duckinator`
This was the last organization removal via Ruby Central.
At this time, `simi` retained access, but the rest of **the maintainers** are no longer in the organization. None of those affected were contacted with an explanation of why the changes had been made.
**September 19, 2025**
- One of the earliest timestamps of a [social post linking](https://narrativ.es/@janl/115230600677063843?ref=rubycentral.org) to "Ruby Central's Attack on RubyGems" (originally posted Sep 19, 2025, 05:57 AM CST and updated over time)
- [Wayback link to "Ruby Central's Attack on RubyGems"](https://web.archive.org/web/20250701000000%2A/https://pup-e.com/goodbye-rubygems.pdf).
The first public description of the incident is published by `duckinator`, though they did not yet name a concrete group or adopt the label **the maintainers**. At the time, Ruby Central had not delivered any description of the situation internally beyond those who played a part in it directly.
Ruby Central found itself in a similar situation to the September 10th, 2025, enterprise/business access changes, where they struggled to explain their motivations without discussing personnel matters. Later that day, Ruby Central would release a [blog post](https://rubycentral.org/news/strengthening-the-stewardship-of-rubygems-and-bundler/) that did not directly address the `duckinator` sequence of events laid out or the “takeover” claims.
A key point in the post said:
> *“In the near term we will temporarily hold administrative access to these projects \[...\].”*
Ruby Central would be unable to return any of the administrative access (or any access) to **the maintainers** without their participation. At this time, there have been two invitations delivered, and one canceled, which leaves one outstanding (`deivid-rodriguez`). Zero invitations have been accepted. In addition, Ruby Central would not relinquish administrative access to the `github.com/rubygems` organization.
In this time period, there were public blog posts by many of **the maintainers**. There were limited and sporadic private communications. Like before, these conversations were unproductive at best, counterproductive at worst. Ruby Central would not be restoring access controls to their state prior to September 10th, and **the maintainers** would not accept anything less.
**September 23, 2025, 20:28:03 UTC** by `simi`
- org.remove\_member: `simi`
This removal of `simi` was self-imposed as a protest after continued talks proved to be unproductive. Prior to this time, none of his access had been changed by Ruby Central.
**September 24, 2025 1:07:58 UTC** by `hsbt`
- org.cancel\_invitation: `deivid-rodriguez`
Deivid indicated in Slack that he would not be accepting the invitation, so it was canceled. The sentiment inside of Ruby Central was that they had “walked away.” This was later validated by a conversation with one of **the maintainers**.
> *“just reflecting a bit, I’m a little surprised you didn’t know that we all walked out on \[Ruby Central\]. That’s the whole situation. This was “you f\[...\]d up that bad and you want us to come groveling back to you, no” \[January 2, 2026\]”.*
As of September 24, two of the original community owners retained organization controls: `hsbt` and `colby-swandale`. Two added members, the Ruby Central Director of Open Source, `mghaught,` and a then Ruby Central Board member, `paracycle`, retained control on behalf of Ruby Central. None of **the maintainers** had membership in the `github.com/rubygems` organization nor any outstanding invitations.
Ufuk’s access was later passed to another board member when he left the Ruby Central board.
## Conclusion
Some execution failures and mistakes are individual, but the purpose of having a foundation and having an institution is that it can rise above individual limitations and provide robust, fault-tolerant systems. Therefore, these are our mistakes, collectively. And collectively we'll learn from them, but only if we face what happened, what we meant to do, and where we fell short.
The hope is that by sharing this, we can provide some closure to the community and increase transparency. It's also been a time to reflect internally and understand deeper issues that led up to this situation. You've likely been witness to some effects of this process, even if they seem mundane or unrelated. We have been going through a period of structural change, and that process will continue. It will not happen overnight. We want to face this and learn from it. You're welcome to judge us by our actions, and we hope you keep [calling us in](https://www.schneems.com/2025/12/19/non-violent-comments-calling-out-or-calling-in/?ref=rubycentral.org) and calling us out when we don't live up to expectations.
## Updates
- September 2, 2026 - Correct the count of developers André updated in the org (`org.update_member` before: admin, after: read) from five to eight.
- September 1, 2026 - List the removal of Evan Phoenix `evanphx` in the same format as the other GitHub changes and place it in the correct timeline sequence. Add a paragraph of context to the removal.
- March 31, 2026 16:33 UTC - Typo fix: Samuel's name was spelled incorrectly. It is now corrected to "Samuel Giddins."
### A Message from the Ruby Central Board
URL: https://rubycentral.org/news/a-message-from-the-ruby-central-board/
Last updated: 2026-03-28T17:00:30.000Z
Over the past several months, there has been significant discussion, disagreement, and concern about RubyGems, Bundler, and Ruby Central’s role in stewarding RubyGems and supporting the Ruby ecosystem.
Because this matter has involved ongoing legal discussions, we have been limited in what we could say publicly. Our priority has been to resolve the situation responsibly and avoid escalating a conflict that affects the broader Ruby ecosystem.
With several new board members joining Ruby Central in recent months, it has also taken time to come up to speed on a complicated situation and begin charting a path forward.
Ruby Central’s actions during this period were taken in response to a breakdown in a working relationship with an individual who had significant access to infrastructure and code. Our responsibility is to protect the stability and security of services that the Ruby ecosystem depends on, including RubyGems.org.
At the time, we believed a serious risk had been introduced to RubyGems and related services. As stewards of services relied upon by millions of developers, we took that risk seriously and made the decision to act quickly to protect that infrastructure.
A full, independent security audit has now been completed. The review was ultimately inconclusive because key logs required for a complete analysis were no longer available. We recognize that this creates continued uncertainty.
A detailed incident report will be published next week to provide additional context on what occurred, who was involved, and how decisions were made.
Our intent was to stabilize a situation that was quickly escalating to work toward an amicable resolution. Ruby Central did not initiate litigation and has consistently sought a path that would allow the community to move forward without prolonged conflict.
At the same time, we recognize that aspects of how this situation was handled and communicated did not meet the expectations of the community. Decisions were made quickly, and we did not engage the existing maintainers or the broader community in the way we should have. This created confusion and frustration, and we take responsibility for that.
Ruby Central’s mission is to support and sustain the Ruby ecosystem and the infrastructure it relies on. The Ruby ecosystem has thrived for decades because of the contributions of maintainers, volunteers, companies, and community members across the world, and Ruby Central is committed to ensuring that stewardship of RubyGems reflects that collaborative spirit.
Looking forward, we want RubyGems to be shaped and supported by a broader group of maintainers, contributors, and companies so that no single person or organization is ever a point of failure.
In the coming weeks, we will share concrete steps we are taking to strengthen governance, improve transparency, and expand community participation in the stewardship of RubyGems. We will also outline how we plan to work more collaboratively with maintainers and the broader community to improve RubyGems and support continued innovation across the Ruby ecosystem.
We, as a Board, are committed to ensuring RubyGems remains stable, secure, and a strong foundation for the Ruby community. We are committed to working together to build a stronger and more resilient future for RubyGems.
*Freedom Dumlao, President*
*Brandon Weaver, Secretary*
*Ran Craycraft, Treasurer*
*on behalf of the board and in support of the staff and volunteers of Ruby Central*
### Ruby Participates in Google Summer of Code
URL: https://rubycentral.org/news/ruby-participates-in-gsoc-2026/
Last updated: 2026-07-10T14:00:03.000Z
We're excited to announce that Ruby will participate in[ Google Summer of Code (GSoC) 2026](https://summerofcode.withgoogle.com/programs/2026/organizations/ruby?ref=rubycentral.org)! This program offers new open source contributors the chance to work on impactful projects supporting the Ruby ecosystem, such as RubyGems.org, RubyGems, and Bundler, with guidance from experienced mentors.
[Google Summer of Code](https://summerofcode.withgoogle.com/?ref=rubycentral.org) is an annual program run by Google that pairs open source organizations with new contributors (18+ years old with less than two years of open source experience). Contributors receive a stipend from Google to work on a defined project over roughly 12 weeks.
### **How to get involved**
Our[ contributor wiki](https://github.com/rubygsoc/rubygsoc/wiki?ref=rubycentral.org) has everything you need to get started: project ideas, guidance on writing a strong proposal, and information on what to expect from the program. We encourage potential contributors to read through the ideas list, start exploring the codebases, and, most importantly, reach out early. The more you engage with the community before submitting your proposal, the better positioned you'll be.
We also have a [**Discord server**](https://discord.gg/XaeDdtwh?ref=rubycentral.org) where mentors and potential contributors are already gathering to discuss project ideas. Join us there to introduce yourself, ask questions, and start building connections with the team.
### **Key dates**
- **March 16 - 31, 2026** \- Contributor application period
- **April 30, 2026** \- Accepted contributors announced
Don't wait until the deadline to start conversations. Reach out now, explore the project ideas, and come say hello on [Discord](https://discord.gg/XaeDdtwh?ref=rubycentral.org). We're looking forward to a great summer of open source contributions to the Ruby ecosystem!
### The Ruby Central README: January 2026
URL: https://rubycentral.org/news/the-ruby-central-readme-january-2026/
Last updated: 2026-01-30T17:10:11.000Z
### January 2026 README
Our January README newsletter is live!
Inside: highlights from the Fundraising Gala, Awards & Honorees, Ruby news, introductions to our new Ruby Central Board members, volunteer spotlights, and a supporter feature with GitButler.
Check out our January 2026 README here: [https://buff.ly/MPIPdSW](https://buff.ly/MPIPdSW?ref=rubycentral.org)
### The Ruby Central README: December 2025 + Annual Report
URL: https://rubycentral.org/news/the-ruby-central-readme-december-2025-annual-report/
Last updated: 2026-01-05T22:15:27.000Z
**Happy New Year** to the Ruby Community and wishing you all a safe and gentler 2026\.
### December 2025 README
In case it was missed, we released our December 2025 README Newsletter at the end of the year. It includes highlights from our 2022–2024 Annual Report, Ruby 4.0’s launch (and a lovely message from Matz), new local regionals, and more. [You can view the newsletter here](https://mailchi.mp/f1b4152f30f0/the-ruby-central-readme-december2025-newsletter?ref=rubycentral.org).
---
### Annual Report
Included in the latest README, we've included information about our Annual Report release.
This **Annual Report covers 2022–2024** and has been in the works since early 2024\. Our goal is straightforward: put three years of work, funding, and decisions in one place so the community can see what Ruby Central has actually been doing and where we’re trying to go next. You can view the Annual Report on the [Support](https://rubycentral.org/support/) page.
---
We will be updating a lot in various areas within the organization, so keep a look out here, on our socials, and newsletters for the latest news and updates from us.
### Ruby Central Weekly Update – Friday, November 14, 2025
URL: https://rubycentral.org/news/ruby-central-weekly-update-friday-november-14-2025/
Last updated: 2025-11-14T22:00:44.000Z
As we head toward the end of the year, this will be our final weekly update before we return to our monthly newsletter cadence. This change allows our small but mighty team to focus time and attention on producing more in-depth, thoughtfully prepared communications.
A reminder that Board of Directors [applications](https://rubycentral.teamtailor.com/jobs/6723164-ruby-central-board-member?ref=rubycentral.org) remain open through **November 21, 2025**. We encourage community members from all backgrounds to apply and take part in shaping Ruby Central’s future.
As a U.S.-based organization serving a global Ruby community, we welcome board applicants from anywhere in the world. Three of our six current board members are internationally based, and we remain committed to global representation.
### **Open Source Update**
We’re excited to welcome Cloud Security Partners to the Open Source team!
They will be conducting a security consulting engagement focused on assessing the security posture of our AWS environment, evaluating current configurations, access controls, and operational practices to identify potential risks, misconfigurations, and areas for improvement.
We’re excited to have their expertise and will share updates on the outcomes of this assessment in the coming weeks.
### **Asynchronous Q&A**
While this week’s update is shorter, we wanted to share a few final clarifications before our next full newsletter. The majority of recent Q&A submissions have come from a single individual, and include a number of repetitive or highly detailed questions not suitable for this quick update format. As previously noted, each weekly update highlights and answers only a few questions to ensure the responses remain clear and constructive.
We appreciate the time and thought put into those questions, most community concerns raised over the past several weeks have now been addressed. We’ll continue responding to new submissions monthly through the newsletter.
**Question 1**: If transparency is a core tenet for community trust, why doesn't Ruby Central release its bylaws publicly? Python Foundation, Linux Foundation, Apache Foundation and Rust Foundation all have public bylaws.
**A**: While it is not required by law for 501(c)(3)s to make their bylaws public, it is a pretty standard practice that many organizations show these publicly for transparency and trust with the communities they represent.
We completely agree, and we would like to make these documents public on our homepage. We are currently working on rebuilding our entire Ruby Central website from the ground up. We would like to include spaces that would not only explain clearly our mission and values, what programs we facilitate and organize, how people can get involved, but also provide these structural documents that would make it clear our organization functions as a whole.
For historical context, the website was made very quickly some years ago, so that we would have an online presence. There was little to no effort put into actually building out the site into a proper institutional website where anyone can navigate and find the who, what, where, when, why, and hows. There isn’t a single person who had “expertise” in building, designing, or coding our current website which also has added additional challenges and blockers, but we are now working through. A lot of those structures should have been in place and unfortunately nothing was done until very recently.
With yours and other community members’ input on what you’d like to see on our public facing site in regard to transparency, we are actively working on this. We ask the community for patience and grace as we try to get this done as soon as we can, knowing our limitations.
**Question 2**: In your Nov 7 update, you announced that Richard Schneeman (/u/schneems) has joined the Open Source Committee for Ruby Central.
In my view, this is a positive step forward given Richard's track record both within OSS development and in his community involvement.
Because he is a moderator of both /r/ruby and /r/rails on Reddit, and Reddit is one of the largest and most visible open conversation forums related to Ruby, it's important to address any potential conflicts of interest that may arise there.
The most simple way to do that would be for Richard to recuse himself from any moderation activities related to discussions of Ruby Central, of which he has historically participated actively and constructively in. And from here on out, it'd be wise for him to disclose his affiliation in any of these related threads.
What if any agreements, formally or informally, have been made to address these overlapping responsibilities? Seeing some thought put into this and some commitments put on public record would go a long way towards showing that Ruby Central is actively gaining an increased awareness of power dynamics in open source communities as well as a willingness to structurally address potential conflicts of interest beyond minimum legal compliance to focus on what's truly in the interest of the community you serve.
**A**: Richard responded, in the most Reddit way possible, via a [Reddit comment](https://www.reddit.com/r/ruby/comments/1or6loi/comment/no45aaq/?context=3&ref=rubycentral.org). He’s also in talks with other Reddit moderators to bring on more help from long-term /r/ruby contributors to balance out the load.
**Question 3**: I recognize that the specific details of individual Ruby Central board members' conflict of interest disclosures may not be shared on public record for privacy reasons.
But in the interest of transparency and to give the Ruby community a clearer picture of the recent composition of Ruby Central, can you provide the following information?
**A**:

### **Closing & Next Steps**
This concludes our weekly update series. Thank you for following along, engaging thoughtfully, and helping shape a stronger, more transparent Ruby Central. We look forward to continuing these conversations through our monthly newsletter, where we’ll share updates on governance, programs, and upcoming community events.
*This was a collaborative effort from all of the Ruby Central Board and Staff.*
### Ruby Central Update Friday 11/7/25
URL: https://rubycentral.org/news/ruby-central-update-friday-11-7-25/
Last updated: 2026-03-04T19:15:38.000Z
Thank you for staying engaged as we move forward together. We value your feedback and encourage your input at every step. Next week, we will share one more Friday update, after which our Open Source and README newsletters will resume on their previous schedule.
Your questions, submitted via the asynchronous Q&A form, will continue to guide our content and conversations. We are excited about next year’s live events and look forward to sharing all the details in the coming weeks.
**Applications Open: Ruby Central Board of Directors**
We are inviting applications for two open Board of Directors seats, starting with the new year. Our board guides the strategic direction of both Ruby Central and the broader Ruby community, overseeing conference planning, open source stewardship, and year-round programs that support Rubyists everywhere.
If you’re passionate about Ruby and excited to make a meaningful impact in our community…
[Apply Now!](https://rubycentral.teamtailor.com/jobs/6723164-ruby-central-board-member?ref=rubycentral.org)
Applications will be open until **November 21, 2025**.
**Help Shape Ruby Central’s Future: Feedback Survey Coming Soon**
Ruby Central’s renewed vision for community development and growth will be built together with input from across the Ruby community.
Earlier this year, Executive Director Shan Cureton’s Listening Tour and our Let’s Build Together: Ruby Central Community Feedback Form surfaced important perspectives, challenges, and hopes from community members. Now, we’re taking the next step by relaunching the form, which will support our strategic planning in the coming days.
Your voice is essential: survey feedback will directly inform a “Community Blueprint” that guides the direction of governance, programs, and initiatives, all with the goal of advancing Ruby to new and experienced members alike.
Watch your inbox and Slack for the survey link. We encourage members to participate and be part of program development and decision-making.
**Compliance and Administration: Transparent Governance**
Ruby Central is required to complete annual independent financial audits. These audits are not mandated by the IRS for all nonprofits, but are required by many states, certain grantmakers, and our own bylaws to help ensure accountability and financial transparency. The audit process examines our financial statements and internal controls, verifying that our work and stewardship are aligned with our charitable mission and regulatory standards.
The annual audit is nearing completion, followed soon by our required IRS Form 990 tax filings. The documents will be available to the public.
Additionally, we are preparing our first-ever Annual Impact Report, which will be released to the community. This comprehensive report will cover the period from 2022 through the end of fiscal year 2024, providing a clear account of Ruby Central’s activities, achievements, and organizational impact during this period.
Sharing our audit outcomes and impact analysis ensures the community has insight into the scope and effectiveness of our stewardship. We believe making these documents public affirms our dedication to inclusivity, transparency, and a collaborative approach to governance.
**Regional Meetup Grants - Cycle 2!**
We’ve launched our 2nd cycle of regional meetup grants this year for our global Ruby meetups, thanks to the generous support of Github. This program has **awarded 35 grants** this cycle empowering local Ruby communities across **6 continents**!
There are a [few grants left available](https://docs.google.com/forms/d/1cny76dtOhGZsPhvQndajVTL9Dyjb6DLpv0wON-iPcF4/edit?ref=rubycentral.org) in this cycle. By reducing barriers for community leaders, we hope to grow the Ruby ecosystem, strengthen local communities, and help Rubyists discover new opportunities. We are thrilled to know that this program has exceeded our expectations and has been able to be a pillar of support for all of our diverse communities around the world.
**Open Source Updates**
**On-Call:** As previously mentioned, we’re looking to expand our on-call rotation beyond six engineers. The goal is twelve engineers for redundancy in different geographic regions such that all eight-hour shifts can be scheduled during normal working hours (no one on-call gets woken up). We are still filling out the membership of the [EMEA](https://en.wikipedia.org/wiki/Europe,%5Fthe%5FMiddle%5FEast%5Fand%5FAfrica?ref=rubycentral.org) and [APAC](https://en.wikipedia.org/wiki/Asia-Pacific?ref=rubycentral.org) rotations. Interested companies and engineers can get more information on helping by contacting [contact@rubycentral.org](mailto:contact@rubycentral.org).
**Operator agreements:** We’ve received some questions about the operator agreement. This is a key aspect of having the proper legal structures in place to allow volunteers access RubyGems.org production service and its data. These agreements protect our volunteers by explicitly stating Ruby Central assumes insurance for volunteers acting within the scope of their duties, and protect RubyGems.org users by explicitly prohibiting volunteers from downloading and using privileged gem download data. The volunteer agreement and data processing addendum are included below for the community to view.
[Sample Volunteer Operator AgreementSample Volunteer Operator Agreement.pdf396 KBdownload-circle](https://rubycentral.org/content/files/2026/03/Sample-Volunteer-Operator-Agreement.pdf "Download")
[Sample RubyGems DPASample RubyGems DPA.pdf685 KBdownload-circle](https://rubycentral.org/content/files/2026/03/Sample-RubyGems-DPA.pdf "Download")
**Support:** In addition to maintaining the RubyGems.org infrastructure, Ruby Central also responds to support requests submitted through the Help link on RubyGems.org. This week, the team spent some time resolving several older requests from our backlog. Going forward, we expect response times to be dramatically improved.
**Open Source Committee additions**: The Open Source Committee recently onboarded two new members, [Bruno Miranda](https://github.com/brupm?ref=rubycentral.org) and [Richard Schneeman](https://github.com/schneems?ref=rubycentral.org). This committee oversees the management of the staff on matters relating to open source (as opposed to conference or education initiatives). Here's a little about our newest members:
Richard has been a Heroku employee for over a decade and is the current Puma maintainer. Richard also maintains \`ruby/syntax\_suggest\` and a platform, [https://www.CodeTriage.com](https://www.codetriage.com/?ref=rubycentral.org), for helping turn aspiring coders into contributors. Here's what he had to say on joining the committee:
"When I saw the RubyGems and Ruby community fracture, I wanted to find a way to help pick up the pieces. I've worked with Terence Lee (former Bundler maintainer) at Heroku for many years, and worked alongside Evan Phoenix (former RubyGems maintainer) on the Open Source webserver Puma (please upgrade to 7.1.0+). Before this happened, Deivid Rodriguez helped me get a \`bundle list --format=json\` feature merged. I have immense respect and gratitude for the open source maintainers who keep our weird and wonderful language ecosystem up and running. I want to help find a path forward."
Bruno is a Board Member at the Rails Foundation and SVP of Software Engineering at Doximity.com. Doximity is the company behind clinical software used by millions of U.S. doctors, where Bruno has been building software and advocating for Ruby there for over 15 years. In his own words:
“Before Doximity, I wrote C++ full-time, where installing dependencies meant installing OS packages and running \`make\`. In contrast, Ruby's package management ecosystem provides unmatched reliability. I work in healthcare and understand the importance of building critical infrastructure that people rely on. I got involved to apply my leadership experiences to help bring stability to the community.”
Welcome to the team Bruno and Richard!
**Asynchronous Q&A**
**Question 1:** If the community strongly disagrees with Ruby Central’s decision to platform DHH at RailsConf 2025, and views it as a conflict of interest given the overlapping roles, would Ruby Central consider asking the involved board member to resign to rebuild trust?
**A:** We appreciate the opportunity to address this directly. As stated previously, sponsors do not have governance or program authority at Ruby Central. Conference programming decisions are made independently by the co-chairs and program teams. The board maintains clear conflict-of-interest policies, and all members are required to submit annual disclosures and recuse themselves from any vote where a conflict exists. The 2025 program team was guided by these same standards. We understand that some community members disagreed with this programming decision, and we take that feedback seriously. We are using this moment to strengthen communication, clarify our policies publicly, and reinforce the shared values that shape our events moving forward.
**Question 2:** Does Ruby Central have a formal Conflict of Interest policy, and if so, how are potential conflicts managed?
**A:** Yes. Ruby Central maintains a formal Conflict of Interest Disclosure Form for all board members. A potential or actual conflict exists when commitments or obligations may be compromised by other material interests or relationships, especially financial ones.
As stated in the form:
“A potential or actual conflict of interest exists when commitments and obligations are likely to be compromised by the Director’s other material interests or relationships (especially economic), particularly if those interests or commitments are not disclosed.”
Board members are required to disclose any organizations in which they have an economic interest, or where they act as an officer or director, as well as any personal, business, or volunteer affiliations that could give rise to a real or apparent conflict of interest. Those with a conflict must refrain from participating in related board decisions, as outlined in Ruby Central’s bylaws.
These disclosures are collected annually and housed in our governance records. While the form itself is not yet published online, it is available upon request for transparency.
**Question 3:** Why does Ruby Central continue to hold conferences if they no longer generate surplus revenue? Was this an intentional shift in strategy or the result of changing circumstances?
**A:** We continue to hold conferences because they matter deeply to the community, regardless of whether they generate net revenue. Since 2020, Ruby Central conferences have generally broken even or operated at a small loss. This was not an intentional shift but the result of broader changes in travel patterns, sponsorship budgets, and event economics after the pandemic. Despite this, Ruby Central conferences remain vital spaces for collaboration, learning, and connection. They foster mentorship, innovation, and growth across the Ruby ecosystem.
While the financial model has evolved, the mission behind these events has not. They remain an investment in community health rather than a profit center. RubyConf also holds historical significance as the birthplace of RubyGems in 2003, and we are proud to continue that tradition. More context about how we are evolving our event model can be found in our detailed post, “[A New Era for Ruby Central Events](https://rubycentral.org/news/anewearforrubycentralevents/)”.
**Question 4:** How does Ruby Central ensure that conference programming remains independent and transparent when individuals hold multiple roles within the organization or the broader community?
**A:** Each of Ruby Central’s conferences is guided by a clear separation between sponsorship, governance, and program decisions. Program committees are made up of volunteers who represent a broad cross-section of the Ruby community, while conference chairs oversee selection processes in coordination with staff. The board does not select speakers or keynotes. To further reinforce transparency, Ruby Central has been strengthening its internal documentation, codifying policies for future conference planning, and updating our governance materials to make these distinctions easier for the community to see and understand.
**Closing and Next Steps**
We will continue to respond to community questions and release updates that reflect both operational transparency and collective progress. Please continue submitting your questions through our official form so we can address them in future updates.
Thank you for your engagement, your patience, and your ongoing partnership as we strengthen, improve, and grow together.
[**Link To Submit Questions**](https://docs.google.com/forms/d/e/1FAIpQLSdzz3Djtp8J-oHdI7IEzwqiIH8%5F2O1Ldc2e1OgEvRE7RWgdBQ/viewform?ref=rubycentral.org)
*This was a collaborative effort from all of the Ruby Central Board and Staff.*
### Ruby Central Update Friday 10/31/25
URL: https://rubycentral.org/news/ruby-central-update-friday-10-31-25/
Last updated: 2025-10-31T22:30:40.000Z
Rubyists, thank you for your continued engagement and patience as we move forward together. The pace of questions has steadied, and the tone across the community has shifted towards progress. Ruby Central remains focused on stability and stewardship, not only in operations but in how we communicate and collaborate. Our commitment remains the same, to keep the infrastructure secure.
Since many of the earlier questions have now been addressed, we’re shifting to a more focused approach, answering a few questions each week over the next few weeks and then resuming our normal monthly newsletter cadence.
**Organizational Updates**
As we return to our steady communication cadence, we are sharing a few key updates across programs, partnerships, and upcoming events. These highlight our continued focus on strengthening operations, expanding capacity, and preparing for 2026.
- **Newsletter Cadence** \- Our regular schedule will resume. The Friday updates will continue for the next few weeks and then be replaced by the normal monthly newsletter.
- **Contributor Stewardship Program** \- We are welcoming new operators to help extend the capacity across our open source infrastructure. These contributors are crucial to strengthening continuity, distributing workload, and supporting ongoing improvements and maintenance.
- **Sponsorships & Partnerships** \- Let’s Build the Future of Ruby! We’re excited to share our new Ruby Central Partnership Guide, designed for companies that want to make a lasting impact in the Ruby community. Whether through events, open source, or educational programs, there are more ways than ever to get involved
Interested in partnering with us? We’d love to explore what’s possible together. Please email [tom@rubycentral.org](mailto:tom@rubycentral.org) for more information.
- **RubyConf 2026** \- In the coming weeks, we’ll be announcing the location for RubyConf, along with all the exciting details. Stay tuned for the official reveal!
**Open Source Updates**
**On-Call:** We’ve extended our primary and secondary on call rotations to six engineers. This forms our core group of operators to manage the service 24/7\. All of these operators have signed our new operator agreements or have joined through our Contributor Stewardship Program. During this time, we’ve created new onboarding documentation and runbooks for the Rubygems.org service.
**AWS Outage:** RubyGems.org was not affected by the recent [AWS outages](https://aws.amazon.com/message/101925/?ref=rubycentral.org). Our status page host, [Statuspage](https://www.atlassian.com/software/statuspage?ref=rubycentral.org), was temporarily affected by the outage.
**Sigstore:** On October 10th, the sigstore-ruby client [fell behind](https://github.com/sigstore/sigstore-ruby/issues/263?ref=rubycentral.org) in its support of Sigstore's production servers, resulting in all attestations failing. We addressed the issue by contributing pull requests to the upstream sigstore Ruby library, resulting in a [new release](https://github.com/sigstore/sigstore-ruby/releases/tag/v0.2.2?ref=rubycentral.org) of sigstore-ruby and full restoration of trusted publishing functionality.
**What's next:**
- Work continues to enhance our disaster recovery procedures
- We're continuing to document our services, runbooks
- Expand our on-call team beyond 6 engineers to bolster our EMEA and APAC coverage
**Asynchronous Q&A**
We know trust is tested by unanswered questions. We’re continuing with an asynchronous Q&A so everyone can participate and read the same answers, regardless of time zone. We may group questions by theme, publish them on a set cadence, and keep answers concise and fact-based.
**Question 1:** What legal and governance challenges led to the new structure, and how does it address them?Perhaps rubygems isn’t a small group of volunteers with small risk, anymore, it could be seen as a critical piece of infrastructure for the globe, and so the old admin practices don’t match the new world? Are there things that NPM and PyPI have struggled with that the new RubyGems governance solves? Do you foresee other language packaging ecosystems making similar moves?
**A:** The more general question raised here is better answered independently in an impartial context by the Open Source Security Foundation: [https://openssf.org/blog/2025/09/23/open-infrastructure-is-not-free-a-joint-statement-on-sustainable-stewardship/](https://openssf.org/blog/2025/09/23/open-infrastructure-is-not-free-a-joint-statement-on-sustainable-stewardship/?ref=rubycentral.org)
While we are members of OpenSSF, we missed the opportunity to be a signatory on the joint statement.
Nevertheless, we support it both generally and as it applies here.
**Question 2:** In your update on Oct 24, you stated: “Shopify, like other sponsors, has never played any role in keynote selection or conference programming decisions. Sponsors do not have governance or program authority.” Can you please confirm who the conference chairs were for RailsConf, and who they are employed by? Can you also further confirm their relationship with RubyCentral otherwise. My understanding is that there were two co-chairs, one who is the founder of GoRails, and the other is a Shopify employee. The latter is also a board member of Ruby Central. Is this accurate? If so, what measures have been taken to ensure that decision making is genuinely independent? The reason for this question is because it is fairly hard to believe that there isn’t some level of bias inherent in this choice given that the program committee was not given input, and the speaker is a member of Shopify’s board, and the moderator a Shopify employee. Is there a reason why you did not at least disclose these affiliations in your reply?
**A:** Hi, Ufuk Kayserilioglu here, the Ruby Central board member who was the co-chair of RailsConf (both 2024, and 2025) that you seem to be asking about. I’ll try to answer this question personally.
I am a Shopify employee, but my Ruby Central board role has nothing to do with my employment at Shopify; it is my personal engagement that is neither directed nor guided by Shopify. I joined the Ruby Central board in December 2023, and the first role assigned to me as a new board member was to co-chair RailsConf 2024\. After accepting the assignment, I made 2 requests to the board. First, I asked the board for permission to seek a community co-chair to help organize RailsConf 2024 and the board approved. This was important, since it was the first time Ruby Central ever had an outside community member have any role in the decision making for our conferences. Program chairs of Ruby Central conferences have complete authority in setting the theme and the program for the conference without needing board approval, so this was an important step towards community engagement for the organization. Since then, we’ve continued to use that model, seen it work really well, and have decided to continue using it for all of our conferences going forward.
The second thing I asked the board to vote on was permission to reach out to DHH to get him on the RailsConf 2024 program, which the board approved. My goal was to find a way to get DHH back to speak at RailsConf, and my co-chair was also on-board with that decision. Back in February 2024, when we did the initial reach out, DHH had no relationship with Shopify, and our decision, as conference chairs, to reach out to him had nothing to do with Shopify either. He actually joined Shopify's board much later, in [Nov 2024](https://www.shopify.com/news/david-heinemeier-hansson-board?ref=rubycentral.org). Ultimately, there was too little time left until RailsConf 2024 to arrange an appearance, so we deferred the conversation to RailsConf 2025.
I volunteered to co-chair the 2025 RailsConf as well, and found a community co-chair with whom we formed the program committee, and restarted the conversation with DHH about an appearance at the conference. At the kick-off meeting of the program committee, as first order of business, I made sure to let the committee members know that DHH might be one of the keynote speakers and that if that was going to be a point of concern with anyone that they could choose to decline their program committee role. There were no objections or concerns raised by any of the committee members and none of the program committee members decided to leave at that point or at any point afterwards. The committee, as a group, ultimately selected all the talks, the workshops and three of the five keynote speakers that formed the conference program.
Given this timeline, I hope it is clear that the program, theme and keynote selection have been done by the co-chairs in a fair and independent manner, with multiple points of community engagement, and soliciting opinions and approvals from multiple parties when and as appropriate. As we have made it clear over and over again, Ruby Central does not take direction from any sponsor, nor allow any sponsor to influence the program which is planned and decided independently by the group of community volunteers on the program committee.
We didn’t feel the need to disclose any company affiliations in our original response, since those affiliations are already a matter of public knowledge given that our board members and conference co-chairs are publicly shared on the relevant websites. For example, the program chairs of both the 2024 and 2025 RailsConf can be seen on their websites at [https://2024.railsconf.org/about](https://2024.railsconf.org/about?ref=rubycentral.org) and [https://railsconf.org/about](https://railsconf.org/about?ref=rubycentral.org). The same is true of our conference sponsors and the speakers at our conferences. The point that seems to be contentious in these questions though is one we can answer clearly: none of those affiliations have played any part in any programming decision in any of our conferences.
**Closing and Next Steps**
We will continue to respond to community questions. As we move forward, we’ll focus on ongoing transparency, consistent communication, and strengthening operations and collaboration.
We encourage you to submit your questions through our [official form](https://docs.google.com/forms/d/e/1FAIpQLSdzz3Djtp8J-oHdI7IEzwqiIH8%5F2O1Ldc2e1OgEvRE7RWgdBQ/viewform?ref=rubycentral.org) so we can continue to address them. Thank you again for your patience and being a part of this evolving and resilient community. We are looking forward to continuing to build, improve, and grow together.
[**Link To Submit Questions**](https://docs.google.com/forms/d/e/1FAIpQLSdzz3Djtp8J-oHdI7IEzwqiIH8%5F2O1Ldc2e1OgEvRE7RWgdBQ/viewform?ref=rubycentral.org)
*This was a collaborative effort from all of the Ruby Central Board and Staff.*
### Source of Truth Update – Friday, October 24, 2025
URL: https://rubycentral.org/news/source-of-truth-update-friday-october-24-2025/
Last updated: 2025-10-24T18:00:14.000Z
We appreciate the community’s patience and grace as we briefly paused our regular cadence of weekly updates. Out of respect for last week’s announcement from Matz and its importance to the community, we held this Q&A until today. For this week’s update, we’re sharing a collection of all the questions that have been presented to Ruby Central over the past several weeks. To respect privacy and consent, we are not attributing where individual questions originated, but in the spirit of transparency and equitable communication, we are including them all here.
Many of the questions we received overlapped or touched on similar themes, so we’ve organized them into groups. This makes it easier to provide clear, thorough answers and ensures every question is acknowledged and addressed.
We’ve shared [**a link to our asynchronous Q&A form**](https://docs.google.com/forms/d/e/1FAIpQLSdzz3Djtp8J-oHdI7IEzwqiIH8%5F2O1Ldc2e1OgEvRE7RWgdBQ/viewform?ref=rubycentral.org) with each update, though we’ve heard that it’s not always easy to find. Starting this week, the form link will appear prominently at the top of every update.
While we also gathered questions that community members posted in other public forums and repositories, moving forward we’ll respond only to those submitted through this [official form using this link](https://docs.google.com/forms/d/e/1FAIpQLSdzz3Djtp8J-oHdI7IEzwqiIH8%5F2O1Ldc2e1OgEvRE7RWgdBQ/viewform?ref=rubycentral.org). This ensures that every question is received, reviewed, and answered and no question is overlooked or mistaken as ignored. We also continue to hear your requests for a live conversation. We’re working toward that and will announce opportunities to connect with us live before the end of the month.
Since many of the questions we received were submitted several weeks ago, some of the information has already been addressed through prior updates and ongoing work. We felt this was the right moment to also hear directly from leadership. **Shan Cureton, Executive Director of Ruby Central, joins Errol Schmidt on the Technology for Humans podcast** today, where she’ll address many of these questions and share what’s ahead for the community. We encourage everyone to tune in for additional context and to continue submitting questions through the Q&A form.
[**Link To Submit Questions**](https://docs.google.com/forms/d/e/1FAIpQLSdzz3Djtp8J-oHdI7IEzwqiIH8%5F2O1Ldc2e1OgEvRE7RWgdBQ/viewform?ref=rubycentral.org)
# Communication and Community Engagement
- Why are there delays in answering submitted questions?
- Why hasn’t the next Q&A session been scheduled? Isn’t this just a simple Zoom call?
- Why is the lack of engagement causing so much frustration?
- When will the community Q&A happen? Why hasn’t it been held yet?
- Will you publish all collected questions and responses?
We understand why the delays in answering questions and the lack of a live conversation have been frustrating. That frustration is real, and it reflects a gap between when actions were taken internally and when the community heard about them. Those delays were not intentional, but they did create a sense of distance between Ruby Central and the community at a critical moment.
The slower pace was due to several factors. First, we made the decision to prioritize accuracy over speed, which meant verifying each answer carefully before publishing. Second, some of the questions touch on legal, personnel, or security matters that require additional review before we can respond publicly. Third, we needed to build a structured process for collecting, reviewing, and publishing questions consistently rather than responding in fragmented or inconsistent ways.
Moving forward, we are committing to a more predictable and visible communication cadence. All collected questions will continue to be grouped by theme and shared in weekly Source of Truth updates so that everyone receives the same verified information. The Q&A submission form is now linked at the top of every update to make it easier for the community to find and use. We are also planning a live Q&A session before the end of the month, once we can ensure accurate and consistent answers are ready for discussion.
We can’t undo the delays, but we can fix the structure behind them. Rebuilding trust means showing up consistently, communicating clearly, and creating more direct ways for the community to engage.
# Stewardship and Rebuilding Trust
- What’s next for rebuilding trust with the community?
- Why should the community trust Ruby Central now?
- How will you repair the damage to Ruby’s reputation?
- What lessons has Ruby Central learned?
- Why should the community believe Ruby Central is a good steward?
- How did we end up here? Who is responsible, and how will you ensure better actions and communication in the future?
Responsibility for what happened rests with Ruby Central as an organization. We acknowledge that gaps in governance, access management, and communication contributed to confusion and frustration across the community. We’ve learned from this, and we’ve made changes.
Stewardship is demonstrated through transparency, open contribution pathways, and responsible management of shared infrastructure.
Ruby Central’s role is to protect the infrastructure that powers the Ruby ecosystem. We aim to rebuild trust with the community by acting transparently, strengthening governance, and inviting collaboration. We’ve implemented stronger controls, released a full incident report, and are engaging openly to rebuild confidence through consistency.
# Timelines and Decision Context
- What was the “funding deadline” referenced in earlier posts? Was it issued by a sponsor?
- What was the “timeline” that drove the access changes?
- Were sponsors behind these decisions? Are there NDAs or funding conditions tied to compliance deadlines?
- Why did you act when you did? Were there real deadlines?
The recent access changes were shaped by ongoing security improvements and a broader governance review that began earlier in the year.
The departure of key individuals from Ruby Central meant that their access to code and production systems were no longer protected by contractor or employment agreements. As part of the standard off-boarding process in any professional organization, we started a review of our internal systems that were under the control of key individuals and set an internal timeline for when control should revert back to Ruby Central. We did this in reflection of our organization’s responsibility for providing a secure and sustainable supply-chain for the Ruby community.
The Board acted independently in their decision based on the internal timeline that was set; there was no sponsor-imposed funding deadline. Ruby Central maintains standard sponsorship agreements that do not grant operational control or impose conditions on governance. As such, sponsors were only briefed as part of normal communication and were not involved in any decisions or deadlines.
We acknowledge that our public communication lagged behind internal actions, which understandably caused concern. Going forward, we’re improving how and when we communicate security and governance changes so the community receives timely, verified information.
# Board Governance and Transparency
- Why isn’t the board elected by a polling or voting process?
- Will minutes from Ruby Central Board meetings be made available to the community? If no, why not?
- If Ruby Together once published minutes showing ownership of the RubyGems client, can we see current Ruby Central board minutes from when repository changes were made?
Ruby Central is a nonprofit governed by a board as outlined in bylaws. Board member applications are open to the whole community and members are chosen from the candidates for their governance, fiduciary, and operational expertise to meet legal and organizational obligations.
Ruby Central’s Board has never published its meeting minutes publicly. As a nonprofit, our governance policy does not include public release of minutes from regular or special sessions, which often involve legal, contractual, or personnel matters. Instead, we provide transparency through published reports and community updates which offer a verified account of the Board’s actions and decisions relevant to this event.
# Maintainers and Project Roles
- Who will maintain RubyGems and Bundler going forward? Are they the same people who operate [RubyGems.org](http://rubygems.org/?ref=rubycentral.org)?
- What is the status of maintainers who lost access? Will commit rights be restored? Will a list of maintainers be published?
- Who are the new maintainers mentioned in the October update? Will you publish a full list?
Maintenance will remain a collaboration between community contributors and vetted operators. Ruby Central oversees the infrastructure, and the security and sustainability of the open-source clients. Contributors from the community continue to work on Bundler and RubyGems codebases under open governance and contributor agreements, including both contracted and grant funded maintenance and voluntary community contributions. We are finalizing operator and contributor agreements that clearly define responsibilities and access to infrastructure and repositories. Several maintainers have already been engaged under these agreements. A current list of maintainers will be published once agreements are fully executed and reviewed for privacy and security compliance.
# Sponsorship and Community Support
- What is the official relationship between Ruby Central and corporate sponsors financially?
- What is the official relationship between Ruby Central and Shopify? Are there signed agreements? How much money is involved?
- How many individual and corporate sponsors currently support Ruby Central?
- Has Ruby Central engaged with other long-time corporate contributors like Stripe, GitHub, 37signals, or Airbnb?
- What’s the relationship between Ruby Central and Shopify?
- How are other companies like Stripe or GitHub involved?
- Why has Ruby Central not been completely transparent about funding sources, spending, and sponsor relationships?
- Do corporate sponsors impose explicit or implicit expectations on Ruby Central?
- Did a sponsor ask for a specific maintainer to be removed?
- Will you publish all sponsor communications?
As a 501(c)(3) nonprofit, Ruby Central reports funding and expenditures annually through public IRS filings. Corporate sponsorships help offset the costs of the services and educational content we deliver, but carry no governance authority or conditions. Our sponsors do not direct or approve decisions related to operations, governance, programming or personnel. None of Ruby Central’s sponsorship agreements confer any form of operational control or governance authority over staffing, events and event content (other than specifically designated sponsor talks and booths), or technical projects.
Ruby Central regularly engages with many companies that depend on Ruby infrastructure. We discuss shared goals for ecosystem stability and how they can help sustain the shared infrastructure managed by our organization, through sponsorship, engineering contributions, or in-kind support. These relationships are collaborative, not directive, and our conversations focus on partnership, not control.
We are finalizing our 2025 fiscal-year reporting and will publish a summary of contributors, grouped by tier, in our annual report and on IRS Form 990\. We continue to expand both unrestricted community and corporate partnerships as well as grant funding to ensure sustainability.
Shopify is a corporate sponsor that supports Ruby Central’s mission through standard funding agreements. Ruby Shield, our partnership with Shopify started 3 years ago and was announced very publicly here: As shared in that announcement, Shopify has committed $1 million USD over four years to strengthen supply-chain security for the Ruby ecosystem. As with our other sponsors, our agreement with Shopify does not grant them any operational control, governance authority, or conditions on program content or personnel.
We will continue to improve clarity by summarizing sponsorship categories and board-approved budgets in our annual report.
# Repository Stewardship and Ownership
- What is Ruby Central’s claim of ownership over RubyGems and Bundler? Does it extend to the code itself?
- Is Ruby Central planning to own the Ruby language?
- Does Ruby Central own RubyGems and Bundler? What’s the chain of custody?
- Could Ruby Central secure RubyGems.org without asserting ownership of the projects?
- What is the basis for Ruby Central’s claim of operational responsibility?
- Did Ruby Central “take control” of RubyGems and Bundler?
RubyGems and Bundler have been managed by Ruby Central, as stated in their repository READMEs, since the merger with Ruby Together. Ruby Central has authority over the code and the gems commensurate with this management responsibility and the responsibility for delivering a secure and sustainable supply chain for the whole Ruby community.
While the RubyGems.org service is deployed from rubygems/rubygems.org repository, it also needs at least 2 more private repositories in the same organization for infrastructure-as-code, and CDN deployments. Additionally, the deployment process has access controls gated on GitHub team membership in the same organization.
On the client tools side, while the repos could have been forked, as long as individuals could publish the gems from any source they want, no forked repository could have been the canonical and secure source of the tools.
In summary, there are many moving parts of the complete supply-chain under Ruby Central management and responsibility, and access changes were the least disruptive and the most secure way of taking action.
# Supply Chain Security
- Are additional projects planned to improve RubyGems supply-chain security?
- What projects are planned to improve RubyGems supply-chain security?
- Have supply chain attacks on RubyGems.org increased?
We have not observed a measurable rise in attacks to RubyGems.org, mostly due to our recent investments in strengthening security by introducing mandatory MFA for owners of popular gems, our implementation of trusted publishing and our long-standing defenses against dependency confusion, namesquatting and typo-squatting. However, industry-wide risks have grown significantly in our peer communities, which is why we’re implementing stronger controls, periodic audits, and multi-factor authentication for all privileged accounts.
We’re also expanding the Corporate Contributor Stewardship Program to strengthen maintenance and resilience. In addition, we have a strong roadmap of features we want to build for strengthening the whole Ruby supply-chain, details of which we will be announcing in the near future.
These upcoming projects include expanding trusted publishing coverage, improving automated detection and response capabilities, and formalizing periodic security audits and operator accountability measures. This work is part of a proactive security posture not a reaction to new incidents ensuring RubyGems remains a secure, resilient service at the center of the Ruby ecosystem.
Sustaining and expanding this work requires dedicated investment. Strengthening supply-chain security isn’t a one-time project, it’s an ongoing commitment to staffing, monitoring, and improvement. Ruby Central is currently hiring a Senior Security Engineer to focus on this work full-time and to help accelerate key initiatives. Additional funding will allow us to build the infrastructure, automation, and capacity needed to meet the scale of security challenges facing open-source ecosystems.
# Code vs. Service: Roles and Responsibilities
- Do you recognize the difference between the open-source RubyGems/Bundler projects and the RubyGems.org service?
- Are you conflating commit rights for Bundler/RubyGems with production access to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org)?
- Could Ruby Central secure RubyGems.org without asserting ownership of the projects?
We recognize that code contributions (Bundler and RubyGems) and production operations (RubyGems.org) are distinct. However, Ruby Central has management responsibilities for both the infrastructure, and the open-source client tools to ensure their security and sustainability.
Operating the service involves managing infrastructure, credentials, deployment pipelines, and other security controls that keep RubyGems.org stable and reliable for the entire Ruby ecosystem. These operational responsibilities are different from contributing to the code itself and cannot simply be replaced through a fork or code-only change.
Contributor agreements outline how people engage with the open-source projects, while operator agreements define who is entrusted with managing the live production environment. Both are essential to ensuring that the code remains open and collaborative while the service remains secure and stable.
# Governance Structure and Technical Roles
- Will Ruby Central separate technical and non-technical governance?
- Will Ruby Central consider separating technical and non-technical governance?
- When will Operator and Contributor Agreements be finalized?
Yes. Ruby Central is actively separating technical and non-technical governance to make roles, responsibilities, and decision-making processes clearer. Technical operations are managed through defined operator and contributor roles, while non-technical governance remains the responsibility of the Board of Directors.
Governance oversight resides with the Board, which holds fiduciary and legal responsibilities for the organization. Technical operations, including infrastructure management, security controls, and the stewardship of [RubyGems.org](http://rubygems.org/?ref=rubycentral.org), are handled by vetted operators and maintainers under documented policies, with technical expertise and guidance from the Open Source Committee.
Operator and Contributor Agreements formalize this separation. They define who has access to infrastructure, who contributes to the code, and how both groups are accountable to each other and to the community. Operator agreements are nearly complete, and contributor agreements will follow shortly after. Updates will continue to be shared through weekly Source of Truth posts.
This structure creates clearer accountability and ensures that technical decision-making is guided by operational expertise and community input, while broader organizational oversight remains with the Board.
# Security Risk Response & Mitigation
- What was the actual risk discovered during the access review?
- Have old AWS credentials and security audit findings been fixed?
- What was the specific security risk involving a single individual with system control? Who was it? Has access been restored?
All historical credentials have been rotated and are MFA-protected. Every prior audit finding has been reviewed and remediated or scheduled for completion under independent verification.
For privacy and legal reasons, we do not identify individuals. The risk involved a concentration of control and unrotated credentials. Access has since been fully restructured under least-privilege and audit-logged accounts. MFA protects all systems.
In addition to remediating the immediate issue, we have strengthened our overall security posture. Access pathways have been narrowed, infrastructure roles have been formally documented, and responsibilities are now tied to clear agreements rather than individual trust. Regular security reviews, credential rotation schedules, and external verification are now part of our ongoing security practices.
These changes ensure that no single individual holds unilateral control over critical systems and that safeguards are in place to detect and prevent similar risks in the future.
# RailsConf Keynotes
- Was DHH’s RailsConf 2025 keynote pre-announced before the review process? Was it part of Shopify’s sponsorship agreement?
- Why was DHH’s role or keynote mentioned so prominently? Was Shopify involved?
- Was DHH’s RailsConf keynote pre-decided or linked to sponsorship?
Programming decisions for RailsConf are made by the volunteer co-chairs and program committee, with support from Ruby Central staff. Conversations to have DHH as a speaker began in early 2024, but the timing didn’t work out for that year. Those conversations resumed in 2025 and since it was the final RailsConf, it made sense to make it happen then. The invitation was not tied to any sponsorship agreements or external requirements, and was purely a programming decision by the co-chairs of the conferences.
Shopify, like other sponsors, has never played any role in keynote selection or conference programming decisions. Sponsors do not have governance or program authority. DHH’s keynote was highlighted the same way as other featured speakers, and any increased visibility came from community conversation around the event.
# Additional Community Questions
**What’s Ruby Central’s stance on external “fact-check” posts and independent investigations?**
We respect the community’s right to question and verify. Our responsibility is to provide verified, source-based updates. You can look at our previous posts here:
- [Ruby Central Statement on RubyGems & Bundler](https://rubycentral.org/news/ruby-central-statement-on-rubygems-bundler/) \- *October 17, 2025*
- [Source of Truth Update](https://rubycentral.org/news/source-of-truth-update-friday-october-10-2025/) \- *October 10, 2025*
- [Rubygems.org AWS Root Access Event – September 2025](https://rubycentral.org/news/rubygems-org-aws-root-access-event-september-2025/) \- *October 9, 2025*
- [Weekly Update](https://rubycentral.org/news/weekly-update-friday-october-3/) \- *October 3, 2025*
Everyone is entitled to their own opinions, and everyone comes with their own perspectives based on the individual experiences we have. We welcome you to look at all sides. Our goal is to release concrete and verifiable information to the community as it comes together.
**Is Ruby Central planning to own the Ruby language?**
No. The Ruby language remains led by Matz and the Ruby Association in Japan. Ruby Central’s role is stewardship of supporting infrastructure and tools such as RubyGem.org, RubyGems, and Bundler. We work in partnership with the broader Ruby community to ensure that these systems remain secure, stable, and accessible, but we do not direct or govern the language itself.
**Does Ruby Central plan to continue membership donations?**
Yes. Individual contributions remain an important part of Ruby Central’s funding; in fact, we encourage a grassroots approach to funding open source and community programs. Donations help maintain RubyGems infrastructure, community events, and educational programs.
Membership contributions are a critical part of sustaining the ecosystem’s long-term health. They provide flexible funding that supports ongoing security investments, helps expand programs, and allows us to respond quickly to emerging needs without relying solely on large sponsors. Updated membership tiers will be announced alongside our next annual report, creating more ways for Rubyists to directly support this work.
**Why did Ruby Central’s actions appear to remove an active maintainer “by mistake”?**
Our rapid credential alignment unintentionally paused access for one active maintainer. That access has since been reviewed under the new agreement process. We’ve updated internal review protocols to mitigate against similar occurrences. These protocols now include a more deliberate verification step before access changes are finalized.
**What happened with the cease-and-desist letter?**
We have no further comment on this matter beyond what we stated in [this update post](https://rubycentral.org/news/source-of-truth-update-friday-october-10-2025/).
**What’s really going on here? What’s the context behind people saying Ruby Central “attacked” RubyGems?**
The situation stems from necessary governance and security changes to align access controls with current policy. We placed a temporary hold on certain privileges while finalizing operator agreements and security reviews. No code changes or ownership “takeover” occurred; RubyGems.org remained fully operational throughout.
At the time, the parties closest to the situation had a limited view of all the facts. Because of that, they responded with the information they had, including the abrupt access changes and the limited communication from us at the time. This combination understandably created confusion and concern.
In reality, these actions were part of a broader security alignment effort to protect the infrastructure and reduce single points of failure. We’ve since improved how we communicate these changes so the intent and scope are clear before, not after, they happen.
**Why did Ruby Central contact someone outside the organization about repository control?**
Discussions about transferring the RubyGems and Bundler repositories under the Ruby Core team have been ongoing for several years. Over time, frequent leadership turnover at Ruby Central made it difficult to sustain the momentum needed to finalize that transition.
Our timeline was ultimately accelerated for two reasons. First, we needed to ensure that governance over these critical repositories was properly aligned with the Ruby language’s upstream leadership. Second, recent personnel changes made it essential to clarify roles and responsibilities in order to reduce operational risk and strengthen long-term stewardship.
The outreach to external parties was not an attempt to seize control or act unilaterally. It was the next step in finalizing a process that had been underway for years and ensuring the transition happened in a way that best serves the community and the long-term stability of Ruby’s infrastructure.
**Is Ruby Central aware of community comparisons to other OSS governance conflicts like TWiki/FOSWiki?**
We’re aware of the discussion but believe direct comparison isn’t accurate. Our goal has always been to secure and stabilize shared infrastructure, not to commercialize or restrict collaboration. We welcome constructive input to strengthen governance.
Ruby Central’s role is focused on responsible stewardship of infrastructure and tools that serve the entire Ruby ecosystem. The open-source projects remain open to contributors, and governance decisions are guided by transparency, community input, and operational security needs. We welcome constructive feedback to strengthen those governance processes even further.
**Will Friday’s communication address projects from separated or continuing staff?**
If such updates directly affect RubyGems infrastructure or governance, they’ll be included. Otherwise, we focus our Friday updates on verified operational and governance topics.
*This was a collaborative effort from all of the Ruby Central Board and Staff.*
### Ruby Central Statement on RubyGems & Bundler
URL: https://rubycentral.org/news/ruby-central-statement-on-rubygems-bundler/
Last updated: 2025-10-17T12:30:01.000Z
Earlier today, the Ruby core team announced the [transfer](https://www.ruby-lang.org/en/news/2025/10/17/rubygems-repository-transition/?ref=rubycentral.org) of **repository ownership for RubyGems and Bundler** to the Ruby core team. This decision reflects our shared commitment to the long-term stability and growth of the Ruby ecosystem.
While repository ownership has moved, Ruby Central will **continue to share management and governance responsibilities** for RubyGems and Bundler in close collaboration with the Ruby core team. We remain deeply committed to strengthening security, performance, and the developer experience through ongoing investments, grants, and active development.
- Ruby Central will continue to own and operate [rubygems.org](http://rubygems.org/?ref=rubycentral.org) for the community.
- RubyGems and Bundler remain open source under their current licenses.
- All contributors retain full authorship and intellectual property rights.
Ruby Central is proud of its long history supporting these critical projects, and we look forward to building their next chapter together with the Ruby core team and the community.
— *Shan Cureton & Ruby Central Board*
*Note: We’re sharing this message in place of our regular weekly update because it deserves its own space and attention. Our next community update will come early next week and include responses to questions submitted by the community. If you have additional thoughts or questions, we welcome them through our* [*Community Q&A Form*](https://docs.google.com/forms/d/e/1FAIpQLSdzz3Djtp8J-oHdI7IEzwqiIH8%5F2O1Ldc2e1OgEvRE7RWgdBQ/viewform?ref=rubycentral.org)*.*
### Source of Truth Update – Friday, October 10, 2025
URL: https://rubycentral.org/news/source-of-truth-update-friday-october-10-2025/
Last updated: 2026-07-10T14:00:52.000Z
Yesterday, we released our **Security Incident Report**, a comprehensive review of the September AWS root-access event. The report reflects both independent and internal analysis, outlining what occurred, what was verified, and the actions we’ve taken to strengthen our systems and practices.
You can read the full report here → [Rubygems.org AWS Root Access Event – September 2025](https://rubycentral.org/news/rubygems-org-aws-root-access-event-september-2025/)
The findings confirm that this was a procedural lapse in credential management for production hosting after a person was discharged.
**Where We Are Now**
All RubyGems.org services remain stable, secure, and operational.
The triggering event revealed weaknesses in credential management practices, which we have corrected. All credentials have been rotated and are further protected with MFA.
We’ve also strengthened operational coverage by adding two new maintainers to our on-call rotation to improve resilience and response capacity.
In our efforts to further strengthen operational resilience, we are opening up opportunities for additional community participation in operations through structured volunteer support from trusted individuals and companies. Specifically, through Ruby Central’s Corporate Contributor Stewardship Program, companies commit in-kind engineering time to work with our team on priority maintenance, reliability, and security tasks across RubyGems, Bundler, and RubyGems.org. Ruby Central coordinates onboarding, scope, and review so contributors can plug in quickly and safely. To learn more, reach out to [contact@rubycentral.org](mailto:contact@rubycentral.org).
**What We’re Hearing**
We recognize the strong emotions that continue to surface in community channels. Many community members have expressed frustration, skepticism, and fatigue, along with a shared desire for clarity and accountability.
Recently, partial email communications regarding production access have circulated publicly. To provide the correct context and clarity and to ensure that the community has the full and accurate picture, we will release the full thread of our original communication informing the individual in question that their production access to RubyGems.org was terminated. Any access after that point was strictly unauthorized.

We also acknowledge that this transition period for the paid contractors that operate the service has created uncertainty and concern.
Our intention is to move beyond back-and-forth exchanges, and to continue to restore calm, trust, and stability by being transparent and clear about key facts.
Trust is earned through consistency. Our goal and our responsibility is to match words with visible actions, strengthening security, operating transparently, and inviting dialogue that is grounded in respect and shared purpose.
**Why No Live Q&A (Yet)**
Several community members have asked why we haven’t held a live Q&A.
During the incident discovery and validation phase, there were many moving parts and active verification steps. A live Q&A at that time would have risked spreading incomplete information and excluded contributors who couldn’t participate in real time.
Additionally, on Friday, September 26, Ruby Central received a cease-and-desist letter from Andre Arko’s lawyer informing us that he claims to own “Bundler” as a trademark and demands that Ruby Central stop using “Bundler,” along with various other demands. Ruby Central disagrees with Arko’s claims, and we have engaged with trademark law counsel to work with Arko’s counsel on this matter. As part of the legal process, we do not expect to make further public comments about the matter until the issues are fully resolved.
Because we are simultaneously addressing a legal matter and responding to a security incident, it has delayed us in rescheduling the Q&A.
We chose an **asynchronous format** with weekly updates and published Q&A, so questions can be addressed publicly and so that everyone, regardless of location or schedule, can review the same verified information.
A live Q&A may still happen once it can add value without detracting from our mission and focus.
**Looking Ahead**
In the coming weeks, Ruby Central will:
- Continue implementing security and governance improvements outlined in the post-incident report.
- Publish follow-up progress on Operator and Contributor Agreements.
Our stewardship of RubyGems.org remains secure and continuous. We are deeply grateful for the community’s patience, accountability, and commitment to Ruby’s future.
**With respect,**
*Shan Cureton*
*Executive Director*
### Rubygems.org AWS Root Access Event – September 2025
URL: https://rubycentral.org/news/rubygems-org-aws-root-access-event-september-2025/
Last updated: 2026-01-06T16:36:38.000Z
As part of standard incident-response practice, Ruby Central is publishing the following post-incident review to the public. This document summarizes the September 2025 AWS root-access event, what occurred, what we verified, and the actions we’ve taken to strengthen our security processes**.**
On September 30th, a [blog post](https://web.archive.org/web/20250930213611id%5F/https://joel.drapper.me/p/ruby-central-security-measures/) raised concerns that a former maintainer continued to have access to the RubyGems.org production environment after administrative access was removed from several accounts earlier that month. We want to share the outcome of our investigation including: what happened, the extent of what we verified, what we got wrong, and the actions we have taken to strengthen our security processes going forward.
When this situation came to light, our immediate concern was the integrity and safety of the RubyGems.org service and its data. We take seriously our responsibility to steward the open-source infrastructure that millions of developers rely on each day. While we have found no evidence that user data or production operations were harmed, we recognize that the existence of an unrevoked shared credential and unclear communication created understandable alarm and frustration. For that, we are sincerely sorry.
## Incident Response Timeline
#### September 30 2025
- **17:23 UTC:** A former maintainer, André Arko, emails the Director of Open Source at Ruby Central stating that he still has access to the RubyGems.org production environment and associated monitoring tools.
**Note:* This is the first and only disclosure to Ruby Central about this access by Mr. Arko.*
- **17:30 UTC:** Joel Drapper (unaffiliated with Ruby Central) publishes a [public blog post](https://web.archive.org/web/20250930213611id%5F/https://joel.drapper.me/p/ruby-central-security-measures/) within minutes describing this access with screenshots taken earlier that day showing root account access.
- **17:51 UTC:** Ruby Central engages its board members and OSS staff to verify the veracity of the report, assembles an incident team, and enumerates all services and credentials to assess exposure scope and ensure complete remediation.
- **18:20 UTC:** Ruby Central begins its emergency review and learns that the existing credentials for the AWS root account in our password vault are no longer valid.
- **18:24 UTC:** Ruby Central initiates an AWS password-reset procedure, validates multi-factor authentication, and regains control of the AWS root account.
- **18:30 UTC**: Ruby Central downloads a “Credentials Report” from the AWS console to understand why we could not access the root account, and learns that the root account password was changed by an unauthorized party on September 19th at 04:35 UTC.
- **20:45 UTC:** After an examination of AWS CloudTrail logs, DataDog alerts, and IAM configurations, Ruby Central identifies and revokes all associated sub-accounts and legacy credentials, issues new MFA tokens to the remaining accounts, and migrates the new root access credentials into a secure vault under Ruby Central’s sole control.
## Analysis of Events
By way of background, Ruby Central’s infrastructure runs on Amazon Web Services (AWS). The root account credentials, essentially the highest level of administrative control, are stored in a shared enterprise password manager in a shared vault to which only three individuals had access: two current Ruby Central staff members and one former maintainer, André Arko.
#### September 18 2025
- **18:04 UTC:** Ruby Central notifies Mr. Arko, via email, of the board’s decision to remove his RubyGems.org production access, and the termination of his on-call services. During that transition, our teams remove the AWS security credentials belonging to Mr. Arko for accessing the production systems, but we fail to rotate the AWS root account password in tandem.
#### September 19, 2025
- **04:34 UTC:** An unauthorized actor originating from a San Francisco, California IP address starts a root account session on the AWS Rubygems.org AWS account.
- **04:35 UTC:** The unauthorized actor changes the root account password.
**Note:* After this point, and until the AWS root credentials were reset by Ruby Central on Sept 30th, all subsequent actions taken on the AWS root account originate from the unauthorized actor.*
- **04:37 UTC:** The unauthorized actor removes authorized users from groups and detaches access policies which reduces the privileges of authorized Rubygems.org AWS account holders.
- **04:39 UTC:** The unauthorized actor rapidly enumerates the IAM posture of the entire AWS account.
#### September 28th, 2025
- **05:49 UTC:** An unauthorized actor originating from a Tokyo, Japan IP address starts a root account session and uses IAM introspection API calls to check users’ group membership, last usage date, and last usage date of associated access tokens and policies.
**Note:* This unauthorized access occurs adjacent to the* [*Kaigi on Rails conference*](https://web.archive.org/web/20250929050252id%5F/https://kaigionrails.org/2025/) *also in Tokyo, Japan from Sept 26th - 27th. As a result, we attribute this access to the same unauthorized actor.*
#### September 30th, 2025
- **15:25 UTC:** An unauthorized actor originating from a Los Angeles, California IP address starts a root account session.
- **15:35:24 UTC:** The unauthorized actor issues a `PutCredentials` command to obtain user credentials, which match the screenshot shared in the blog post announcing the security vulnerability. The [blog post asserts](https://web.archive.org/web/20250930213611id%5F/https://joel.drapper.me/p/ruby-central-security-measures/#the-front-door) that this action was taken by Mr. Arko.

- **18:24 UTC:** As we mentioned previously, Ruby Central performs the AWS password-reset operation to take back control of the root account.
**Note:** *After this point, all actions taken on the AWS root account can be attributed back to authorized actors.*
## Extent of the Incident
After a careful review, Ruby Central is relieved to report **that we see no evidence** that this security incident **compromised end user data, accounts, gems, or infrastructure availability**. In addition:
- RubyGems.org remained fully operational throughout.
- No personally identifiable information (PII) of RubyGems.org users nor Ruby Central financial data was accessed or transferred.
- The production database, S3 buckets, and CI/CD pipeline were unaffected.
Nonetheless, the existence of unrotated credentials and the public disclosure of continued access constitute a serious procedural failure, and we are treating it as such.
## How Was The Incident Resolved?
After regaining control of the AWS account, Ruby Central:
1. **Revoked all existing root and IAM credentials**, created new MFA-protected access, and moved them to a restricted vault with per-user audit logs.
2. **Rotated all related secrets and tokens**, including DataDog, GitHub Actions, and other external system integrations.
3. **Enabled AWS CloudTrail, GuardDuty, and DataDog alerting** for any root login, password change, or IAM modification.
4. **Reviewed all IAM roles and policies** to ensure least-privilege access and removed legacy permissions.
5. **Began a full end-to-end security audit** with external advisors, covering infrastructure, credential storage, and incident-response procedures.
6. **Updated the Ruby Central Security Runbook** to include immediate password and key rotation upon personnel or role changes, quarterly credential reviews, and coordinated communication steps for any future incident.
## Root Cause Analysis
After a post-mortem review, the root cause of the security incident was two-fold:
1. While Ruby Central correctly removed access to shared credentials through its enterprise password manager prior to the incident, our staff did not consider the possibility that this credential may have been copied or exfiltrated to other password managers outside of Ruby Central’s visibility or control.
2. Ruby Central failed to rotate the AWS root account credentials (password and MFA) after the departure of personnel with access to the shared vault.
Both of these events enabled the unauthorized actor to access RubyGems.org production infrastructure where they attempted unsuccessfully to lock out authorized personnel and frustrate recovery efforts.
## What We Are Doing to Prevent Future Incidents?
RubyGems.org is a critical service that the entire Ruby community depends on, and we take that responsibility seriously. For RubyGems.org to succeed, it must not only maintain near-perfect operational uptime but also earn the community’s trust that it is operated professionally, that its operators can attest to the integrity of both the data and the code it serves to millions of Ruby applications worldwide, and that the privacy of the data we hold remains intact.
To that end, we commit to the following improvements:
1. Update our access revocation procedures and checklists to ensure access is also revoked to the Ruby Central enterprise password manager.
2. Update our access revocation procedures to ensure any non-federated credentials (particularly shared credentials) are rotated quickly after a personnel separation.
3. Commission **an independent security audit** of Ruby Central’s systems and access.
4. Finalize formal Operator and Contributor Agreements to clearly define who may hold production access and under what conditions
## Why Did Ruby Central Treat This Event as a Security Incident?
[As part of our recent actions](https://rubycentral.org/news/our-stewardship-where-we-are-whats-changing-and-how-well-engage/), we determined that many RubyGems.org systems were controlled by a single individual; an untenable situation for a service of this importance.
To provide additional context to the community about our decision to formalize production access through Operator and Contributor Agreements, and to explain why we treated this incident as a genuine security event, we are sharing context from conversations between Mr. Arko and Ruby Central personnel leading up to the September 18th access changes.
In early August 2025, Ruby Central began reviewing its open source contractor budget, which totaled approximately $762,000 in 2024\. On-call coverage is critical for a service like RubyGems.org and allows us to ensure operational continuity and rapid response to production incidents. Every on-call shift has a primary who is directly responsible for responding to incidents, and a secondary who is there to serve as a back up and an escalation point, if and when needed.
For RubyGems.org, the secondary on-call rotation, which serves as a backup layer, was rarely activated. Ruby Central’s long-term goal was to transition this limited paid function into a distributed network of volunteer operators who could share those responsibilities without additional cost, ensuring both operational continuity and financial sustainability.
Following these budget adjustments, Mr. Arko’s consultancy, which had been receiving approximately $50,000 per year for providing the secondary on-call service, submitted a proposal offering to provide secondary on-call services at no cost in exchange for access to production HTTP access logs, containing IP addresses and other personally identifiable information (PII). The offer would have given Mr. Arko’s consultancy access to that data, so that they could monetize it by analyzing access patterns and potentially sharing it with unrelated third-parties.

The board and leadership team determined that this proposal crossed important ethical and legal boundaries, introducing privacy, conflict-of-interest, and governance concerns inconsistent with Ruby Central’s responsibilities as stewards of the ecosystem. These concerns set in motion Ruby Central’s decision to adopt the new operating model and governance structure detailed [in this blog post](https://rubycentral.org/news/our-stewardship-where-we-are-whats-changing-and-how-well-engage/). With this context in mind, when we discovered that Mr. Arko had retained access to production systems containing PII, it prompted us to consider it as a security incident and to respond immediately.
Based on our preliminary investigation, as of the publication of this post, we have no evidence to indicate that any RubyGems.org data was copied or retained by unauthorized parties, including Mr. Arko.
We recognize that these events have raised valid questions within the community and tested confidence in how Ruby Central fulfills its stewardship role. Our intent in sharing this level of detail is to be transparent about what occurred, what we have learned, and what we are doing to prevent it from happening again. We are hopeful that this openness marks a meaningful step toward rebuilding trust in our stewardship and demonstrating that accountability and collaboration remain central to how we serve the Ruby ecosystem.
We are deeply grateful to the community for holding us accountable and for the patience and professionalism shown during this process. Ruby Central remains committed to transparent, responsible stewardship of the RubyGems infrastructure and to maintaining the security and trust that the Ruby ecosystem depends on.
Sincerely,
Shan Cureton
Executive Director
## Editorial Notes
- **January 6, 2025:** This post was updated to correct a typographical error in the timeline. The production access notification timestamp was corrected from **18:40 UTC** to **18:04 UTC** to match the time the email was sent. No other content was changed.
### Weekly Update — Friday, October 3
URL: https://rubycentral.org/news/weekly-update-friday-october-3/
Last updated: 2025-10-03T22:30:56.000Z
Thanks for holding us to a regular cadence. I’m liking being able to share with you all regularly.
Today’s Friday update is brief, as we shared a comprehensive status on [Tuesday](https://rubycentral.org/news/our-stewardship-where-we-are-whats-changing-and-how-well-engage/), and much of that work is still in motion. Here’s where things stand:
### **Production services (rubygems.org operations)**
- We remain on track to finalize and execute **operator agreements** on the schedule we set.
- Service is stable; publishing and installing gems continue as normal with on-call coverage active.
### **Code & repositories (Ruby Gems/Bundler and rubygems.org source)**
- A narrow set of elevated permissions remains under the temporary procedural hold while roles are confirmed and least-privilege + MFA are verified. This matches the process we outlined Tuesday.
### **Governance & stewardship**
- We’re drafting a **proposed governance framework** to clarify roles, accountability, and review cycles. We’ll share more soon.
- We have launched our **Corporate Stewardship Program**. If your company can offer in-kind engineering or adjacent support (e.g., SRE, security review, incident response, compliance), please reach out: [contact@rubycentral.org](mailto:contact@rubycentral.org).
### **Discovery reminder**
We continue our discovery work related to supply-chain security and governance concerns. We’ll share facts as soon as we’re able. [As noted Tuesday](https://rubycentral.org/news/our-stewardship-where-we-are-whats-changing-and-how-well-engage/), our current focus is formalizing accountability and auditability.
### **How to engage**
- We’ll keep publishing updates on a predictable **weekly Friday** schedule.
- Companies needing security/controls details can request a briefing at [contact@rubycentral.org](mailto:contact@rubycentral.org).
- Please continue sending questions via our [Community Feedback form](https://forms.gle/J3mDEU85TXpRur7Z6?ref=rubycentral.org); we’ll batch responses on cadence.
With respect,
**Shan Cureton**
Executive Director, Ruby Central
### Our Stewardship: Where We Are, What’s Changing and How We’ll Engage
URL: https://rubycentral.org/news/our-stewardship-where-we-are-whats-changing-and-how-well-engage/
Last updated: 2025-10-07T22:30:22.000Z
Dear Rubyists,
Thank you for giving me this opportunity to share with you. We take our stewardship of the Ruby Gems ecosystem seriously. Our mission is clear: keep the language and the infrastructure you rely on stable, safe, and trustworthy. Before we get to what the next steps will be, here is a quick recap from the video that we shared last week.
### **Moving parts:**
- We recognize there is confusion between some of the moving parts in this conversation, and we would like to add some clarity around that.
- The rubygems client and bundler source code both live in the `rubygems/rubygems` Github monorepo
- Similarly, the source code for the [rubygems.org](http://rubygems.org/?ref=rubycentral.org) service lives in the `rubygems/rubygems.org` Github repo
- Lastly, the production [rubygems.org](http://rubygems.org/?ref=rubycentral.org) service is run on AWS servers by Ruby Central operators.
- These components are distinct but related, and work together to provide gems from developers to end-users. Ruby Central’s role is to ensure the whole platform runs securely and reliably end-to-end, from gem publishing to gem hosting and, eventually, to gem installation on end-user machines.
- The `rubygems` repository [README](https://github.com/rubygems/rubygems/blob/master/README.md?ref=rubycentral.org#supporting) and the `rubygems.org` repository [README](https://github.com/rubygems/rubygems.org/blob/master/README.md?ref=rubycentral.org#support) both explicitly state that they are “managed by Ruby Central”
### **Where we are**
- We implemented a temporary, procedural change to privileged access to the `rubygems/rubygems` repository, to the `rubygems/rubygems.org` repository and to the production systems for the rubygems.org service. Why we did this and how long it lasts are outlined in the next section.
- Publishing and installing gems continue as usual; on-call coverage and incident response remain active.
- We are prioritizing the finalization of Operator Agreements for access to our [Rubygems.org](http://rubygems.org/?ref=rubycentral.org) production systems as a priority, followed by Contributor Agreements for contributions to the open-source above-mentioned repositories, both on a firm timeline. The operator agreements are essential to define who can access production systems, under what conditions, and with what accountability. This prevents unilateral control over critical infrastructure and removes single points of failure. Similarly, contributor agreements will clarify how code is contributed, reviewed, and licensed, ensuring contributions remain open source, transparent, and aligned with Ruby Central’s mission.
- We are also conducting a final review of credentials to ensure that no legacy access remains in the system.
### **Why we acted**
- Ruby Central is responsible for the security, maintenance, and availability of the RubyGems service, including the canonical clients, RubyGems and Bundler, which install and update gems. To meet that duty of care, privileged access and operational decisions must align under a single, accountable stewardship model from codebase to production.
- Unlike open-source projects that are simply distributed “as-is” with no warranties, but similar to other infrastructure projects, these codebases underpin a service operated by Ruby Central, and its canonical clients, relied on by millions of developers every day to securely download and publish gems.
- A recent access review had revealed that many systems were under the control of a single individual, which we determined presented a risk to the security and operational sustainability of those systems. We had intended to resolve this over time. However, the departure of key maintainers and contribution data showing that some maintainers had long periods of inactivity (Least Privileged Access), changed the timeline.
- During our review, we also saw potential privacy risks stemming from gaps in accountability. No signs of unauthorized access or PII exposure were found. At the same time, new privacy laws in multiple jurisdictions require Ruby Central to have agreements in place with operators that protect the personal information in its control. To comply with these obligations and maintain community trust, we moved quickly to strengthen security, increase auditability, and set clear responsibilities.
### **How we decided to address these gaps**
- For production access (live systems), we’ve put a short, procedural hold on top-level/admin permissions while we finalize operator agreements, enforce least-privilege + MFA, rotate keys, and verify audit logging. Service remains uninterrupted.
- For code access (RubyGems/Bundler repo), community PRs continue as normal, while a small set of direct commit/owner rights are temporarily paused and are being re-granted as roles are confirmed.
- We have set a clear deadline to complete this work within the next two weeks, so access can be restored in an orderly, transparent way.
### **What this is—and what it isn’t.**
- **It is:** Risk-reduction and accountability; signed operator and contributor agreements, MFA, audit logging, and periodic access reviews for privileged accounts.
- **It is not:** This is not a takeover, a shutdown of contribution, or commentary on individuals. We accept responsibility for how our initial communications created the impression of sponsor-driven action. In practice, we focused first on contacting the team members directly affected and left our broader communication for business hours. Ultimately, we moved fast without providing enough advance detail, did not publish the rationale and timeline at the same time as the changes, and let routine sponsor briefings be conflated with direction. To rebuild trust, we’re sharing more detailed rationale and checkpoints (operator agreements executed, access restorations, audit verifications, uptime/MTTR), updating a public FAQ on a set cadence, and reiterating that Board decisions are independent and not contingent on funding.
- Additionally, we’d like to address a related concern we’ve heard from the community. Publishing a gem on the [rubygems.org](http://rubygems.org/?ref=rubycentral.org) service does not mean that Ruby Central can “take” it from you. Ownership changes on rubygems.org are handled through the standard administrative procedures available to gem owners. Ruby Central has not unilaterally altered database records or reassigned ownership. In other words, ownership changes are initiated by gem owners in accordance with established procedures.
### **On Our Communication**
We could have communicated earlier and in more detail. And we won’t stop apologizing for the confusion that caused. We are improving cadence and clarity so you always know what’s changing, why, and when.
### **The Latest**
- In the last few weeks, partial or speculative information has spread quickly and caused concern. We recognize our obligation is to the entire Ruby Community and we appreciate your efforts to hold us to account. We ask for your patience as we respond to your concerns as quickly as we are able.
- In an open community, information and personnel updates move quickly. We speak regularly with current sponsors as part of routine briefings and potential sponsors regarding organizational support. Their input is not instruction; their input did not direct our actions. The Board acted independently, and financial support was NOT conditioned on taking these steps.
- We know that everyone wants to know about the status of the repos. An update will be out soon. I know this isn’t the best news. But that is all that can be shared at the moment.
- We will moderate official channels to keep discussion constructive and aligned with our Code of Conduct.
- We’ll publish updates on a predictable schedule (weekly on Fridays).
We want to assure the community that we have our heads down and all hands have been on deck to resolve this in a way that will be the best for the community. This will take a little bit of time. There are a number of moving pieces we are trying to resolve and we know that our next steps are integral in improving your trust with Ruby Central.
### **How we will engage**
- **Written FAQ + updates**: Recurring posts that track decisions, timelines, and what’s next.
- **Async questions:** A short [form](https://docs.google.com/forms/d/e/1FAIpQLSdzz3Djtp8J-oHdI7IEzwqiIH8%5F2O1Ldc2e1OgEvRE7RWgdBQ/viewform?ref=rubycentral.org) to collect questions between live sessions. We’ll publish responses on a regular cadence.
- **Security briefings for companies:** If your security team needs details on controls and escalation paths, contact [**contact@rubycentral.org**](mailto:contact@rubycentral.org).
### **Our commitments**
- **Mission first:** Stability, safety, and trust for the RubyGems ecosystem.
- **Timely and accurate information:** We’ll say what we know, what we’re doing, and what’s still in progress.
- **Transparency and consistency:** One source of truth, mirrored to official channels.
- **Respectful dialogue:** Strong opinions welcome; personal attacks and speculation are not.
We truly appreciate you for all of your concerns and for holding us to a high standard.
With respect,
**Shan Cureton**
Executive Director, Ruby Central
### Strengthening the Stewardship of RubyGems and Bundler
URL: https://rubycentral.org/news/strengthening-the-stewardship-of-rubygems-and-bundler/
Last updated: 2025-09-25T16:14:00.000Z
*Updated 2025-09-25 to reflect: Postponement of Q&A Session and link to updated statement.*
**Ruby Community,**
At the heart of Ruby Central’s mission is our responsibility to steward the open source tools that power the Ruby ecosystem. That commitment is only as strong as the people and processes behind it. Over the past several months, we have been carefully reviewing how RubyGems.org, RubyGems, and Bundler are governed, and we are making changes to ensure these critical services are supported in a sustainable, transparent, and secure way.
As the nonprofit steward of this infrastructure, Ruby Central has a fiduciary duty to safeguard the supply chain and protect the long-term stability of the ecosystem. In consultation with legal counsel and following a recent security audit, we are strengthening our governance processes, formalizing operator agreements, and tightening access to production systems. Moving forward, only engineers employed or contracted by Ruby Central will hold administrative permissions to the [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) service.
In addition, with the recent increase of software supply chain attacks, we are taking proactive steps to safeguard the Ruby gem ecosystem end-to-end. To strengthen supply chain security, we are taking important steps to ensure that administrative access to the RubyGems.org, RubyGems, and Bundler is securely managed. This includes both our production systems and GitHub repositories. In the near term we will temporarily hold administrative access to these projects while we finalize new policies that limit commit and organization access rights. This decision was made and approved by the Ruby Central Board as part of our fiduciary responsibility. In the interim, we have a strong on-call rotation in place to ensure continuity and reliability while we advance this work. These changes are designed to protect critical infrastructure that power the Ruby ecosystem, whether you are a developer downloading gems to your local machine, a small or large team who rely on the safety and availability of these tools.
Looking forward, our goal is to move these projects into a healthier, more transparent and community-centered governance model that is more in line with OSS development. We envision a structure with a public core team to set direction, a committers team to help advance the work, and a triage team to support issues and PRs. Ruby Central will play a supporting role in collaboration with the Ruby Core team, and we will continue to provide project-based grants to ensure these projects evolve in a way that is secure, community-driven, and sustainable.
Looking ahead, Ruby Central is focused on building the right conditions for open source stewardship to thrive. This includes modernizing Bundler and RubyGems to make them more performant, ensuring that decision-making is transparent and equitable, with continued investment in the engineers and infrastructure needed to maintain a secure supply chain. Our aim is to shift away from informal arrangements toward a model of stewardship that truly reflects the collaborative nature of open source.
We know these are meaningful changes, and we want to provide space for conversation. Ruby Central will host a community Q&A session with members of our Board, Shan Cureton, our Executive Director, and Marty Haught, our Director of Open Source on September 23 at 1pm-2pm EST. This will be an opportunity to share more about our governance work, answer your questions, and hear directly from you about the future of RubyGems and Bundler. **You can register for the Q&A session here**. **EDIT:** We recognize that we had scheduled the Q&A session on a major holiday in addition to it being an inconvenient time for our global community. This Q&A has been postponed and a new date & time announcement will be shared soon with those considerations in mind. We invite you to [watch this statement from our Executive Director](https://youtu.be/VyCiE3GjQps?ref=rubycentral.org). This update is intended to ensure everyone receives the same information and can view it at a time that works best for them.
We want to express our deep gratitude to the many cohorts of maintainers who have contributed to Bundler and RubyGems over the past two decades. Ruby tooling would not be what it is today without their dedication and leadership. Their work laid much of the foundation we are building on today, and we are committed to carrying that legacy forward with the same spirit of openness and collaboration.
The Ruby community has always thrived on collaboration, accountability, and care. These changes are about carrying that spirit forward and ensuring the infrastructure we all depend on remains healthy, secure, and resilient for the long run.
With gratitude and commitment,
**Ruby Central**
### Company Spotlight: Buzzsprout and the Lasting Power of "Vanilla" Ruby on Rails
URL: https://rubycentral.org/news/company-spotlight-buzzsprout-and-the-lasting-power-of-vanilla-ruby-on-rails/
Last updated: 2025-08-30T20:23:33.000Z
Back in 2007, [**Higher Pixels**](https://www.higherpixels.com/?ref=rubycentral.org) was a Rails-powered product company with two core offerings: Tick for time tracking, and M Sites for helping small nonprofits create websites.
Around this time, many of M Site’s customers were local churches across the U.S. **When church leaders started asking Tom Rossi and his co-founder how they could publish their sermons online, it sparked an idea that would evolve into something much bigger than they could have imagined.**
The solution became [**Buzzsprout,**](https://buzzsprout.com/?ref=rubycentral.org) which is now one of the world’s leading podcast hosting platforms.
**Launched in 2008, Buzzsprout has helped over 400,000 podcasters get their shows online.** It is particularly loved by podcasters in the Ruby and Rails ecosystem and used by many, including [Remote Ruby,](https://www.remoteruby.com/?ref=rubycentral.org) the [RubyGems Podcast,](https://www.buzzsprout.com/?ref=rubycentral.org) and more.
[**\[Watch our YouTube interview with Tom Rossi here\]**](https://www.youtube.com/watch?v=%5F9aV0-WDD6E&ref=rubycentral.org)
# The Journey to Rails & Buzzsprout
Higher Pixels began as a client services company in the mid-90s. In 2001, Tom Rossi and his co-founder Kevin Finn decided to make a pivotal shift. Instead of continuing to build software for other people, they decided to create their own products.
One of the first of those products was Tick, a time-tracking tool inspired by their own frustrations with client work. “It was all about tracking time to hit your budgets,” Tom explained to us in an [interview.](https://www.youtube.com/watch?v=%5F9aV0-WDD6E&ref=rubycentral.org) “At the end of a project, you’d realize you blew your budget a week ago and nobody knew. Tick helped solve that.” The product quickly found a loyal user base and remains in use today, despite the team shifting its focus to newer products.
**In 2005, Tom discovered Ruby on Rails through the now-famous “build a blog” demo showcasing Rails.**
“We were a Microsoft shop before that,” Tom explained. “But Rails provided focus, not just in how you build software, but how you build a product. **We started building with Rails and haven’t looked back.”**
During this period, Tom rebuilt M Sites on Rails. And when church leaders started asking how to share sermons online, the Higher Pixels team saw an opportunity. **“We built a very simple application to be able to build a podcast,” Tom said. “We had no idea how big podcasting would be.”**
# Buzzsprout Today
**Today, Buzzsprout is a podcast hosting service trusted by over 120,000 active podcasters.** It has scaled through the iPhone boom, the ‘Serial’ wave, and the pandemic podcast explosion, thanks in part to Ruby on Rails.
**Buzzsprout’s growth has been matched by its features, which include:**
- **Podcast hosting & distribution:** Easily publish episodes to Apple Podcasts, Spotify, and every major directory.
- **Magic Mastering:** AI-powered audio cleanup for studio-quality sound.
- **CoHost AI:** Automatically generate transcripts, show notes, and chapters.
- **Advanced analytics:** IAB-certified stats on downloads, devices, and listener locations.
But as Tom says, what differentiates Buzzsprout isn’t just its tools. Their team is known for its first-class support for the podcasting community.
“Podcasters are often introverted,” Tom shared. “They don’t always get a lot of affirmation. **Our support team isn’t just answering technical questions, they’re encouraging people and helping them push through challenges.”**
# Building with “Vanilla” Ruby on Rails
Higher Pixels has always made a deliberate choice to keep the tech behind their products “as vanilla as can be.” Rather than chasing the latest frameworks or experimenting with untested tools, **they’ve leaned into Rails’ conventions and have trusted the opinions of the broader community.**
This philosophy has allowed Buzzsprout to scale cleanly and move fast. “**Rails is why we can ship features competitors can’t,”** Tom said. “For example, we built fully native iOS and Android apps in under a year. The only reason we could do that was because we kept our Rails codebase simple and maintainable.”
Equally important has been the way Higher Pixels approaches collaboration. As a product company first, they prioritize delivering value to users rather than chasing technical novelty. **That means cultivating what Tom calls a “healthy tension” between designers and developers.**
“If one side dominates, the product pays the price,” he explained. “If designers dominate, you end up with something overly complicated. If programmers dominate, you end up with something efficient but not usable. That tension has always been important to us.”
# Giving Back to the Ruby on Rails Ecosystem
Buzzsprout has long been a supporter of the Ruby on Rails ecosystem, which is one reason why many Ruby podcasters (like Marty Haught and David Hill, co-hosts of the [**RubyGems Podcast**](https://www.buzzsprout.com/?ref=rubycentral.org)) have trusted the platform.
The company has also been a sponsor of Rails World since its inception. **This year, they are even funding Ruby podcasters to attend the conference in Amsterdam and setting up an on-site recording studio so Rails creators can interview others and share stories with the community.**
Looking ahead, Tom hopes Buzzsprout can contribute technical expertise back to Rails through open sourece. **One area where the team’s experience could be especially valuable is serving public assets at scale.**
Buzzsprout currently handles hundreds of thousands of RSS feeds and millions of MP3 requests, all of which must be delivered quickly and reliably to podcast directories and apps worldwide. **Unlike private file storage, which Rails’ Active Storage handles elegantly, Buzzsprout’s use case requires high-volume, public-facing delivery of large assets.** Optimizing this flow means reducing API calls, managing CDN performance, and ensuring files remain instantly accessible even under sudden traffic spikes.
“37signals has done an excellent job around *private* file storage,” Tom says. “But for us, it’s the opposite. We don’t want it secure. We want it open to the public, and we want to limit the number of API calls being made to serve those assets. That’s where we think Buzzsprout might be able to uniquely help Rails.”
As Tom says, **“We’ve benefited so much from Rails. Now we’re trying to figure out how we can bring that back into the ecosystem.”**
# Why Choose Ruby on Rails Today
For Tom, there’s no question about whether new startups should choose Ruby on Rails for their tech stack. “It’s just an incredible framework to move fast and build product. **I still think it’s the best thing out there for building web software.”**
That speed to market has always been a hallmark of Rails. But beyond speed, it provides a foundation that makes long-term growth possible. By following conventions and keeping their code “as vanilla as possible,” Higher Pixels has avoided the technical debt traps that slow down many young companies.
For Tom, that’s the real power of Rails: a framework that supports both rapid iteration in the early days and sustainable growth over time. **“It’s not just about moving fast,” he says. “It’s about building something that can last.”**
**Watch our interview with Tom Rossi on Ruby Central's YouTube channel:**
### Inspired By RailsConf: The Ruby Friends App
URL: https://rubycentral.org/news/inspired-by-railsconf-the-ruby-friends-app/
Last updated: 2025-08-26T05:46:31.000Z
When Joe Masilotti attended RailsConf 2025 in July, he noticed something small but interesting: the QR codes on everyone’s badges. Scanning one pulled up a contact card with the person's phone number and email address. While useful, this felt a little too personal for someone you might have met less than five minutes prior.
But it gave Joe an idea.
What if there was a simpler, more intentional way for conference attendees to share the information they want and, in turn, more easily remember who they connected with?
**Less than a month later, this idea became the** [**Ruby Friends app.**](https://rubyfriends.app/?ref=rubycentral.org)
## **Building With Hotwire Native**
Joe’s journey with Rails started over ten years ago. At the time, he was an iOS developer at a consulting agency and got thrown into a Rails project without any prior experience. Over time, he shifted more toward Rails, but he never lost his mobile background.
With Ruby Friends, he saw a chance to bring both worlds together. **He built the app with Hotwire Native, which allowed him to launch it across web, iOS, and Android in under a month, with feature parity on all three.**
“This is a way for me to use my iOS, Android knowledge, and Rails experience together,” Joe said in a [video interview](https://www.youtube.com/watch?v=pE1vVK7AbZM&ref=rubycentral.org) with Ruby Central. “It’s been really fun for those worlds to collide.”
## **Future Plans**
Ruby Friends started as a simple website where Rubyists could create a profile with their photo, a short bio, and links to the platforms where they actually want to connect, like GitHub, Twitter, or Bluesky.
However, Joe is building quickly and hopes to experiment with NFC integrations and develop more features to make conference networking feel more natural and stay connected with your Ruby friends.
While this idea could work for any developer community, Joe has no plans to move the app beyond Ruby in the foreseeable future (if ever). “By starting with Ruby, I can tap into the network I already know, and I can actually use the app myself,” he shares.
**Joe will be a keynote speaker at Rails World 2025 in Amsterdam next month, where he is excited to use Ruby Friends and get user feedback from other attendees.**
## **Watch the Interview**
We sat down with Joe to discuss how he built [Ruby Friends](https://rubyfriends.app/?ref=rubycentral.org) so quickly, how the app can improve networking in the Ruby ecosystem, and potential features, business, and collaboration ideas.
**Watch** [**here:**](https://www.youtube.com/watch?v=pE1vVK7AbZM&ref=rubycentral.org)
### Ruby Central's OSS Changelog: August 2025
URL: https://rubycentral.org/news/ruby-centrals-oss-changelog-august-2025/
Last updated: 2025-08-22T18:44:42.000Z
Hello, and welcome to the August newsletter. Read on for announcements about our Open Source Program and a report of the OSS work we’ve done over the past month!
As mentioned in our previous newsletters, we will now be sending out separate updates for the Open Source Program and general Ruby Central organization and community news.
**You can expect our general Ruby Central newsletter (the Ruby Central README) in your inbox later this month.**
## Open Source Program Announcements
### New ways to support RubyGems.org: A note from Marty
After giving my keynote at Baltic Ruby on sustainable open source, I was approached by several people who wanted to know about how the RubyGems service was funded. **This led me to write** [**a post going into detail about the funding model**](https://rubycentral.org/news/rubygems-org-funding-model-a-new-path-for-community-led-growth/) **for RubyGems.org that I published on August 1st.**
One suggestion that stood out during my hallway conversations was when an attendee asked if their company could provide RubyGems.org with money on the spot. I told him about our sponsorships, but it was too much effort, as it would involve other leaders in the company to get involved. If we gave him a way to make a small but meaningful payment by credit card, he could get it done. **This led to the addition of supporter levels of $2,500 and $5,000 per year. Those levels were selected because they are within reason for a profitable software company or consultancy.**
Given how many companies build with Ruby, it seemed like a great opportunity to build support for our operations. If this unlocks a new way for you or someone you know to get involved with supporting our work, **take a moment to** [**read more about it here**](https://rubycentral.org/open-source/#/portal/signup) **(and share this news with your #RubyFriends!).**
**We'd also like to thank our first** [**supporters**](https://rubygems.org/pages/supporters?ref=rubycentral.org) **for their generosity in giving back to RubyGems.org:**
- [**CloudAMQP**](https://www.cloudamqp.com/?ref=rubycentral.org)
- [**Pennylane**](https://www.pennylane.com/?ref=rubycentral.org)
- [**GoBetween**](https://gobetweenlab.com/?ref=rubycentral.org)
- [**SerpAPI**](https://serpapi.com/?ref=rubycentral.org)
- [**Coffee And Code**](https://www.coffeeandcode.com/?ref=rubycentral.org)
- **+3 anonymous supporters**
Not every supporter wishes to be recognized and may choose to remain anonymous.
**If you'd like to appear in next month's Changelog and on our** [**Supporter page,**](https://rubygems.org/pages/supporters?ref=rubycentral.org) **or simply** [**give back**](https://rubycentral.org/#/portal/signup) **to the OSS work you rely on, we would greatly appreciate your support!**
### The final RailsConf

Several of the RubyGems team members attended [RailsConf 2025](https://railsconf.org/?ref=rubycentral.org). This was the largest RailsConf since the pandemic, and it felt like a proper sendoff.
The team hosted a table during the hack space on community day. **We had great conversations, five PRs submitted, and lots of folks eager to get involved!** I heard about the various challenges and unusual edge cases that teams have, which helps us think about where we should invest our time and focus to have the most impact on the ecosystem.
Another highlight was watching Nick Quaranto, creator of GemCutter (the app that became [RubyGems.org](http://rubygems.org/?ref=rubycentral.org)), join Samuel Giddins, our Security Engineer in Residence, to talk about the evolution of [RubyGems.org](http://rubygems.org/?ref=rubycentral.org). It brought back many memories of how we used to do things in Rails, with a fun section on remembering gems we no longer use.
We held a team offsite the day after the conference, where we had great discussions around refining our policies on gem deletion, archiving, gem ownership, and unreachable maintainers. We were largely in agreement, and copious notes were taken. We have a follow-up to draft these policies for internal review.
**—Marty Haught, Director of Open Source**

RubyGems team offsite after RailsConf 2025
## RubyGems News
In July, we shipped [**Bundler 2.7.0**](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#270-2025-07-16) and [**RubyGems 3.7.0**](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#370--2025-07-16), marking a major milestone in our roadmap toward Bundler 4\. These releases introduce the new `simulate_version` setting, making it easier for developers to test breaking changes early and share feedback. We also continued work on long-requested improvements across RubyGems and Bundler, including experimental support for prebuilt binaries.
***Bundler 2.7.0 and RubyGems 3.7.0 are out!***
- This release marks a major milestone in the roadmap toward Bundler 4\. With `bundle config simulate_version 4`, users can now try out upcoming breaking changes in Bundler 4 ahead of time, helping gather feedback and ease the eventual transition.
- Although the releases were mostly complete last month, we took additional time to carefully review and tag unreleased changes so our tooling could generate a clean and informative changelog. We also [published a blog post](https://www.notion.so/150d7bddd38780988929f2d399093288?pvs=21&ref=rubycentral.org) summarizing the highlights of the release, and the release was mentioned in [Ruby Weekly](https://rubyweekly.com/issues/759?ref=rubycentral.org) and [Reddit](https://www.reddit.com/r/ruby/comments/1m22l57/bundler%5Fbundler%5Fv27%5Flast%5Frelease%5Fbefore%5Fbundler%5F4/?ref=rubycentral.org).
- As part of the post-release cycle, we addressed some reported issues and community feedback:
- The planned change to install gems in a `.bundle` folder per application (instead of globally) has been [**delayed**](https://github.com/rubygems/rubygems/pull/8867?ref=rubycentral.org), pending resolution of known issues. We still hope to ship this in Bundler 4.
- The deprecation of `bundle install --force` has been [**reverted**](https://github.com/rubygems/rubygems/pull/8843?ref=rubycentral.org), following user feedback.
[**Improvements in Bundler CLI documentation**](https://github.com/rubygems/rubygems/pull/8861?ref=rubycentral.org)
- We noticed that some CLI commands and flags were not properly documented, making them harder for users to discover. Thanks to a [contribution](https://github.com/rubygems/rubygems/pull/8861?ref=rubycentral.org) by [@Edouard-Chin](https://github.com/Edouard-Chin?ref=rubycentral.org), we now have a CI check that ensures new commands and flags are reflected in the official documentation.
- The implementation introspects Thor commands and flags used by Bundler and verifies they are included in the man pages, making the CLI more consistent and discoverable.
**Gems with Prebuilt Binaries**
- After months of groundwork and iteration, experimental support for Python-style “wheels” has landed in RubyGems, thanks to [@segiddins](https://github.com/segiddins?ref=rubycentral.org).
- This work introduces a new compatibility model for gems with native extensions, using `tag sets` (inspired by Python) to represent which platforms a gem can run on. This solves long-standing limitations in the legacy `Gem::Platform` system, which struggled to represent both "what can run" and "what's running now" in a backward-compatible format.
- The feature is still under active development and review, and a formal RFC is coming soon. Support in Bundler will follow before this ships more broadly.
## [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) News
This month, [RubyGems.org](https://rubygems.org/?ref=rubycentral.org) continued to scale and improve its services with the support of our infrastructure donors: [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Fastly](https://www.fastly.com/?ref=rubycentral.org), and [Datadog](https://www.datadoghq.com/?ref=rubycentral.org).
The following are highlights of what the team worked on this month:
[***RubyGems.org***](http://rubygems.org/?ref=rubycentral.org) ***Organizations launches in private beta***
- [Organizations](https://guides.rubygems.org/organizations/getting-started/?ref=rubycentral.org) is one of the longest-standing feature requests for [RubyGems.org](https://rubygems.org/?ref=rubycentral.org). It allows teams and companies to better manage ownership and permissions across multiple gems under a shared namespace.
- We’ve launched the feature in **private beta**, and are currently collecting feedback from early users. We plan to open it up to more teams in the coming weeks. More information will be shared in an upcoming blog post.
## **Thank you**
A huge thank you to all the contributors to RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) this month! We deeply appreciate your support and dedication.
### Contributors to RubyGems:
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@dgonzdev](https://github.com/dgonzdev?ref=rubycentral.org) Dgonzdev
- [@rye-stripe](https://github.com/rye-stripe?ref=rubycentral.org) Peteris Rudzusiks
- [@djbender](https://github.com/djbender?ref=rubycentral.org) Derek Bender
- [@roberthopman](https://github.com/roberthopman?ref=rubycentral.org) Robert Hopman
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@hlascelles](https://github.com/hlascelles?ref=rubycentral.org) Harry Lascelles
- [@Edouard-chin](https://github.com/Edouard-chin?ref=rubycentral.org) Edouard Chin
- [@rhenium](https://github.com/rhenium?ref=rubycentral.org) Kazuki Yamaguchi
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
### Contributors to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org):
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@mghaught](https://github.com/mghaught?ref=rubycentral.org) Marty Haught
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@landongrindheim](https://github.com/landongrindheim?ref=rubycentral.org) Landon Grindheim
- [@a-mitch](https://github.com/A-Mitch?ref=rubycentral.org) Alex Mitchell
- [@qrush](https://github.com/qrush?ref=rubycentral.org) Nick Quaranto
- [@spikex](https://github.com/spikex?ref=rubycentral.org) Spike Ilacqua
- [@arunagw](https://github.com/arunagw?ref=rubycentral.org) Arun Agrawal
- [@jeffwidman](https://github.com/jeffwidman?ref=rubycentral.org) Jeff Widman
- [@mullermp](https://github.com/mullermp?ref=rubycentral.org) Matt Muller
*If we missed you, please let us know so we can include you in our shout out!*
### RubyGems.org Funding Model & A New Path For Community-Led Growth
URL: https://rubycentral.org/news/rubygems-org-funding-model-a-new-path-for-community-led-growth/
Last updated: 2025-08-04T15:30:11.000Z
TL;DR: Today, we’re launching a sustainable and community-driven funding model for RubyGems.org infrastructure, maintenance, and security.
**If you build with Ruby, join us in keeping RubyGems.org, RubyGems, and Bundler secure and sustainable for years to come.** [**Contribute here**](https://rubycentral.org/#/portal/signup) **or share this with your company leadership.**
---
At Baltic Ruby in June, I delivered a keynote on building sustainable open source through the lens of RubyGems.org.
What struck me most was how many attendees didn’t realize that **Ruby Central, a nonprofit dedicated to supporting the Ruby ecosystem, is responsible for maintaining RubyGems**.
RubyGems.org powers over 1,500 gem requests per second, supports billions of downloads per month, and underpins nearly every Ruby application in the world, from one-person startups to large enterprises like GitHub.
While many developers assume RubyGems is part of the Ruby language or maintained by a single company, the reality is that it’s a community-run service, supported by a coalition of contributors and sponsors, and maintained by the team at Ruby Central.
**Because the platform has been so reliable, with** **no full outages since 2013,** it’s easy to forget about the ongoing work required to keep it running securely and efficiently. We also have ambitious goals for improving our infrastructure, tooling, and security in the coming years.
That’s why we’re launching a new funding program to ensure RubyGems remains reliable, secure, and community-driven for years to come.
# RubyGems Funding Model
RubyGems was created in 2004, and the RubyGems.org service, where gems are hosted and served, has been running under that domain since the mid-2000s.
For much of its history, RubyGems was maintained by volunteers and companies contributing developer time. In 2015, a nonprofit called Ruby Together was founded to provide more formal, community-backed support. In 2022, Ruby Together merged with Ruby Central, consolidating all funding and maintenance of RubyGems.org, RubyGems, and Bundler under a single umbrella.
RubyGems today is made possible by a combination of infrastructure donations, community memberships, corporate sponsorships, and grants to Ruby Central.
**Our core infrastructure is provided by:**
- [**AWS**](https://aws.amazon.com/?ref=rubycentral.org) (service infrastructure)
- [**Fastly**](https://www.fastly.com/?ref=rubycentral.org) (CDN)
- [**Datadog**](https://www.datadoghq.com/?ref=rubycentral.org) (observability)
- [**Honeybadger**](https://www.honeybadger.io/?ref=rubycentral.org) (application monitoring)
- [**DNSimple**](https://dnsimple.com/?ref=rubycentral.org) (domain management)
- [**Mend.io**](https://www.mend.io/?ref=rubycentral.org) (malicious gem scanning)
- [**Avo**](https://avohq.io/?ref=rubycentral.org) (admin panel)
These in-kind contributions enable us to maintain a lean operations budget.
Ongoing work, including maintenance, upgrades, on-call rotations, customer support, and security reviews, is funded primarily through donations and sponsorships.
**In 2024:**
- Support came from long-term corporate sponsors like [**Shopify**](https://shopify.com/?ref=rubycentral.org) **(via Ruby Shield)** and [**Sidekiq**](https://sidekiq.org/?ref=rubycentral.org)
- **\~60% of our budget** came from grants (AWS, Alpha-Omega, Sovereign Tech Agency)
However, grant funding is typically allocated for specific projects and is not always a renewable funding source.
**To ensure the long-term health and stability of this critical infrastructure, we would like to diversify our funding sources and provide an easier path for community members and businesses to support us long-term.**
# Why Ongoing Support Matters
RubyGems.org has quietly delivered **over a decade of nearly uninterrupted service.** Behind that is a dedicated team and continuous maintenance.
In 2024, we completed a [third-party security audit](https://blog.rubygems.org/2024/12/11/security-audit.html?ref=rubycentral.org) and outlined several goals for strengthening our infrastructure in 2025 and beyond. These include:
- Improving **software supply chain security**
- Creating a **formal disaster recovery (DR) plan** so we’re better prepared for outages
- Improving the **performance and usability** of our existing tools
Bringing in additional funding from the community will allow us to expedite moving these initiatives forward.
# Community Funding Program
We believe that open source infrastructure like RubyGems should be funded by the community it serves.
**To support that, we’re launching a new, lightweight** [**support program**](https://rubycentral.org/#/portal/signup) **that makes this possible, where businesses and developers can contribute $2,500 or $5,000 annually to directly fund RubyGems operations and maintenance costs.**
We’ve designed the program to be easy to participate in, with a contribution amount that’s small enough to avoid lengthy procurement processes, but meaningful enough to make a real impact.
**With roughly 110 supporters,** we would be able to fully fund our annual goals for operations and maintenance. In addition to our other funding sources, such as corporate sponsors, this level of community funding would enable us to expand beyond maintenance and focus on new features and enhancements that will benefit developers and gem creators.
# Where Community OSS Funding Fits In
This new program works in tandem with our existing corporate sponsorship program and individual membership program (note: we are currently working to overhaul our individual membership program, which we plan to relaunch in Q3).
**Here’s how these pieces fit together:**
| Program | Who it’s for | Amount | Benefits |
| --------------------- | ------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------- |
| Individual membership | Ruby community members | Low dollar amount – like what you might pay for a SaaS subscription | TBA – but think exclusive access to content, community spaces, & discounts on Ruby Central events |
| Open source supporter | Individuals like consultants, agency owners, & businesses that rely on RubyGems | $2,500 or $5,000 annually | Fund the operation and maintenance of RubyGems.orgName on RubyGems.org supporter page |
| Corporate sponsorship | Companies seeking greater visibility in the Ruby ecosystem while supporting our broader organizational & open source work | $10K+ annually | Marketing & PR opportunities based on sponsorship amount |
| One-time donation | Everyone! | Any amount | Flexible, no-strings-attached support for Ruby Central |
While individual membership and corporate sponsorship funds go toward funding the organization as a whole, **the open source supporter program is unique in that the funds are targeted to supporting our work on RubyGems,** [**RubyGems.org**](http://rubygems.org/?ref=rubycentral.org)**, and Bundler.** We will also be launching a supporter page on [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) in August to recognize all our community supporters.
**If you're interested in corporate sponsorship opportunities, you can reach out to sponsorships@rubycentral.org.**
Whether you’re an individual, a startup, or a large company, there’s a way to get involved and support Ruby Central!
# Join Us in Supporting the Security & Growth of Ruby’s Core Infrastructure
**RubyGems.org isn’t owned by a corporation. It’s a shared foundation that helps all of us build and run great software, and it belongs to the community.**
Our goal isn’t just to keep things running, but to create a model that will keep RubyGems strong, evolving, and community-driven for the next decade and beyond.
If you rely on RubyGems and believe in our vision, *now* is the time to support us. You can [**contribute here**](https://rubycentral.org/#/portal/signup)**.**
**If you’re a tech or business leader whose company uses Ruby and relies on RubyGems,** you can support us in reaching our goals by becoming a financial supporter of our crucial open source work.
**If you’re an engineer within an organization that builds with RubyGems,** you can support us by talking with your company leadership about how your organization can contribute to the growth and security of Ruby’s core infrastructure.
We deeply appreciate your support and look forward to keeping RubyGems.org, RubyGems, and Bundler secure and sustainable for years to come.
**\- Marty Haught**, Director of Open Source, Ruby Central
### Ruby Central's OSS Changelog: July 2025
URL: https://rubycentral.org/news/ruby-centrals-oss-changelog-july-2025/
Last updated: 2025-07-18T16:26:13.000Z
Hello, and welcome to the July newsletter. Read on for announcements about our Open Source Program and a report of the OSS work we’ve done over the past month!
As mentioned in our previous newsletters, we will now be sending out separate updates for the Open Source Program and general Ruby Central organization and community news.
**You can expect our general Ruby Central newsletter (the Ruby Central README) in your inbox later this month.**
# Open Source Program Announcements
## Ruby Central at Open Source Summit North America
At [Open Source Summit North America](https://events.linuxfoundation.org/open-source-summit-north-america/?ref=rubycentral.org), our lead security engineer, Samuel Giddins, continued discussions on supply chain security and creating a binary transparency scheme that will work across packaging repositories.
**Binary transparency**
This included developing a more comprehensive threat model that BT is meant to address, in addition to sketching out a deployment plan that will involve the different package registries witnessing each others BT logs.
**Sigstore Ruby**
Samuel also led a discussion at the Sigstore meetup at Open Source Summit around helping Sigstore client maintainers keep clients up-to-date. The conclusion was that Sigstore Ruby needs another maintainer, and the group will work to identify a good candidate to assist with maintenance and development.
## [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) Policy Launch
The new policies went live on June 30th after some final discussions with legal counsel, and integrating critical last-minute community feedback we received, including an important clarification around restricting the deletion policy in the case of actively used gems.
RubyGems engineer Colby Swandale sent out the policy announcement email to all \~230,000 [rubygems.](http://rubygems.org/?ref=rubycentral.org)org users, a first for the application. (We do not maintain any 3rd party email list, so we had to plan, schedule and send each email through [rubygems.org](http://rubygems.org/?ref=rubycentral.org) job queues).
**We have several follow-up actions for this:**
- [We’ve published a blog post](https://blog.rubygems.org/2025/07/08/policies-live.html?ref=rubycentral.org) on [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) announcing the official rollout of the policies.
- We have a backlog of policy-related customer support tickets to address.
- The team will refine the specific policies around ownership transfer, absent accounts, and gem lifecycle (deprecation, yanking, deletion).
# RubyGems News
In June, we introduced a new **Bundler 4 mode** for early feedback and continued work on the upcoming **Bundler 2.7.0** and **RubyGems 3.7.0** releases. These changes reflect our ongoing focus on flexibility, modernization, and improving developer workflows.
[**Bundler 4 mode is now available**](https://github.com/rubygems/rubygems/pull/8780?ref=rubycentral.org)
- We’ve launched a user-facing simulation mode that lets you preview Bundler 4 behavior before its final release. This feature allows developers to test upcoming breaking changes, provide feedback, and participate in shaping the final version. You can now opt in by configuring:
```bash
bundle config simulate_version 4
```

- Initially, we tried overriding the `Bundler::VERSION` constant, but this proved unreliable due to side effects like misrepresenting versions in lockfiles. After significant refactoring across specs and core logic, we isolated version-specific behaviors into the `Bundler::FeatureFlag` class.
- The result is a cleaner and more robust approach where Bundler behaves as if it's version 4, without changing the actual version.
- Why Bundler 4 and not 3? We’re matching version numbers between Bundler and RubyGems to simplify releases and reduce confusion.
**Upcoming Bundler 2.7.0 and RubyGems 3.7.0 releases:**
- This year we’re committed to releasing major versions of Bundler and RubyGems, and this is special. The last major Bundler release was `2.0.0` in 2019, but that version only dropped support for old versions of Ruby and delayed all breaking changes to a future major release. So effectively, the last “real” major Bundler release was `1.0.0` back in 2010! For RubyGems, the last major release was `3.0.0` in 2018.
- To make transitioning easier and get more community consensus with breaking changes, we will be releasing mid-year minor releases—including an easy way to try future Bundler 4 (see update above).
**Gems with prebuilt binaries**
- We [finished refactoring](https://github.com/rubygems/rubygems/pull/8703?ref=rubycentral.org) `Gem::Platform` matching logic from Bundler into RubyGems. This work will enable sharing code for platform matching between Bundler & RubyGems in preparation for wheel support hitting both projects simultaneously.
- We have already used this refactor to [improve platform](https://github.com/rubygems/rubygems/pull/8751?ref=rubycentral.org) selection in the RubyGems CLI, picking the best platform gem that matches the running platform.
- Our lead security engineer Samuel Giddins spent the majority of the month prototyping ways to encode the new platform information for wheels into existing platform strings in a backwards compatible way.
- As a part of this prototyping work, Samuel researched the translation of Python’s platform tags into the Ruby ecosystem. He found that RubyGems, unlike `CPython`, won’t need a separate ABI tag (the binary level contract between compiled code) from the Ruby tag, since Ruby implementations tend not to have stable ABIs.
- Expect a PR demonstrating wheels to hit in the coming month.
# [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) News
This month, [RubyGems.org](https://rubygems.org/?ref=rubycentral.org) continued to scale and improve its services with the support of our infrastructure sponsors: [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Fastly](https://www.fastly.com/?ref=rubycentral.org), and [Datadog](https://www.datadoghq.com/?ref=rubycentral.org).
June 2025 was another high-traffic month on [RubyGems.org](http://rubygems.org/?ref=rubycentral.org), serving over 4.08 billion gem downloads, a slight increase over May’s 4.06 billion. We served 221 million downloads on our busiest day this month.
**Ruby usage stats**
- Ruby 3.4 adoption continues to climb steadily. In June, it accounted for 10.93% of all gem downloads — up from 9.3% in May — showing strong momentum just six months after release.
- Ruby 3.2 still leads with 33.84%, meanwhile, Ruby 3.1, which reached EOL in March, dropped further to 10.15%.
- Would you like to get more insight into [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) stats? Feel free to explore [RubyGems.org ClickHouse public dataset](https://clickhouse.com/blog/announcing-ruby-gem-analytics-powered-by-clickhouse?ref=rubycentral.org).
The following are highlights of what the team worked on this month:
***PostgreSQL 14 upgrade***
- We have started updating [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) PostgreSQL, and are currently testing it in a staging environment. PostgreSQL is the main source of truth for [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) and the currently in use PostgreSQL 13 is slowly reaching EOL. We aim to upgrade to PostgreSQL 17 by the end of the summer.
- We will be using the approach explained in [pg major update](https://github.com/rubygems/pg-major-update/?ref=rubycentral.org), which has been successfully used in previous upgrades, to achieve zero-downtime. A separate blog post with more details on the process is forthcoming.
## **RubyGems Ecosystem News**
This is where we highlight exciting updates made to Ruby infrastructure projects that support our RubyGems work.
**Experimental namespacing progress:**
- [A lot of activity](https://bugs.ruby-lang.org/projects/ruby-master/issues?fields%5B%5D=issue%5Ftags&fields%5B%5D=status%5Fid&operators%5Bissue%5Ftags%5D=%3D&operators%5Bstatus%5Fid%5D=o&set%5Ffilter=1&values%5Bissue%5Ftags%5D%5B%5D=namespace&values%5Bstatus%5Fid%5D%5B%5D=&ref=rubycentral.org) continues around the experimental Namespace feature ([see May 2025 newsletter](https://blog.rubygems.org/2025/06/16/may-rubygems-updates.html?ref=rubycentral.org#interesting-ruby-news)) as numerous bugs and refinements are being addressed. Quality-of-life improvements are also starting to land, like [Namespace#eval](https://bugs.ruby-lang.org/issues/21365?ref=rubycentral.org), which simplifies testing and experimentation inside a given namespace.
**`Array#join (Enumerable#join_map)`proposal:**
- There’s growing momentum behind making joining transformed collections, a common Ruby pattern, more ergonomic. A [new proposal for Array#join with a block](https://bugs.ruby-lang.org/issues/21455?ref=rubycentral.org) and the related [Enumerable#join\_map](https://bugs.ruby-lang.org/issues/21386?ref=rubycentral.org) aim to make expressions like: `users.map(&:name).join(", ")` more elegant and expressive, by writing: `users.join_map(", ", &:name)`.
- If accepted, this could be a small but meaningful step making Ruby simpler and more readable. If this improvement matters to you, consider sharing your thoughts on the [Ruby bug tracker for Array#join](https://bugs.ruby-lang.org/issues/21455?ref=rubycentral.org) or [Enumerable#join\_map](https://bugs.ruby-lang.org/issues/21386?ref=rubycentral.org). Community feedback often helps shape which proposals move forward.
**New gems spotlight**
- June brought a few interesting new gems into the ecosystem. AWS released a fresh batch of SDK components like `aws-sdk-evs`, `aws-sdk-mpa`, and `aws-sdk-aiops`, which topped the download charts for new gems.
- Alongside those, two standout gems deserve a mention:
- [hati-command](https://github.com/hackico-ai/ruby-hati-command?ref=rubycentral.org) ([release announcement](https://www.linkedin.com/posts/mariya-giy%5Fthe-hati-command-gem-ive-been-working-on-activity-7343420184830820353-P59V?ref=rubycentral.org)) – a small gem to help structure service objects around a clear success/failure contract, encouraging clean, expressive business logic.
- [llmed](https://github.com/bit4bit/llmed?ref=rubycentral.org) (by [Jovany Leandro G.C](https://github.com/bit4bit?ref=rubycentral.org))– a no-code-friendly gem that lets you build LLM-powered applications with just Markdown blocks. AI tooling is gaining traction in the Ruby world, and `llmed` is an exciting example of what’s possible.
- We encourage you to check them out and maybe even build something fun and share it with the community.
## Thank you
A huge thank you to all the contributors to RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) this month! We deeply appreciate your support and dedication.
### Contributors to RubyGems:
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@larouxn](https://github.com/larouxn?ref=rubycentral.org) Nicholas La Roux
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@rwstauner](https://github.com/rwstauner?ref=rubycentral.org) Randy Stauner
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@tangrufus](https://github.com/tangrufus?ref=rubycentral.org) Tang Rufus
- [@antoinem](https://github.com/antoinem?ref=rubycentral.org) Antoine Marguerie
- [@joshuay03](https://github.com/joshuay03?ref=rubycentral.org) Joshua Young
- [@thomasmarshall](https://github.com/thomasmarshall?ref=rubycentral.org) Thomas Marshall
- [@ccutrer](https://github.com/ccutrer?ref=rubycentral.org) Cody Cutrer
- [@landongrindheim](https://github.com/landongrindheim?ref=rubycentral.org) Landon Grindheim
- [@MSP-Greg](https://github.com/MSP-Greg?ref=rubycentral.org) MSP-Greg
- [@Earlopain](https://github.com/Earlopain?ref=rubycentral.org) Earlopain
### Contributors to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org):
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@mghaught](https://github.com/mghaught?ref=rubycentral.org) Marty Haught
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@landongrindheim](https://github.com/landongrindheim?ref=rubycentral.org) Landon Grindheim
- [@iox](https://github.com/iox?ref=rubycentral.org) Ignacio Huerta
- [@yykamei](https://github.com/yykamei?ref=rubycentral.org) Yutaka Kamei
*If we missed you, please let us know so we can include you in our shout out!*
### Ruby Central Announces Open Source Fiscal Sponsorship Program & Hanami Support
URL: https://rubycentral.org/news/ruby-central-announces-open-source-fiscal-sponsorship-program-hanami-support/
Last updated: 2025-07-07T16:17:38.000Z
At Ruby Central, we've been exploring new ways to support open source maintainers and make their work more sustainable. After speaking with project owners across the ecosystem, we heard a common theme: fundraising requires a huge amount of time and pulls maintainers away from building and working with the community.
**As a 501(c)(3) nonprofit, Ruby Central is well-positioned to support open source projects with the administrative side of fundraising through fiscal sponsorship. And today, we’re excited to share our first partnership:** [**Hanami**](https://hanamirb.org/?ref=rubycentral.org)**!**
#### What does fiscal sponsorship mean?
Ruby Central handles the back-office aspects of fundraising, including donation processing, accounting, and reporting. This means that the Hanami team can focus more time on improving the framework. This also makes it easier for individuals and companies worldwide to contribute through a trusted and transparent structure.
#### What is Hanami?
Hanami is a lightweight and flexible approach to building Ruby web applications. It’s one of several projects that are helping expand the possibilities of how Ruby can be used. We’re excited to help remove some of the admin overhead from their work.
**If you’ve ever used Hanami, dry-rb, or rom-rb consider supporting their fundraiser here:** [**https://sponsor.hanamirb.org**](https://sponsor.hanamirb.org/?ref=rubycentral.org)**.**
#### What’s the long-term vision?
Hanami is our first fiscal sponsorship, but it won’t be the last. We’re already thinking about how this model could extend to other projects. Our goal is to ensure that important projects have the resources and visibility they need to grow and that critical libraries remain strong into the future.
In addition to helping open source projects, fiscal sponsorship also helps Ruby Central. We charge a small administrative fee (significantly lower than other platforms, such as Open Collective), which enables us to offer this level of support to more projects.
**We are excited to share more as the program continues to grow and we bring on more projects!**
### Company Spotlight: FastRuby is the Answer to Rails Tech Debt That Overwhelms Teams
URL: https://rubycentral.org/news/company-spotlight-fastruby-is-the-answer-to-rails-tech-debt-that-overwhelms-teams/
Last updated: 2025-07-02T15:53:11.000Z
What happens when your Rails app is stuck on an outdated version? You may know it needs to be upgraded, but the work feels overwhelming, risky, and no one on your team really wants to take it on.
**That’s where** [**FastRuby**](https://fastruby.io/?ref=rubycentral.org) **comes in.**
For the past eight years, FastRuby has carved out a unique (and much-needed) niche in the Ruby ecosystem: helping companies upgrade their Rails apps safely and sustainably. Founded by Ernesto Tagwerker, **FastRuby has worked with clients like SoundCloud and Power Home Remodeling, and completed more than 100 projects, with over 50,000 developer hours invested in upgrades alone.**
[](https://fastruby.io/?ref=rubycentral.org)
“Early on, we did an upgrade for Power Home Remodeling,” Ernesto explained. “We finally had one client who was excited to work with us on this very specific problem. And we thought, okay, this is great validation that there is something there.”
So why does keeping Rails apps up to date really matter?
“The number one problem is security,” Ernesto said. “There are a lot of security issues that have been discovered, and not all of them are backported to really old versions. **If you’re running Rails 4.2 in production, there are known security holes in that codebase, and you’re increasing the chances of someone exploiting it.”**
The other cost of staying on old versions is losing momentum and even increased churn on your engineering team. “You will find it harder to ship features over time because you’re working with an old version of the framework,” he said. “And nobody wants to be working with Rails 4.2 or Ruby 2.6\. Engineers want to be working with the latest versions.”
However, despite these risks, making timely Rails upgrades is a common problem. “If you don’t make it a goal every month to upgrade some of the dependencies you have, you can kind of forget about it,” says Ernesto.
The FastRuby team steps in to offer a structured path forward, taking on the work of upgrading their client’s apps while also teaching the team strategies to help them stay modern over time. “We train their engineers to know what to do and how to upgrade without a ton of risk.”
A big part of what sets FastRuby apart is their commitment to open source. While the company reserves some internal tools for client work, **they open source about 90% of the tooling they create.**
Their team maintains and contributes to a variety of upgrade and quality-focused tools, including NextRails, RubyCritic, Skunk, and RailsBump.org.
“We love to share with the community all the things we do in articles about how to upgrade,” Ernesto said. “And open source is part of our marketing strategy. If we open source the tooling that we use, we have something to write about, to talk about, to present at conferences, and that helps people find us.”
That philosophy has helped FastRuby grow from a one-person business to a company of 25 people, including 15 engineers. “We were about six people for a long time,” Ernesto said. “Then eventually, when we productized this service and created FastRuby.io, that helped us scale.”
But growth for growth’s sake isn’t the goal. **“Quality is the main thing we care about,” Ernesto emphasized. “We don’t want to grow to 100 engineers and sacrifice quality.”**
Looking ahead, the team is focused on expanding its reach to startups and small teams. “We came up with this idea of a fixed-cost monthly maintenance service,” Ernesto shared. “We work with a lot of clients who are just one person doing everything. And they now know they can add our team at a fractional cost without breaking the bank.”
Of course, like many others in the industry, FastRuby is also thinking about the impact of AI. “In the next six months, the work is not going to be delivered 100% by humans,” Ernesto said. “So we’re going to have to figure out how to shift our pricing model from hours to value.”
Through all of this, Ruby and Rails remains at the center of FastRuby’s work. “Rails is a great framework to build something really quickly with,” Ernesto said. **“The story of the one-person framework is real.”**
In addition to their client work and open source projects, FastRuby is an active supporter of the Ruby community, sponsoring open source projects like Hanami, the Philly.rb Meetup, and even RailsConf!
**At RailsConf 2025, the FastRuby team will be on-site at Hack Spaces area on day two, ready to pair with attendees and answer questions.** And Ernesto has this advice for newcomers: “Just come, find a friendly face and say hi! You’re going to see that maintainers are friendlier than you think. We’re happy to help you learn more about the tools we’ve built and work with you on improving them.”
By sharing about their work, sponsoring open source projects and events, and engaging in places like Hack Spaces, FastRuby is putting in the work to keep the Rails ecosystem modern and welcoming.
And by helping companies upgrade their apps and mentoring their teams along the way, **they are doing the kind of work that, while not flashy, is absolutely essential.**
For the teams who’ve been quietly running Rails 4.2 in production for far too long, it’s exactly the kind of help they’ve been waiting for.
### Ruby Central's OSS Changelog: June 2025
URL: https://rubycentral.org/news/ruby-centrals-oss-changelog-june-2025/
Last updated: 2025-06-25T14:00:35.000Z
Hello, and welcome to the June newsletter. Read on for announcements about our Open Source Program and a report of the OSS work we’ve done over the past month!
As mentioned in our previous newsletters, we will now be sending out separate updates for the Open Source Program and general Ruby Central organization and community news.
**You can expect our general Ruby Central newsletter (the Ruby Central README) in your inbox later this month.**
# Open Source Program Announcements
### Marty keynotes at Baltic Ruby

We’re excited to share that our Director of Open Source, Marty Haught, spoke at Baltic Ruby, June 12-14! Marty joined a fantastic keynote lineup alongside Matz and Hanami’s Tim Riley.
In his talk, Sustained Open Source, Marty reflected on the long-standing success of Ruby and RubyGems, and explored what it will take to ensure the Ruby ecosystem thrives for decades to come. He dove into themes of sustainability, security, and reliability, particularly as conversations around open source resilience grow in response to upcoming regulations, such as the EU's Cyber Resilience Act.
### 📢 [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) policies update
The new [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) policies, originally [March 20th announcement](https://blog.rubygems.org/2025/03/20/introducing-new-policies.html?ref=rubycentral.org) effect in late June. We are in the process of integrating the email feedback we received from the community over the past few weeks. Once the policies are updated, an announcement will be posted on the RubyGems blog.
These updates demonstrate our commitment to security and sustainability in the RubyGems ecosystem, enhancing clarity and transparency around our operations, data protection practices, and our dedication to ensuring a safe and respectful environment for all RubyGems users.
We want to extend a heartfelt thank you to everyone who shared feedback during the policy preview period. Your input helped us refine the policies to better serve the entire community.
If you haven’t already, we encourage you to review the finalized policies on [RubyGems.org](https://rubygems.org/policies?ref=rubycentral.org).
Thank you for being a part of the Ruby community!
## RubyGems News
In May, we released RubyGems [3.6.9](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#369--2025-05-13) and Bundler [2.6.9](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#269-may-13-2025). These releases bring a series of enhancements and bug fixes designed to improve the overall developer experience with RubyGems.
Notable improvements include [fixing the doctor command’s parsing of otool output](https://github.com/rubygems/rubygems/pull/8665?ref=rubycentral.org), [adding SSL troubleshooting to bundle doctor](https://github.com/rubygems/rubygems/pull/8624?ref=rubycentral.org), [printing WebAuthn authentication links on a separate line for easier access](https://github.com/rubygems/rubygems/pull/8663?ref=rubycentral.org), [adding an mtime argument to Gem::Package::TarWriter#add\_file](https://github.com/rubygems/rubygems/pull/8673?ref=rubycentral.org), and [removing the unnecessary shellwords autoload](https://github.com/rubygems/rubygems/pull/8644?ref=rubycentral.org).
We also made substantial progress on the upcoming Bundler 4 release. We plan to introduce an environment variable or CLI flag that allows users to opt in to upcoming functionality and share feedback prior to the final release.
Another important accomplishment from the team this month includes:
**Improved support for precompiled binaries**
- This month, we laid foundational work toward bringing Python-style wheels to RubyGems, with the goal of enhancing the experience of both using and producing gems with native extensions.
- Following several rounds of community feedback, the focus has shifted toward a broader vision: combining compatibility tags, sigstore attestations, and common platform build workflows (with SLSA, trusted publishing, etc.) to streamline how precompiled gems are distributed and consumed.
- We’re actively incorporating the feedback we've received and will be sharing updated, concrete proposals for these improvements soon.
## [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) News
The updates made this month to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform. Sponsored hosting for [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) in May was provided by [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Fastly](https://www.fastly.com/?ref=rubycentral.org) and [Datadog](https://www.datadoghq.com/?ref=rubycentral.org).
[RubyGems.org](http://rubygems.org/?ref=rubycentral.org) served 4.06 billion gems in May 2025 — up from 2.87 billion in May 2024\. The busiest day was Wednesday, May 14th, with a record-breaking 193 million downloads, while the quietest was Saturday, May 31st, with 36 million. Star of the Month goes to [gitlab-crystalball](https://rubygems.org/gems/gitlab-crystalball/?ref=rubycentral.org) (a gem inspired by a [Predicting Test Failures](https://tenderlovemaking.com/2015/02/13/predicting-test-failues.html?ref=rubycentral.org) post by top Ruby and Rails contributor [tenderlove](https://rubygems.org/profiles/tenderlove?ref=rubycentral.org), revived by [GitLab](https://gitlab.com/?ref=rubycentral.org)) a new gem published on May 8th, which has already reaching 785,000 downloads in its debut month!
**Ruby usage stats 2024-2025**
```html
| Ruby Version | May 2025 | April 2025 | May 2024 | Notes |
| ------------ | -------- | ---------- | -------- | ----------------------- |
| **3.4** | 9.30% | 8.12% | 0.00% | New release (Dec 2024) |
| **3.3** | 24.25% | 23.46% | 11.47% | Trending |
| **3.2** | 33.10% | 33.11% | 24.14% | Peak usage |
| **3.1** | 14.52% | 15.76% | 25.30% | EOL: Mar 31, 2025 |
| **3.0** | 3.48% | 4.00% | 9.92% | EOL: Apr 23, 2024 |
| **2.7** | 8.25% | 8.66% | 15.78% | EOL: Mar 2023 |
| **2.6** | 2.91% | 2.84% | 6.23% | EOL |
| **2.5** | 1.74% | 1.70% | 2.56% | EOL |
| **2.4** | 0.43% | 0.40% | 0.98% | EOL |
| **2.3** | 0.41% | 0.43% | 0.72% | EOL |
| **2.2** | 0.04% | 0.04% | 0.07% | EOL |
| **2.1** | 0.12% | 0.11% | 0.09% | EOL |
| **2.0** | 0.07% | 0.07% | 0.16% | EOL |
| **1.9** | 0.02% | 0.02% | 0.03% | EOL |
| **1.8** | 0.002% | 0.002% | 0.004% | EOL |
| *(unknown)* | 1.21% | 1.10% | 2.42% | Missing user agent info |
```
Ruby version usage continues to trend steadily toward modern releases. In May 2025, Ruby 3.3 became the most widely used version, growing to 24.25%, while Ruby 3.4, released in December 2024, jumped to 9.3% adoption in just five months. Ruby 3.2 held stable at 33%, but its share may begin declining soon as newer versions take over. Meanwhile, Ruby 3.1, which reached end-of-life on March 31, 2025, dropped from 25.3% a year ago to 14.5%. Ruby 3.0, already EOL since April 2024, continues to decline (now 3.5%), and older Ruby 2.x versions are steadily fading as the ecosystem moves forward.
*Note: These numbers represent all downloads in a given month, not only downloads of the Bundler gem as in the previous monthly summary*
## RubyGems Ecosystem News
This is where we highlight exciting updates made to Ruby infrastructure projects that support our RubyGems work.
**Experimental namespacing lands in Ruby Master**
- A new experimental namespacing feature has been introduced in Ruby master, allowing the creation of virtual top-level namespaces.
- This enables applications to `require` or `load` libraries in isolation from the global namespace—including `.rb` files and native extensions. Dependencies loaded within a namespace remain confined to it.
- Currently Ruby has only one global shared namespace. The proposed namespacing feature will help avoid name conflicts between libraries that define the same modules or classes, and prevent unintended sharing of global objects.
- The feature is fully compatible with libraries that use relative name resolution and opens the door for safer, more modular Ruby applications.
```ruby
```ruby
# app2.rb
PORT = 4096
class App
def self.port = ::PORT
end
```
```ruby
# main.rb
app1 = Namespace.new
app1.require('/app1.rb')
app2 = Namespace.new
app2.require('/app2.rb')
puts app1::App.port # => 2048
puts app2::App.port # => 4096
puts defined?(PORT) # => nl
```
```
## Thank you
A huge thank you to all the contributors to RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) this month! We deeply appreciate your support and dedication.
### Contributors to RubyGems:
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@jbampton](https://github.com/jbampton?ref=rubycentral.org) John Bampton
- [@larouxn](https://github.com/larouxn?ref=rubycentral.org) Nicholas La Roux
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@matthewhively](https://github.com/matthewhively?ref=rubycentral.org) Matthew Hively
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@ntkme](https://github.com/ntkme?ref=rubycentral.org) なつき
- [@ntl](https://github.com/ntl?ref=rubycentral.org) Nathan Ladd
- [@rwstauner](https://github.com/rwstauner?ref=rubycentral.org) Randy Stauner
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@tangrufus](https://github.com/tangrufus?ref=rubycentral.org) Tang Rufus
- [@thatrobotdev](https://github.com/thatrobotdev?ref=rubycentral.org) James Kerrane
- [@unasuke](https://github.com/unasuke?ref=rubycentral.org) Yusuke Nakamura
- [@voxik](https://github.com/voxik?ref=rubycentral.org) Vít Ondruch
- [@antoinem](https://github.com/antoinem?ref=rubycentral.org) Antoine Marguerie
- [@woodruffw](https://github.com/woodruffw?ref=rubycentral.org) William Woodruff
- [@mperham](https://github.com/mperham?ref=rubycentral.org) Mike Perham
### Contributors to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org):
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@mghaught](https://github.com/mghaught?ref=rubycentral.org) Marty Haught
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
*If we missed you, please let us know so we can include you in our shout out!*
### Company Spotlight: How Persona Scales High-Stakes Identity Systems With Rails
URL: https://rubycentral.org/news/company-spotlight-how-persona-scales-high-stakes-identity-systems-with-rails/
Last updated: 2025-06-04T18:20:07.000Z
For Ruby developers who have ever been told that Rails won’t scale, [Persona](https://withpersona.com/?ref=rubycentral.org) is a perfect counterexample. Their identity verification product helps global companies verify users across 200+ countries, processing passports, government IDs, and digital credentials with millisecond precision. And Rails is at the center of it all.
“We chose Ruby on Rails because its emphasis on convention over configuration helps us avoid common pitfalls and keeps our focus on identity problems,” says Charles Yeh, CTO at Persona. “One of our biggest technical challenges is domain modeling—defining and evolving complex real-world concepts in software—and **Ruby on Rails’ emphasis on clear, maintainable models made it a natural fit for us.”**
Rails enables Persona to support everything from basic verifications to high-risk workflows in heavily regulated industries such as fintech and healthcare. From day one, this choice has allowed the team to stay ahead of the ever-changing threat and compliance landscape.
“Rails enabled us to ship quickly without compromising quality as we scaled,” says Yeh. “Its flexibility made it easy to adapt to the ever-evolving regulatory and fraud landscapes, while **its rich ecosystem of tools and libraries helped us sustain our development velocity as our team expanded.”**
Even as they’ve started working with new technologies like AI, Persona has remained a Rails-first company. **While much of the fraud prevention world builds on Python, their team is finding ways to integrate advanced signal intelligence and decisioning models into their Ruby stack.**
“As a Rails-first company, we’ve been exploring ways to bridge the gap between Ruby and the Python-heavy AI ecosystem,” Yeh explains. “This includes integrating AI-driven decisioning and risk signals while continuing to improve our no-code tooling.”
Their engineering culture also reflects this pragmatism and care.
“We have a collaborative, fast-moving culture where engineers have real ownership over what they build,” says Yeh. **“We value craftsmanship, learning, and using the right tool for the job—and Rails continues to be one of our favorites.”**
That investment in Ruby will continue to grow this year as Persona scales its tech team.
“We plan to continue growing our engineering team, including Ruby engineers,” says Yeh. “As our customer base and product surface expand, we need more builders to help us scale. We’re always looking for talented engineers who care about craftsmanship and impact.”
For Yeh and the team, Rails remains a competitive advantage, not a constraint.
**“Rails is still one of the fastest ways to start with a strong foundation that works in production at a global scale,”** he says. “Its mature ecosystem and conventions help teams avoid common pitfalls and stay focused on customer value. For early-stage startups or companies operating in rapidly evolving industries, that combination of speed and adaptability can be a game-changer.”
As a sponsor of [RailsConf 2025,](https://railsconf.org/?ref=rubycentral.org) Persona hopes to serve as an example of what’s possible with Rails.
“We hope to show that Rails is still a great choice for building scalable, production-grade systems in high-stakes industries like identity,” says Yeh. **“We’re continuing to invest in performance, security, and best practices, and we aim to share our insights with the broader community.”**
The Persona team will be at RailsConf 2025 in Philadelphia this summer, connecting with fellow Rubyists and sharing how Rails continues to power their work at scale.
**Tickets for RailsConf (July 8–10 in Philadelphia, PA) are** [**on sale now.**](https://ti.to/railsconf/2025?ref=rubycentral.org)
### Ruby Central's OSS Changelog: May 2025
URL: https://rubycentral.org/news/ruby-centrals-oss-changelog-may-2025/
Last updated: 2025-05-19T15:00:38.000Z
Hello, and welcome to the May newsletter. Read on for announcements about our Open Source Program and a report of the OSS work we’ve done over the past month.
As mentioned in our previous newsletters, we will now be sending out separate updates for the Open Source Program and general Ruby Central organization and community news.
**You can expect our general Ruby Central newsletter (the Ruby Central README) in your inbox later this month.**
# Open Source Program Announcements
### **RubyKaigi 2025**
Ruby Central OSS team members Marty Haught, Samuel Giddins, and Colby Swandale joined over 1,500 other attendees last month in Matsuyama, Japan for [RubyKaigi](https://rubykaigi.org/2025/?ref=rubycentral.org). The popular, deeply technical Ruby conference with a uniquely Japanese spirit provided an inspiring atmosphere for team to connect with Rubyists from around the world.

Marketing Director Rhiannon Payne at the RubyKaigi "campfire" with Marty Haught, Samuel Giddins, and Colby Swandale
Our Security Engineer in Residence, Samuel Giddins, delivered a talk on the challenges of building the [sigstore-ruby](https://github.com/sigstore/sigstore-ruby?ref=rubycentral.org) sigstore client and, most importantly, have crucial in-person discussions with the folks building Ruby, including:
- The JRuby team: what is the path forward for JRuby’s crypto primitives, and how can we help get JRuby to parity with MRI?
- Ruby Core: the [state of ruby release build reproducibility](https://traveling.engineer/posts/ruby-release-reproducibility/?ref=rubycentral.org). The core team accepted, in principle, our proposed improvements. We will be testing and making the archive build reproducible as our immediate next steps. Future reproducibility of built and installed binaries is planned as a follow-up.
- Gem developers: other projects intersecting with the ongoing "wheels" work, and what a more declarative build system could look like for extensions. Our eventual goals include an improved replacement for `extconf.rb` and `mkmf`, which are hard to understand, slow due to serial execution, and duplicate work across different extensions.

The team also participated in the in-person Ruby Developer Meeting, where other Ruby committers met to discuss regular Ruby Core business.
"It was refreshing to see how our community extends far beyond the familiar North American context," said Marty, Ruby Central's Director of Open Source. "I look forward to finding more ways to build bridges with the global Ruby community in the year ahead."
### [**RubyGems.org**](http://rubygems.org/?ref=rubycentral.org) **Policies**
We will conclude the review-and-comment period for the new policies for Ruby Central and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) on May 20th. As a reminder, you can send your feedback to [legal@rubycentral.org](mailto:legal@rubycentral.org) or join the conversation in the #oss-program-ruby-central channel on the Ruby Central Community Slack.
## RubyGems News
In April, we released RubyGems [**3.6.7**](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#367--2025-04-03), [**3.6.8**](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#368--2025-04-13) and Bundler [**2.6.7**](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#267-april-3-2025), [**2.6.8**](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#268-april-13-2025). These releases bring a series of enhancements and bug fixes designed to improve the overall developer experience with RubyGems.
Notable improvements include [defaulting to a SOURCE\_DATE\_EPOCH of 315619200](https://github.com/rubygems/rubygems/pull/8568?ref=rubycentral.org) to simplify reproducible builds, [sorting gemspec metadata fields](https://github.com/rubygems/rubygems/pull/8569?ref=rubycentral.org) to support consistent build outputs, [fixing a crash when the compact index API only listed versions](https://github.com/rubygems/rubygems/pull/8594?ref=rubycentral.org), and [speeding up Gem::Version#<=> comparisons by 20–50%](https://github.com/rubygems/rubygems/pull/8565?ref=rubycentral.org) when version lengths differ.
Some other important accomplishments from the team this month include:
**Progress on gems with precompiled binaries**
- Following community interest and questions about the initial **“wheels” proposal**, We opened a [GitHub discussion](https://github.com/rubygems/rubygems/discussions/8645?ref=rubycentral.org) to gather feedback and facilitate conversation. We also invited input from members of the **OpenSSF Securing Software Repositories Working Group** to help align Ruby’s approach with best practices from other language ecosystems.
- We are now focused on collecting \*\*\*\*this feedback into a concrete list of features that will make it easier to use and develop gems with precompiled binaries, guiding the future of RubyGems in this space.
**Development of a Bundler 4 roadmap**
- [The Bundler 4 roadmap has been drafted](https://github.com/rubygems/rubygems/issues/8650?ref=rubycentral.org), aiming to consolidate over a decade of unreleased improvements and breaking changes into a major release.
**`bundle doctor` now troubleshoots SSL issues**
- The `bundle doctor` command [now includes a new \--ssl flag](https://github.com/rubygems/rubygems/pull/8624?ref=rubycentral.org) to help users diagnose SSL-related issues. This improvement brings the functionality of the previously separate [ruby-ssl-check script](https://github.com/rubygems/ruby-ssl-check?ref=rubycentral.org) directly into Bundler, making it easier to maintain and more accessible to users.
- Thanks to [@Edouard-chin](https://github.com/Edouard-chin?ref=rubycentral.org) for contributing this enhancement by porting the script and integrating it into `bundle doctor`.
- The plan is to review and discuss all pending changes, allow users to opt-in and provide feedback, and prepare for a big release in December. This marks an important step toward modernizing Bundler while giving the community a clear path forward.

bundle doctor SSL diagnosis output (successful!)
## [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) News
The updates made this month to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform. Sponsored hosting for [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) in April was provided by [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Fastly](https://www.fastly.com/?ref=rubycentral.org) and [Datadog](https://www.datadoghq.com/?ref=rubycentral.org).
**April 2025 RubyGems stats**
In April 2025, [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) recorded over **4.15 billion total gem downloads**, a **51% increase** from 2.74 billion in April 2024\. This marks the first time in history that monthly gem downloads surpassed the **4 billion mark**, highlighting the continued momentum and growing impact of the Ruby ecosystem. Thanks to all of our partners and sponsors for helping this to happen!
Looking at Bundler gem downloads trends, usage data shows a clear shift towards modern Ruby versions:
- **Ruby 3.4**, released in December 2024, already accounts for **13.1%** of Bundler downloads.
- **Ruby 3.3** rose from **10.4% to 27.9%**, making it the most widely used version.
- **Ruby 3.2** declined from **28.1% to 21.8%**, while **Ruby 3.1,** which reached EOL in March 2025, fell from **24.8% to 14.1%**.
- **Ruby 2.7**, EOL since March 2023, dropped from **20.4% to 16.1%**.
- Older versions (2.6 and below) continued their gradual decline.
These trends reflect a strong migration toward actively maintained, supported Ruby versions. Analytics were powered by [Clickhouse](https://clickhouse.com/?ref=rubycentral.org).
The following are highlights of what the team worked on this month:
**Progress update on organizations**
- Work has resumed on the long-anticipated **Organizations feature** in [RubyGems.org](http://rubygems.org/?ref=rubycentral.org), led by [Colby Swandale](https://github.com/colby-swandale?ref=rubycentral.org). After identifying the remaining functionality a few months ago, we’ve now secured budget to complete the work.
- The feature is currently being demoed to a small group of beta testers, with plans to open it to the broader community in the future. We’re looking forward to gathering feedback once Organizations becomes publicly available.
## Thank you
A huge thank you to all the contributors to RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) this month! We deeply appreciate your support and dedication.
### Contributors to RubyGems:
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@Edouard-chin](https://github.com/Edouard-chin?ref=rubycentral.org) Edouard Chin
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@jeremyevans](https://github.com/jeremyevans?ref=rubycentral.org) Jeremy Evans
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@mperham](https://github.com/mperham?ref=rubycentral.org) Mike Perham
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@thatrobotdev](https://github.com/thatrobotdev?ref=rubycentral.org) James Kerrane
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@skipkayhil](https://github.com/skipkayhil?ref=rubycentral.org) Hartley McGuire
### Contributors to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org):
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
- [@gingerwizard](https://github.com/gingerwizard?ref=rubycentral.org) Dale McDiarmid
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@marcoroth](https://github.com/marcoroth?ref=rubycentral.org) Marco Roth
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@skipkayhil](https://github.com/skipkayhil?ref=rubycentral.org) Hartley McGuire
*If we missed you, please let us know so we can include you in our shout-out*for *!*
### RailsConf 2025 Keynote: John Dewsnap on What Happened After Flexcar Switched from Java to Ruby on Rails
URL: https://rubycentral.org/news/railsconf-2025-keynote-john-dewsnap-on-what-happened-after-flexcar-switched-from-java-to-ruby-on-rails/
Last updated: 2025-05-14T14:25:37.000Z
Last year, [Flexcar](http://www.flexcar.com/?ref=rubycentral.org) migrated its entire platform from a complex Java-based microservice architecture to a Ruby on Rails monolith. That shift happened almost in real time at RailsConf 2024, after [Irina Nazarova announced it during her keynote.](https://www.youtube.com/watch?v=-sFYiyFQMU8&ref=rubycentral.org)
One year later, Flexcar’s Director of Engineering, John Dewsnap, is joining us at RailsConf 2025 to share the full story of what happened before and after that launch.
### **RailsConf 2025 Keynote: “**365 Days Later**”**
John’s keynote will explore how and why Flexcar left behind its 80 microservices in favor of a single Rails application.
At the time, switching to Rails was a radical decision. With the exception of CTO Freedom Dumlao, the team had no prior Ruby or Rails experience. **But they reached a breaking point with their previous architecture when a caching layer had to be built to fetch car data that should have been readily available.**
“It had to go out and make seven or eight different calls to get the data we needed and then present that to our front end," says John. "It literally is the bazooka to kill a mosquito analogy.”
After that moment, Freedom began exploring alternatives. **Rails offered a chance to simplify the architecture, improve delivery speed, and cut down internal friction.**
“We were definitely, I think as a group, reluctant,” John says of the early days. “I’m more of a frontend guy myself, so my big question was, how much are we changing the frontend?”
Ultimately, they kept React for their consumer-facing app and introduced Stimulus and Turbo internally. But everything behind the curtain was new.
And despite the steep learning curve, the transition moved fast. **The team was able to migrate the entire product to Rails in just four months, with everyone adapting much faster than expected.**
“Rails was very forgiving for us," says John. "We were writing not-the-best code at first, and some of it looked like Java, but it performed. Rails just dealt with it, which gave us the space to learn and improve. People felt comfortable fast, and by the end, they already wanted to go back and rewrite things better.”
### **Finding Community at RailsConf**
Inspired by the enthusiasm in the room during Irina's keynote at RailsConf Detroit, the Flexcar team made a game-time decision to begin their migration to Rails that night. By noon the next day, the app was fully operational and taking real customer orders.
**As John reflects back, he remembers this as one of the most exciting moments of his career.** “Everyone was coming up to us like, How did it go? They cared and were hoping it went well. And we could say yes, we launched, it’s working, it’s running.”
“The community is the thing that stuck out," John says of his time at RailsConf 2024, which was his first Ruby or Rails conference. "There are tons of smart people. I went to tons of great talks. But the thing that stuck with me was just how accepting, nice, and open a community it is. In my 20-plus years in \[the tech\] industry, I’ve never had that before.”
### **What You’ll Take Away**
John’s keynote will focus primarily on what happened after Flexcar's switch to Rails, including major changes in velocity, morale, and culture that extended beyond the engineering and product teams.
**Attendees can expect to take away:**
- A real-world case study on transitioning from Java microservices to a Rails monolith
- Honest insight into adopting Rails as a team with no prior experience
- Lessons in managing change across engineering, product, and executive teams
- A reflection on what Rails made possible for Flexcar’s product and people
- And much more...
**RailsConf 2025** [**tickets are on sale now.**](https://ti.to/railsconf/2025?ref=rubycentral.org) **Join us in Philadelphia this July to hear John’s full story!**
You can also watch our interview with John on the Ruby Central YouTube channel:
### The Ruby Central README: April 2025
URL: https://rubycentral.org/news/t/
Last updated: 2025-05-07T14:12:53.000Z
Welcome to The Ruby Central README 🎉
Instead of combining updates on our Open Source Program, conferences, and organizational news into one, The README is a newsletter focused on Ruby Central as an organization, our events, and the broader community.
**For Open Source Program news, check out our dedicated newsletter,** [**The OSS Changelog,**](https://rubycentral.org/news/ruby-centrals-oss-changelog-april-2025/) **and subscribe** [**here.**](https://rubycentral.org/news/ruby-centrals-oss-changelog-february-2025/#/portal/signup)
## Welcome to Ruby Central’s New Executive Director!
Big news — Ruby Central is thrilled to welcome our new Executive Director, [Shan Cureton!](https://www.linkedin.com/in/shancureton/?ref=rubycentral.org)
Shan is joining our team at Ruby Central at a pivotal moment. Over the last few years, we launched our [Open Source Program,](https://rubycentral.org/open-source/) redefined [RubyConf as our flagship annual conference](https://rubycentral.org/news/announcing-railsconf-2025-and-a-new-chapter-for-ruby-central-events/) (beginning in 2026), expanded our grant program to support local Ruby meetups around the world, and much more. Looking to our next phase of growth, we sought an Executive Director with strong operational leadership experience and a deep understanding of how to support mission-driven communities.
With 15 years of experience leading nonprofits and startups, Shan brings exactly that. She has led complex programs, built sustainable systems from the ground up, and consistently prioritized equity, education, and long-term sustainability.
“What has really stood out to me is how aligned the team is around values and community,” says Shan. “I see so much potential to expand access, grow contributor support, and ensure Ruby remains a top choice for the next generation of developers. I can’t wait to be a part of that.”
As Shan steps into this role, she’ll be working closely with our outgoing interim Executive Director, Chelsea Kaufman, to ensure a smooth transition.
We’re looking forward to what’s ahead, and we hope you’ll join us in welcoming her to Ruby Central!
**You can read more about Shan’s appointment** [**here.**](https://rubycentral.org/news/welcoming-ruby-centrals-new-executive-director-shan-cureton/)
## RailsConf Updates
This year’s RailsConf will take place July 8-10th in Philadelphia, PA. It will be the FINAL RailsConf and our only conference this year (there will be no RubyConf until Spring 2026).
### RailsConf Program & Schedule is NOW LIVE
Our [program for the final RailsConf](https://railsconf.org/schedule/?ref=rubycentral.org) is live!
**Highlights include:**
✨ Hotwire & modern frontend techniques
✨ Ruby internals & framework evolution
✨ Scaling, performance, & dev tooling
✨ Open source, careers, community stories
And MUCH more! 🎉
We will be announcing all of our keynotes within the coming weeks. [Tickets for RailsConf are currently on sale](https://ti.to/railsconf/2025?ref=rubycentral.org)—we can’t wait to see you in Philly!
### Introducing: Aji Slater and the “Keynote of Keynotes”
Our first RailsConf 2025 keynote announcement is also LIVE.
**We’re thrilled to welcome Aji Slater, Dev Team Lead at thoughtbot, as our first keynote speaker! 🤩**
Aji’s talk, “The Keynote of Keynotes,” will be an incredible trip down memory lane for those who have been part of RailsConf since 2006, and a fascinating retrospective for those newer to Rails.
[You can learn more about Aji, their unique career journey, and what to expect from their keynote in our recent video interview.](https://youtu.be/%5F2tuWljLleg?ref=rubycentral.org)
### RailsConf Merch Store
**New swag for RailsConf 2025 is now available in our** [**merch store!**](https://store.rubycentral.org/collections/railsconf-2025?ref=rubycentral.org)
[](https://store.rubycentral.org/collections/railsconf-2025?ref=rubycentral.org)
We've got some incredible original designs from Valenzia Cina at Flagrant, honoring the city the conference will be held in—Philadelphia, PA! [**Get your swag now.**](https://store.rubycentral.org/collections/railsconf-2025?ref=rubycentral.org)
Note: We will be offering t-shirts to the first 500 attendees, but the merch store includes exclusive items like crop tops and hats! Registered attendees also received a 10% off promo code via email last week. 😍
### Encourage Your Company to Become a Sponsor!
Sponsoring the final RailsConf will showcase your company’s dedication to the Rails and Ruby ecosystem, provide unparalleled visibility in the community, and highlight your support for open source and developer education.
**Send sponsorship inquiries to Tom Chambers at** **sponsors@rubycentral.org** **.**
## Company Spotlight: Honeybadger
Every month, we feature incredible startups and corporations that are building with Ruby! [**This month’s feature is Honeybadger.**](https://rubycentral.org/news/company-spotlight-how-honeybadger-built-a-profitable-bootstrapped-business-on-rails/)
In 2012, Joshua Wood and his co-founders Ben Curtis and Starr Horne were frustrated with unreliable error monitoring tools, so they built their own.
**They launched Honeybadger with paying customers on day one and have stayed 100% bootstrapped and profitable ever since.**
From the start, Ruby on Rails was the obvious choice for building Honeybadger. “Rails has been critical to our ability to ship fast and scale quickly as a small team,” says Wood in an interview with us.
With a dev team of just five, Honeybadger ships faster than many companies ten times their size. They are proud to launch new feature requests quickly, often on the same day customers request them.
Recently, Honeybadger launched Insights, a performance and observability tool made for Rails teams. “It’s the most ambitious thing we’ve done both architecturally and at the UI layer,” says Wood.
**You can read more about Honeybadger’s origin story, why they chose Ruby and Rails, their team culture, and much more in our** [**interview.**](https://rubycentral.org/news/company-spotlight-how-honeybadger-built-a-profitable-bootstrapped-business-on-rails/)
**You can also see the team IRL at** [**RailsConf**](https://railsconf.org/?ref=rubycentral.org) **in Philly this summer, with Honeybadger as one of our sponsors!**
## Community Spotlight
Here we share exciting projects and events from the Ruby community! While these projects aren’t always directly affiliated with Ruby Central, we love highlighting interesting things happening in the ecosystem. If you would like to be featured in our next newsletter, apply here!
### OSS Expo at Baltic Ruby (APPLY NOW!)
[Applications are now open for the OSS Expo at Baltic Ruby,](http://balticruby.org/expo?ref=rubycentral.org) happening June 12–14 in Riga in partnership with Ruby Central.
Whether you want to demo your project, host a workshop, or run a hacking session, the OSS Expo is a great chance to gain contributors and visibility for your work.
[**Submit your application today!**](http://balticruby.org/expo?ref=rubycentral.org) We hope to see you there. 🇱🇻
### ChicagoRuby Meetups For May & June
ChicagoRuby is hosting monthly meetups in May and June, both in person and online!
📍 May 7 at Avant with speakers Chelsea Troy (Mozilla) and Joel Hawksley (GitHub)
📍 June 4 at Chime, with speakers TBA
**You can find full event info and virtual links on the** [**ChicagoRuby Meetup page.**](https://www.meetup.com/chicagoruby/?ref=rubycentral.org)
### Hack Club’s Open Source Neobank Platform
Sam Poder and the team at Hack Club just [open sourced their neobank platform,](https://github.com/hackclub/hcb/?ref=rubycentral.org) which has processed over $50 million in nonprofit transactions, all built with Ruby on Rails!
**You can learn more about the project** [**here.**](https://hackclub.com/fiscal-sponsorship/open-source/?ref=rubycentral.org)
## Other News & Updates
###
Reflections on RubyKaigi from Marty Haught, Director of Open Source at Ruby Central:
“I just got home from my first RubyKaigi, which took place this year in Matsuyama, Japan.
It can feel intimidating to attend a conference in another country, especially without speaking the language, but the experience was incredible. What struck me most was how vibrant, full of personality, and deeply technical the event felt. And with over 1,500 attendees and 60+ sponsoring companies, it felt like a different world where the Ruby scene is alive and thriving like 2010\. It was heartwarming to see, and I left feeling inspired and energized.
Another thing that stood out was the level of care in every detail, from food trucks to the afterparties to the code party. It was clear how much thought went into creating a great experience.
It was also great to see our Security Engineer in Residence, Samuel Giddins, give a talk on his work with sigstore-ruby and advancing security in the Ruby ecosystem.
Seeing so many Rubyists and companies outside the U.S. ecosystem made me reflect on how Ruby Central can better engage with the global community. While RubyKaigi has a uniquely Japanese spirit that can’t be replicated, there’s so much we can learn from it.
I’m grateful to everyone who took the time to connect with me in Matsuyama, and I’m looking forward to finding more ways to build bridges with the global Ruby community in the year ahead.”
**— Marty Haught, Director of Open Source, Ruby Central**
### Join Us on Slack
Did you know that Ruby Central has a Slack community? While it originally started as a space for conference attendees, it’s now open to all. [**Join us here!**](https://join.slack.com/t/rubycentralcommunity/shared%5Finvite/zt-2uh1lvotg-227RO9FJYT%5FC9RLNiA8Bng?ref=rubycentral.org)
### Become a Ruby Central Corporate Sponsor
Your company can support the security and growth of the Ruby ecosystem by becoming a sponsor of Ruby Central. As a sponsor, you’ll support Ruby’s core open source tools and community development work, be recognized as a community leader, and can get a seat at the table by joining a working group or advisory board.
**Send sponsorship inquiries to Tom Chambers at** **sponsors@rubycentral.org** **.**
### Open Source Program News
For Open Source Program news, check out our dedicated newsletter, [The OSS Changelog,](https://rubycentral.org/news/ruby-centrals-oss-changelog-april-2025/) and subscribe [here.](https://rubycentral.org/news/ruby-centrals-oss-changelog-february-2025/#/portal/signup)
### Introducing Aji Slater: From Vaudevillian to RailsConf 2025 Keynote Speaker
URL: https://rubycentral.org/news/introducing-aji-slater-from-vaudevillian-to-railsconf-2025-keynote-speaker/
Last updated: 2025-04-29T16:47:46.000Z
Before they were writing code, Aji Slater was working as a vaudevillian, touring with the Ringling Brothers and Barnum & Bailey Circus. As a “career changer,” their path into tech wasn’t traditional. But like many in the Ruby on Rails community, it has been driven by creativity, community, and a deep connection to the language that they were lucky enough to learn at a coding boot camp.
Today, Aji is a Development Team Lead at [thoughtbot](https://thoughtbot.com/?ref=rubycentral.org) and has a decade of Ruby and Rails experience. They call Ruby their “native language”—the programming language that truly taught them how to think like a developer.
**At** [**RailsConf 2025,**](https://railsconf.org/?ref=rubycentral.org) **Aji will take the stage with a keynote that honors the history of the ecosystem as seen through the lens of RailsConfs past: “The Keynote of Keynotes.”**
## What is “The Keynote of Keynotes”?
The concept for Aji’s keynote started with a simple idea: **what if they went back and watched *every* RailsConf keynote from 2006 to today?** What stories, themes, and questions would emerge about RailsConf and Rails itself?
Since being accepted, Aji has already started the process of watching two decades' worth of talks. While some of the ideas feel rooted in their time, many of the lessons, challenges, and questions raised years ago are still relevant today.
Aji’s keynote will connect those threads, sharing distilled lessons from previous RailsConfs while offering a fresh perspective on where we’re headed.
## What You’ll Take Away
As Aji says, **“It is easy to use a tool every day without knowing the history behind it. But when you understand the journey and why things are the way they are, you see it all a little differently.”**
Whether you have been part of RailsConf since the early days or are newer to the community, you’ll walk away with:
- A unique perspective on nearly 20 years of Rails history
- Insight into how the Rails community has evolved and where it might go next
- A sense of connection to the bigger story we are all a part of
As we head into the final RailsConf, Aji’s keynote is a perfect opportunity to pause and reflect. It is a celebration of everything Rails has made possible and a reminder that the ideas that built this ecosystem are still shaping its future.
**RailsConf 2025 tickets are on sale now—**[**get yours here!** ](https://ti.to/railsconf/2025?ref=rubycentral.org)
You can hear more about Aji’s story, their personal journey in tech, and the making of their keynote by watching our [full interview on the Ruby Central YouTube channel.](https://www.youtube.com/watch?v=%5F2tuWljLleg&ref=rubycentral.org)
### Company Spotlight: How Honeybadger Built a Profitable Bootstrapped Business on Rails
URL: https://rubycentral.org/news/company-spotlight-how-honeybadger-built-a-profitable-bootstrapped-business-on-rails/
Last updated: 2025-04-28T13:21:43.000Z
If you’ve worked on a Rails app in the last decade, there’s a good chance that [Honeybadger](https://www.honeybadger.io/?utm%5Fsource=rubycentral&utm%5Fcampaign=2025-company-spotlight) has helped you fix a bug in your code or improve your application’s performance. But behind this essential monitoring tool is a story many developers aren’t aware of.
**Honeybadger has never raised VC funding and doesn’t have a large engineering team working behind the scenes.** The business started with a simple frustration shared by a small team of Rubyists and has grown organically and sustainably ever since. Today, its error monitoring service is hugely popular within the Ruby community and beyond.
In the early 2010s, Joshua Wood, Ben Curtis, and Starr Horne were working together as Ruby consultants. Around this time, the most popular error tracking tool for Ruby was acquired by a competitor, after which its support quality dropped and it stopped delivering reliable results.
As Joshua Wood, one of Honeybadger’s co-founders, shares: “The user experience was so bad, we decided to build our own exception monitoring app.”
The team worked tirelessly over nights and weekends to create something that they themselves needed. They launched the product in October of 2012 and got paying customers on day one.
“We loved Honeybadger so much that we wanted to share it with other developers like us,” Wood says.
From the beginning, Rails was the obvious choice for building Honeybadger. **“There was no question of which tech stack to choose. Rails has been critical to our ability to ship fast and scale quickly as a small team,”** says Wood.
Honeybadger started with a monolith and has broken out a few services into plain Ruby/Rack apps and Go services over the years; however, the core application and processing pipeline are still primarily Rails-based.
**“Ruby is a joy to use, and happier developers tend to be more productive,”** says Wood. “Rails multiplies that baseline productivity by providing conventional solutions to common problems in a full-stack environment that everyone on the team can understand.”
For more than a decade, the team has remained lean (with no more than five full-time developers at one time), but they ship at a pace that rivals companies ten times their size. “We were already deploying multiple times per day when we started (using Capistrano), and while we have more CI/automation today, \[our pace\] hasn’t changed. **One of our favorite things is shipping small feature requests on the same day customers ask for them,”** says Wood.
Over time, Honeybadger has grown beyond error tracking. Most recently, they launched Honeybadger Insights, an [observability and performance monitoring tool built for Rails teams](https://www.honeybadger.io/for/rails/?utm%5Fsource=rubycentral&utm%5Fcampaign=2025-company-spotlight). “It’s the most ambitious thing we’ve done both architecturally and at the UI layer,” says Wood.
Even with all this progress, Honeybadger has stayed true to its roots as a developer-first, bootstrapped business. **“Because we are 100% self-funded, we answer to no one but our customers.”**
The company culture also reflects this: “We highly value personal autonomy and work-life balance and try to actually live those values,” says Wood. “We were working 30-hour weeks before 4-day weeks became popular, and that’s still our target.”
Honeybadger’s long-term mission has always been clear: “We want to do for monitoring what Ruby and Rails have done for development—improve developer happiness and make teams of all sizes more efficient.”
You won’t see Honeybadger raising funding rounds or scaling a big sales team, but you will see them at RailsConf 2025 in Philadelphia this summer, learning and celebrating alongside the community that helped them get started.
**“RailsConf has been such an important conference for us over the years,”** says Wood. “I’m looking forward to reconnecting with friends, meeting new people, and hearing all the stories I’m sure will be told.”
**Honeybadger is also a RailsConf sponsor. Tickets for the event (July 8-10 in Philadelphia, PA) are** [**now on sale!**](https://ti.to/railsconf/2025?ref=rubycentral.org)
Interested in becoming a sponsor? Reach out to our Sponsorship Manager, Tom Chambers, at sponsorships@rubycentral.org to learn more!
### Ruby Central's OSS Changelog: April 2025
URL: https://rubycentral.org/news/ruby-centrals-oss-changelog-april-2025/
Last updated: 2026-07-10T14:02:39.000Z
**Hello! Welcome to the April OSS newsletter—now known as Ruby Central’s OSS Changelog.**
As mentioned in our previous newsletters, we will now be sending out separate updates for the Open Source Program and general Ruby Central organization and community news.
You can expect our general Ruby Central newsletter (the Ruby Central README) in your inbox later this month.
# Open Source Program Announcements
## **Reminder: New Ruby Central and RubyGems Policies**
Reminder that we are still in the review-and-comment period for the new policies for [Ruby Central](https://rubycentral.org/privacy-notice/) and RubyGems we announced on March 20th. We appreciate the feedback we have received so far and encourage you to voice any concerns (or appreciation). If you haven’t yet had a chance, [please review them and follow the instructions to leave your comments here](https://rubygems.org/policies?ref=rubycentral.org). Our goal is to have the policies go into effect on May 20th, 2025.
## RubyGems News
In March, we released RubyGems [**3.6.6**](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#366--2025-03-13) and Bundler [**2.6.6**](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#266-march-13-2025). These releases bring a series of enhancements and bug fixes designed to improve the overall developer experience with RubyGems. Notable improvements include fixing an [ENAMETOOLONG error when creating the compact index cache](https://github.com/rubygems/rubygems/pull/5578?ref=rubycentral.org), showing clearer errors when writing a [lockfile on a read-only filesystem](https://github.com/rubygems/rubygems/pull/5920?ref=rubycentral.org), \*\*\*\*and updating [bundle doctor to not report issues about unwritable files](https://github.com/rubygems/rubygems/pull/8520?ref=rubycentral.org).
Some other important accomplishments from the team this month include:
**Improving reproducible gem builds**
- The RubyGems team implemented changes to make gem builds more reproducible based on recommendations from [Giacomo Benedetti](https://github.com/giacomobenedetti?ref=rubycentral.org) and [William Enck](https://github.com/enck?ref=rubycentral.org).
- Their suggestions included [setting a default SOURCE\_DATE\_EPOCH value of 315619200](https://github.com/rubygems/rubygems/pull/8568?ref=rubycentral.org) and [sorting metadata values in gemspecs](https://github.com/rubygems/rubygems/pull/8569?ref=rubycentral.org). These updates improve compatibility with tools like Debian’s *reprotest*, making it easier to verify that gem builds are consistent across environments.
- This work was inspired by the paper [*An Empirical Study on Reproducible Packaging in Open-Source Ecosystems*](https://www.cs.cmu.edu/~ckaestne/pdf/icse25%5Frb.pdf?utm%5Fsource=chatgpt.com), which will be presented at the [2025 International Conference on Software Engineering.](https://conf.researchr.org/home/icse-2025?ref=rubycentral.org)

**Building RubyGems itself is trivially reproducible now without needing to specify SOURCE\_DATE\_EPOCH*
**Resolver performance improvements**
- We've made significant performance improvements to Bundler's dependency resolution, thanks to recent contributions from [Hartley McGuire](https://github.com/skipkayhil?ref=rubycentral.org).
- Initial changes focused on [reducing object allocations in methods like Gem::Version#<=> and Bundler::Candidate#<=>](https://github.com/rubygems/rubygems/pull/8559?ref=rubycentral.org). Further optimizations targeted the resolution algorithm itself, including improvements to the [**pub\_grub** resolver](https://github.com/jhawthorn/pub%5Fgrub/pull/37?ref=rubycentral.org).
- As a result, Hartley reported a 60% speedup in `bundle update` time in his app after applying all patches. Huge thanks to Hartley for his contributions, and to [John Hawthorn](https://github.com/jhawthorn?ref=rubycentral.org) for maintaining `pub_grub` and helping refine its API to support these enhancements.
**Wheels for RubyGems**
- Progress continues on bringing a prototype for precompiled binary packages\*\*,\*\* or "wheels" to RubyGems. [Samuel Giddins](https://github.com/segiddins?ref=rubycentral.org) has defined a naming scheme for package files and finalized the set of identifying tags needed to support this across the Ruby ecosystem.
- Next steps include advocating within the Ruby community to help shift perceptions around precompiled binaries, and helping Rubyists understand that precompiled packages are actually **more secure** (no code execution at install time) and **more ergonomic** for users (no build tools or compilation delays). An RFC is also forthcoming.
**Compact index cache now handles long path names**
- Bundler now better handles long path names in the \*\*\*\*compact index cache, addressing an issue that could raise [**“Filename too long”** errors](https://github.com/rubygems/rubygems/pull/5578?ref=rubycentral.org)—especially when using private servers like *JFrog Artifactory*.
- The fix was long delayed due to persistent CI failures, which were eventually traced to a [**Ruby on Windows bug**](https://bugs.ruby-lang.org/issues/21177?ref=rubycentral.org) that has since been resolved.
- As part of the debugging process, we also improved our test reliability by removing the use of `FileUtils.rm_rf` in Bundler specs, as it silently fails on cleanup errors and made diagnosing the issue harder. This change will help prevent similar issues in the future.
## [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) News
The updates made this month to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform. Sponsored hosting for [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) in February was provided by [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Fastly](https://www.fastly.com/?ref=rubycentral.org) and [Datadog](https://www.datadoghq.com/?ref=rubycentral.org).
The following are highlights of what the team worked on this month:
**Ecosystem data for Clickgems**
- [Marty](https://github.com/mghaught?ref=rubycentral.org) collaborated with the [**ClickHouse**](https://clickhouse.com/?ref=rubycentral.org) team to finalize details for our partnership on *Clickgems*, the Ruby equivalent of the popular [ClickPy](https://clickpy.clickhouse.com/?ref=rubycentral.org) site, [which officially launched last week!](https://clickhouse.com/blog/announcing-ruby-gem-analytics-powered-by-clickhouse?ref=rubycentral.org)
- [Samuel Giddins](https://github.com/segiddins?ref=rubycentral.org) led the effort to push RubyGems ecosystem data into ClickHouse, which now includes daily download totals and the latest public database dumps from [RubyGems.org](http://rubygems.org/?ref=rubycentral.org). Work is underway to roll out granular download data, made possible by retooling the [Kirby](https://github.com/rubytogether/kirby?ref=rubycentral.org) log parser to stream data directly from the [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) CDN.
- This new level of insight will help the Ruby community better understand package usage trends and support maintainers in making more informed decisions, especially around platform support.
[**Database performance investigation after brief DoS**](https://github.com/rubygems/rubygems.org/pull/5595?ref=rubycentral.org)
- A brief Denial of Service (DoS) incident targeting [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) prompted an investigation into web pages with heavy database queries.
- While no specific culprit was found, the incident served as a reminder of the need for strong visibility into database performance when operating a web system at scale.
## Thank you
A huge thank you to all the contributors to RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) this month! We deeply appreciate your support and dedication.
### Contributors to RubyGems:
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
- [@devsheva](https://github.com/devsheva?ref=rubycentral.org) Mateo Sheshi
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@saraid](https://github.com/saraid?ref=rubycentral.org) Michael Chui
- [@cllns](https://github.com/cllns?ref=rubycentral.org) Sean Collins
- [@taralbass](https://github.com/taralbass?ref=rubycentral.org) Tara Bass
- [@mbclu](https://github.com/mbclu?ref=rubycentral.org) Mitch Clutter
- [@jacobat](https://github.com/jacobat?ref=rubycentral.org) Jacob Atzen
- [@skipkayhil](https://github.com/skipkayhil?ref=rubycentral.org) Hartley McGuire
- [@rwstauner](https://github.com/rwstauner?ref=rubycentral.org) Randy Stauner
- [@ioquatix](https://github.com/ioquatix?ref=rubycentral.org) Samuel Williams
- [@giacomobenedetti](https://github.com/giacomobenedetti?ref=rubycentral.org) Giacomo Benedetti
- [@olleolleolle](https://github.com/olleolleolle?ref=rubycentral.org) Olle Jonsson
### Contributors to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org):
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@wooly](https://github.com/wooly?ref=rubycentral.org) Steve Bell
- [@mghaught](https://github.com/mghaught?ref=rubycentral.org) Marty Haught
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
*If we missed you, please let us know so we can include you in our shout out!*
### The Ruby Central README: March 2025
URL: https://rubycentral.org/news/the-ruby-central-readme-march-2025/
Last updated: 2026-07-10T14:03:10.000Z
Welcome to The Ruby Central README! 🎉
**As we announced last month, we’ve revamped our newsletters to better serve the Ruby community!** Instead of combining updates on our Open Source Program, conferences, and organizational news into one, The README will focus on Ruby Central as an organization, our events, and the broader community.
For Open Source Program news, check out our dedicated newsletter, [The OSS Changelog,](https://rubycentral.org/news/ruby-centrals-oss-changelog-march-2025/) and subscribe [here.](https://rubycentral.org/news/ruby-centrals-oss-changelog-february-2025/#/portal/signup)
## RailsConf Updates
**This year’s** [**RailsConf**](https://railsconf.org/?ref=rubycentral.org) **will take place July 8-10th in Philadelphia, PA.** It will be the FINAL RailsConf and our ONLY conference this year (there will be no RubyConf until Spring 2026).
[](https://railsconf.org/?ref=rubycentral.org)
### RailsConf Tickets NOW ON SALE (Early Bird Sold Out)
Tickets for the FINAL RailsConf are [now on sale!](https://ti.to/railsconf/2025?ref=rubycentral.org)
**We have already sold out of early bird tickets, and general ticket sales are going strong!** If you plan to join us in July, we suggest snagging your ticket sooner than later.
### Program Announcements COMING SOON
Our Program Committee, led by Ufuk Kayserilioglu (Shopify) and Chris Oliver (GoRails), has been hard at work reviewing CFPs and selecting talks and workshops for this year’s event.
With over 250 submissions, it was extremely difficult to narrow them down and fill \~30 slots. We appreciate everyone who sent in a CFP!
**We will be announcing the program and speakers in April. Stay tuned! 👀**
### Thank You to Our Supporters
We want to extend a special thank you to the individuals and organizations that have purchased Supporter Tickets!
💎 Ben Sheldon
💎 Collective Idea
💎 McGeary Consulting Group
💎 Anton Tkachov (Gotoinc)
💎 Codeminer42
💎 Jenna Quindica
💎 Jeremy Hinegardner
💎 The Rails Foundation
And anonymous supporters.
**These tickets are priced at a premium ($1,500) to help fund our programs and operations, including the Scholars & Guides program.** You can [purchase your own Supporter Ticket here.](https://ti.to/railsconf/2025?ref=rubycentral.org) 💙
### Encourage Your Company to Become a Sponsor!
Sponsoring the final RailsConf will showcase your company’s dedication to the Rails and Ruby ecosystem, provide unparalleled visibility in the community, and highlight your support for open source and developer education.
**Send sponsorship inquiries to Tom Chambers at** **sponsors@rubycentral.org** **.**
## Company Spotlight: Power Home Remodeling
Every month, we feature incredible companies and startups building with Ruby. [This month’s spotlight is Power Home Remodeling.](https://rubycentral.org/p/a4073471-2b48-425b-b066-24e2a3a358c3/)
**Power is a $1B exterior renovation company with over 4,000 employees across 24 U.S. cities.** At the heart of its operation is proprietary technology built almost entirely in Ruby on Rails.
“Our custom Ruby on Rails applications are the operating system of the business and the fuel behind our vision of a fully tech-enabled workforce,” says Jenny Gray, VP of Application Development and Infrastructure.
Instead of relying on third-party tools, Power prefers to invest in building software that meets the needs of the business processes they define. This includes internal and customer-facing apps, plus a new AI platform currently in development.
**Their 250+ person tech team ships to production up to 35 times a day and continues to scale.** “We strongly believe no other language can keep the same quick pace that Ruby can when it comes to delivering business value,” says Principal Developer Wade Winningham.
**Power will have over 85 developers at RailsConf 2025 in Philly and plans to hire 15 new Rails devs this year.** Say hi if you see them!
[**Read More**](https://rubycentral.org/p/a4073471-2b48-425b-b066-24e2a3a358c3/)
## Community Spotlight 💡
Here we share exciting projects and events from the Ruby community! While these projects aren’t directly affiliated with Ruby Central, we love highlighting the amazing things happening in the ecosystem. **If you would like to be featured in our next newsletter,** [**apply here!**](https://forms.gle/rSyEWejw1Znrxa7A8?ref=rubycentral.org)
### Sin City Ruby: April 10-11 🎰
The third and FINAL edition of [Sin City Ruby](https://www.sincityruby.com/?ref=rubycentral.org) is happening in Las Vegas next month!
Hosted by Jason Swett, Sin City brings together Rubyists for an intimate gathering full of talks, fun, and good vibes. (Plus some arm wrestling!)
Speakers include Chris Oliver, Irina Nazarova, Jason Charnes, Drew Bragg, Freedom Dumlao, Dave Thomas, and more. [**Learn more and get your ticket here!**](https://www.sincityruby.com/?ref=rubycentral.org)
## Other News & Updates
### Join Us on Slack
Did you know that Ruby Central has a Slack community? While it originally started as a space for conference attendees, it’s now open to all. [**Join us here!**](https://join.slack.com/t/rubycentralcommunity/shared%5Finvite/zt-2uh1lvotg-227RO9FJYT%5FC9RLNiA8Bng?ref=rubycentral.org)
### Say “Hi” at RubyKaigi! 🇯🇵
Several of our team members will be at RubyKaigi in Matsuyama, Japan next month, including Marty Haught (Director of Open Source), Colby Swandale (RubyGems engineer), and Rhiannon Payne (Marketing Director). **Our Security Engineer in Residence, Samuel Giddins, will be** [**speaking**](https://rubykaigi.org/2025/presentations/segiddins.html?ref=rubycentral.org#day3) **at the event.**
If you would like to set up a meeting with Marty to discuss RubyGems, tech or partnership opportunities with Ruby Central, or anything else, you can reach out to marty\[at\]rubycentral\[.\]org before the event. Or say hi if you see us!
### Local Meetup Grants
In collaboration with [Fastly,](https://fastly.com/?ref=rubycentral.org) Ruby Central has been providing grants for Ruby and Rails meetups and events all over the world! **In March, our grants supported meetups like SF Ruby, ChicagoRuby, Vienna.rb, and more.**
We will make another announcement via our newsletter, Slack, and social media channels when grant applications open again (date TBD).
### Become a Ruby Central Corporate Sponsor
Your company can support the security and growth of the Ruby ecosystem by becoming a sponsor of Ruby Central. As a sponsor, you’ll support Ruby’s core open source tools and community development work, be recognized as a community leader, and can get a seat at the table by joining a working group or advisory board.
**Send sponsorship inquiries to Tom Chambers at** **sponsors@rubycentral.org** **.**
### Company Spotlight: Power Home Remodeling Scales a $1B Business With Ruby on Rails
URL: https://rubycentral.org/news/company-spotlight-power-home-remodeling-scales-a-1b-business-with-ruby-on-rails/
Last updated: 2026-07-10T14:03:43.000Z
Power Home Remodeling isn’t your typical software company. It’s a $1B exterior renovation business with more than 4,000 employees across 24 U.S. cities, and at the heart of its operation is proprietary tech built almost entirely in Ruby on Rails.
“Power prefers to build our own custom software or use open source whenever possible," says Wade Winningham, Principal Developer at Power.
**That philosophy has fueled Power’s transformation from a traditional remodeling business into a technology-led enterprise.** Their internal platform, *Nitro*, was first developed in 2008 with a small team that had prior success with Ruby and Rails. V1 of Nitro offered sales reps a view of their sales and commissions, which the team was able to deliver within a few months.
As Winningham says, “We haven’t stopped shipping since.”
Today, Nitro touches every part of the business, from lead generation to hiring to installations. **“Our custom Ruby on Rails applications are the operating system of the business and the fuel behind our vision of a fully tech-enabled workforce,**” says Jenny Gray, VP of Application Development and Infrastructure. “Every single employee touches our applications in some way.”
Rather than buying third-party software, Power has committed to building and owning everything they can.
“Buying software off the shelf is an expensive proposition,” Gray explains. “It often forces inefficient business processes on the workforce. To change the off-the-shelf software, a company needs to spend even more money on outside developers or get in line with expensive software change requests.”
“At Power, we would rather invest in our employees and Business Technology team to build software that supports and meets the needs of the business processes *we* define. We believe that we know our business better than anyone else, so how could we rely on software that somebody else designed and built to run our business? It just doesn’t make sense.”
That investment now powers a tech organization of over 250 people. The team includes more than twenty feature development teams and a dozen shared service groups, who collectively **ship to production up to 35 times a day.**
“We retain top developer talent who have been here for years and know the business and Nitro inside and out,” Gray says. “It has been several years since we had a resignation letter from a Ruby on Rails developer.”
Much of that retention comes from Power’s culture of continuous investment, especially in talent and education. Each year, Power runs the *Power Code Academy*, a two-year program to teach high-performing employees how to code.
**“We take 6 to 8 exceptional Power employees from all parts of the business, and we teach them how to code in Ruby on Rails,”** says Gray. “Not only do we get to invest in the continued growth of our employees, but now we have all that great business knowledge working to design and develop needed features in Nitro.”
To date, the team has seen over 35 individuals graduate from PCA and is about to kick off their 6th class.
“We invest heavily in tech by investing heavily in ourselves,” adds Winningham. “That’s always money well spent.”
Power also maintains full control over infrastructure. **“We believe so strongly in investing in our technology team that we even host our applications in our own private cloud using hardware in our own data centers,”** says Winningham. “All developed, maintained, and run by Power employees.”
This infrastructure supports a steady stream of innovation. In 2022, the company launched *Pulse,* a customer-facing app that gives homeowners real-time updates on projects, from scheduling to sign-off.
Now, the team is turning its focus to AI. “We are developing Nitro Intelligence, an in-house AI platform designed to integrate GenAI capabilities seamlessly into Power’s existing technology stack,” says Ben Langfeld, a Principal Developer.
“The Nitro Intelligence Platform will provide product teams with easy access to AI-driven functionalities, eliminating reliance on external AI services while ensuring data security. Key features include multi-model support, retrieval-augmented generation (RAG), AI-powered business intelligence, and operational efficiency enhancements across various domains, such as customer interactions, sales analytics, and staff coaching.”
Even as Power expands into new technologies, Rails remains the foundation of their tech strategy.
**“We strongly believe no other language can keep the same quick pace that Ruby can when it comes to delivering business value,”** says Winningham. “Rails, specifically, gives developers more time to think through the specific problems they are trying to solve rather than the trivial details like getting data saved into a database.”
Rails has also enabled Power’s unique architectural approach. Their team runs a large [Component Base Rail Application](https://cbra.info/?ref=rubycentral.org) (CBRA), a notable achievement in enterprise-scale systems.
“We love being an example of a Component-Based Rail Application, which seems pretty rare these days,” says Winningham. “Many companies who’ve attempted it have ended up switching to [Packwerk](https://github.com/Shopify/packwerk/blob/main/USAGE.md?ref=rubycentral.org).”
**To support their CBRA setup, Power has open sourced several internal tools:**
- [cobra\_commander](https://github.com/Shopify/packwerk/blob/main/USAGE.md?ref=rubycentral.org) for managing CBRA apps
- [power-tools](https://github.com/powerhome/power-tools?ref=rubycentral.org), a set of utility gems
- [Playbook Design System](https://playbook.powerapp.cloud/?ref=rubycentral.org), a full design system for Rails, Swift, and React
“We’d love for others to use them and contribute,” Winningham adds.
**This summer, Power will send more than 85 Ruby developers to** [**RailsConf 2025**](https://railsconf.org/?ref=rubycentral.org) **in Philadelphia, just a few miles from their headquarters.** Don’t miss the opportunity to say hello to their team while you’re there!
With over 15 new Ruby hires planned this year and continued investment in homegrown tools, talent, and infrastructure, Power is showing what’s possible when Rails is used not just to build apps but to build an entire company.
### Ruby Central's OSS Changelog: March 2025
URL: https://rubycentral.org/news/ruby-centrals-oss-changelog-march-2025/
Last updated: 2026-07-10T14:04:12.000Z
**Hello! Welcome to the March newsletter—now known as Ruby Central’s OSS Changelog.**
As mentioned in our previous newsletters, we will now be sending out separate updates for the Open Source Program and general Ruby Central organization and community news.
You can expect our general Ruby Central newsletter (the Ruby Central README) in your inbox later this month.
## Letter From Our Open Source Director
RubyGems has grown significantly in recent years, with a greater focus on stability and security to ensure you have the tools you need to build with confidence.
As we continue to mature, we’re putting stronger foundations in place to support that growth over the long term. **This includes creating clear standards and processes for how** [**RubyGems.org**](http://rubygems.org/?ref=rubycentral.org) **is managed.**
While this might not be as exciting as solving tough engineering problems, it is an important part of the evolution of RubyGems. Without clear policies, we carry unnecessary risk, and we make it harder to act fairly and consistently across the board.
**With this in mind, we partnered with a law firm that specializes in working with open source organizations to help us formalize a set of** [**policies.**](https://blog.rubygems.org/2025/03/20/introducing-new-policies.html?ref=rubycentral.org) **And we are now opening a 60-day review and comment period for community members to weigh in.**
If you have thoughts on our new policies, we encourage you to send feedback to [legal@rubycentral.org](mailto:legal@rubycentral.org) or join the conversation in the #oss-program-ruby-central channel on the Ruby Central Community Slack.
[**You can read my full letter on this matter here for more details.**](https://rubycentral.org/news/introducing-new-policies-to-support-the-growth-of-rubygems/)
Thank you for being part of this journey with us.
Best,
**Marty Haught**
Director of Open Source, Ruby Central
## Open Source Program Announcements
### Our seasoned security engineer in residence shares a lesson on d**ealing with malicious packages**
- [Samuel Giddins](https://github.com/segiddins?ref=rubycentral.org) pubished a blog post illustrating how a fictional package repository might handle a malicious package. Many in our community are unaware of the behind-the-scenes efforts in resolving compromised packages, and sharing this story sparked positive engagement. Read the blog post here: [Dealing with Sham Packages](https://blog.rubygems.org/2025/02/20/dealing-with-sham-packages.html?ref=rubycentral.org).
### RubyGems presentations in Poland
- Sam presented at [Ruby Community Conference 2025](https://rubycommunityconference.com/?ref=rubycentral.org) last month. He gave a hands-on workshop on modernizing gem development practices, guiding maintainers through setting up trusted publishing and sigstore signing to improve the security and integrity of their gem releases.
- He also led a session at the KRUG’s (Krakow Ruby User Group) February 2025 meetup about the future of Ruby supply chain security.
[YouTube](https://www.youtube.com/embed/iKKRLHm1OxU?si=WTzK-K57Lu0uPm6S&ref=rubycentral.org)
## RubyGems News
In February, we released RubyGems [3.6.4](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#364--2025-02-17), [3.6.5](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#365--2025-02-20) and Bundler [2.6.4](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#264-february-17-2025), [2.6.5](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#265-february-20-2025)[.](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#263-january-16-2025) These releases bring a series of enhancements and bug fixes designed to improve the overall developer experience with RubyGems. Notable improvements include removing [gem server from gem help to streamline command output](https://github.com/rubygems/rubygems/pull/8507?ref=rubycentral.org), raising a [clearer error message when RubyGems fails to activate a dependency](https://github.com/rubygems/rubygems/pull/8449?ref=rubycentral.org), ensuring Bundler correctly [considers gems under platform: :windows](https://github.com/rubygems/rubygems/pull/8428?ref=rubycentral.org) in the Gemfile when running on Windows with ARM architecture, and fixing a resolver issue caused by [incorrectly defined version ranges](https://github.com/rubygems/rubygems/pull/8503?ref=rubycentral.org).
Some other important accomplishments from the team this month include:
**Upgrading Kubernetes cluster to v1.32 and our OpenSearch cluster to v2.17**
- We regularly update our infrastructure systems to ensure we’re taking advantage of the latest software features and security patches. This upgrade was scheduled and performed seamlessly without impacting users.
**Developing wheels for RubyGems**
- A proposal is in progress to introduce **"wheels" for RubyGems**, improving the gem build process until every gem ships precompiled binaries.
- This is better for security as it eliminates the need to execute code during installation. It’s also a huge improvement for the gem install experience thanks to removing the need for build tools, avoiding compilation errors, and reducing installation time. An outline of the project goals has been published at [traveling.engineer](https://traveling.engineer/posts/goals-for-binary-gems/?ref=rubycentral.org), and implementation sketches are in the works.
**Resolution improvements in Bundler**
- A release of Ruby 3.4.2 introduced incorrect gemspec dependencies for `net-smtp`, leading to multiple bug reports. To prevent similar issues in the future, Bundler now attempts to automatically [fix incorrect dependencies in the lockfile](https://github.com/rubygems/rubygems/pull/8483?ref=rubycentral.org) whenever possible. When auto-fixing is not possible (e.g., in frozen mode), Bundler now provides clearer error messages to help users resolve the issue.
- Depfu reported cases where Bundler 2.6 was unexpectedly downgrading dependencies. This was fixed by ensuring [Bundler properly respects locked versions](https://github.com/rubygems/rubygems/pull/8491?ref=rubycentral.org) and re-adds necessary lower bound requirements.
- Investigating these issues also led to fixing the [only known issue in our resolver engine (pub\_grub)](https://github.com/rubygems/rubygems/pull/8503?ref=rubycentral.org), improving Bundler’s dependency resolution logic.
## [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) News
The updates made this month to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform. Sponsored hosting for [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) in February was provided by [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Fastly](https://www.fastly.com/?ref=rubycentral.org) and [Datadog](https://www.datadoghq.com/?ref=rubycentral.org).
The following are highlights of what the team worked on this month:
**Fixed API key role creation for Buildkite**
- A system test was added to fix an issue where creating an [API Key Role for Buildkite incorrectly assigned a GitHub Actions principal](https://github.com/rubygems/rubygems.org/pull/5434?ref=rubycentral.org) instead of the correct Buildkite principal. This happened because the form defaulted to GitHub OIDC settings, hiding the principal input and preventing users from changing it.
- The fix removes the unnecessary principal assignment, allowing the correct value to be set automatically for GitHub Actions and Buildkite, ensuring smoother API Key Role creation.
## **RubyGems Ecosystem News**
This is where we highlight exciting updates made to Ruby infrastructure projects that support our RubyGems work.
### Sigstore
**sigstore-ruby**
- The **sigstore-ruby** client is nearly ready for its **0.3.0 release**, bringing **improved spec compliance** and **JRuby support**.
- Adding JRuby support was particularly challenging, as it required the reimplementation of certain cryptographic operations using Java security APIs instead of relying on the `jruby-openssl` gem.
- You can read more about the development of sigstore-ruby in [Sam’s 2024 year in review](https://traveling.engineer/posts/2024-in-review/?ref=rubycentral.org#sigstore-ruby).
**Ecosystem adoption**
- A tracker has been launched to monitor sigstore adoption among the most popular gems: [Are We Attested Yet?](https://segiddins.github.io/are-we-attested-yet/?ref=rubycentral.org)
- Currently, 20 of the top gems are shipping attestations, and efforts are ongoing to help more maintainers integrate sigstore signing into their release workflows.
## Thank You
A huge thank you to all the contributors to RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) this month! We deeply appreciate your support and dedication.
### Contributors to RubyGems:
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@johnnyshields](https://github.com/johnnyshields?ref=rubycentral.org) Johnny Shields
- [@edouard-chin](https://github.com/Edouard-chin?ref=rubycentral.org) Edouard Chin
- [@y-yagi](https://github.com/y-yagi?ref=rubycentral.org) Y Yagi
- [@saraid](https://github.com/saraid?ref=rubycentral.org) Michael Chui
### Contributors to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org):
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@yob](https://github.com/yob?ref=rubycentral.org) James Healy
- [@kachick](https://github.com/kachick?ref=rubycentral.org) Kenichi Kamiya
*If we missed you, please let us know so we can include you in our shout-out!*
### Introducing New Policies to Support the Growth of RubyGems
URL: https://rubycentral.org/news/introducing-new-policies-to-support-the-growth-of-rubygems/
Last updated: 2025-03-26T16:53:41.000Z
RubyGems has grown significantly in recent years, with a greater focus on stability and security to ensure you have the tools you need to build with confidence.
As we continue to mature, we’re putting stronger foundations in place to support that growth over the long term. **This includes creating clear standards and processes for how** [**RubyGems.org**](http://rubygems.org/?ref=rubycentral.org) **is managed.**
Within my first two months in this role overseeing RubyGems, we received a takedown request for a gem that potentially violated a trademark. As we looked into it, we realized we didn’t have a formal policy to guide our response. The team had a general sense of how such cases were handled in the past, but nothing was documented. That incident led us to discover a broader gap: we lacked foundational policies that are important from a legal and compliance standpoint.
This might not be as exciting as solving tough engineering problems, but it matters. Without clear policies, we carry unnecessary risk, and we make it harder to act fairly and consistently across the board.
**With this in mind, we partnered with a law firm that specializes in working with open source organizations to help us formalize a set of policies.** [These include a Terms of Service, Privacy Notice, Acceptable Use Policy, and Copyright Policy.](https://blog.rubygems.org/2025/03/20/introducing-new-policies.html?ref=rubycentral.org) They essentially reflect how we’ve already been operating, but make those practices official and transparent. These updates will help us respond to issues more consistently and ensure the platform remains safe, reliable, and well-governed.
**You can read more about these policies** [**here.**](https://blog.rubygems.org/2025/03/20/introducing-new-policies.html?ref=rubycentral.org)
**We announced these policies on the RubyGems blog last week and are now opening a 60-day community review and comment period.** If you’d like to weigh in, we encourage you to send feedback to [legal@rubycentral.org](mailto:legal@rubycentral.org) or join the conversation in the #oss-program-ruby-central channel on the Ruby Central Community Slack.
Thank you for being part of this journey with us.
Best,
**Marty Haught**
Director of Open Source, Ruby Central
### The Ruby Central README: February 2025 Newsletter
URL: https://rubycentral.org/news/the-ruby-central-readme-feb-2025-newsletter/
Last updated: 2025-02-28T05:10:29.000Z
**Welcome to the first edition of The Ruby Central README 🎉**
We’ve revamped our newsletters to better serve the Ruby community! Instead of combining updates on our Open Source Program, conferences, and organizational news into one, The README will focus on Ruby Central as an organization, our events, and the broader community.
For Open Source Program news, check out our dedicated newsletter, [The OSS Changelog,](https://rubycentral.org/news/ruby-centrals-oss-changelog-february-2025/) and subscribe [here.](https://rubycentral.org/news/ruby-centrals-oss-changelog-february-2025/#/portal/signup)
---
## RailsConf 2025 Updates
**This year’s** [**RailsConf**](https://railsconf.org/?ref=rubycentral.org) **will take place July 8-10th in Philadelphia, PA.** It will be the FINAL RailsConf and our only conference this year (there will be no RubyConf until Spring 2026).
### Chris Oliver Joins as Co-Chair
Chris Oliver (CEO of GoRails) is joining Ufuk Kayserilioglu (Engineering Manager at Shopify) as RailsConf Co-Chair!
Chris and Ufuk will work with Ruby Central to set the vision and theme, shape the program, and help with planning and execution to create an unforgettable final RailsConf. [**See our video interview with Chris**](https://www.youtube.com/watch?v=81Is61afykA&ref=rubycentral.org) to learn more about why he joined as Co-Chair and what he’s excited about!
### CFPs are NOW Due!
If you’d like to present a talk or workshop at the final RailsConf this summer, now’s your chance! CFPs are closing EOD on February 28th (at midnight EST). [**Submit your proposal now.**](https://sessionize.com/railsconf-2025/?ref=rubycentral.org)
We also had CFP coaching sessions last week and turned those insights into a [**guide for submitting the best RailsConf proposal.**](https://rubycentral.org/news/til-in-cfp-coaching-how-to-submit-a-railsconf-talk-proposal/)Best of luck!
### RailsConf Tickets
Ticket sales are slated to begin in late March/early April. If you’d like to get your ticket now, [**consider purchasing a Supporter Ticket!**](https://ti.to/railsconf/2025?ref=rubycentral.org) Supporter Tickets are priced at a premium to help fund our programs and operations, including the Scholars and Guides program.
### Scholars & Guides Applications OPEN
Want to level up your Ruby on Rails career? The Scholars and Guides Program pairs you with a mentor to help you navigate your learning journey, prep for RailsConf 2025, and connect with the Rails community. Scholars get a free RailsConf ticket, one-on-one mentorship, and guidance to present a mini-project. [**Apply by March 18, 2025!**](https://docs.google.com/forms/u/1/d/e/1FAIpQLSdddI4k9PTTqj4etSA6piKxtS0FoVX135Pr7mNeNfbXtYdvAg/viewform?ref=rubycentral.org)
### Program Committee Selected
We have also selected this year’s RailsConf Program Committee! Thank you to our six incredible Committee members: Adrianna Chang, Bhumi Shah, David Hill, Drew Bragg, Noel Rappin, and Rosa Gutiérrez.
### Encourage Your Company to Become a Sponsor!
Sponsoring the final RailsConf will showcase your company’s dedication to the Rails and Ruby ecosystem, provide unparalleled visibility in the community, and highlight your support for open source and developer education.
**Send sponsorship inquiries to Tom Chambers at sponsors@rubycentral.org.**
---
## Company Spotlight: DNSimple
Every month, we will be featuring incredible startups and corporations that are building with Ruby! [**This month’s feature is DNSimple.**](https://rubycentral.org/news/company-spotlight-how-ruby-shaped-dnsimples-growth/)
**DNSimple, a Ruby Central sponsor, helps businesses simplify domain management, including registration and DNS hosting across multiple providers.** CEO Anthony Eden introduced the company to the world during a lightning talk at RubyConf 2010.
**When it comes to choosing Ruby:** “The speed of development that Ruby enabled let DNSimple stay lean and profitable throughout its earliest days, when it really mattered to be efficient.”
**Eden credits the Ruby community for opening doors:** “My connections with the Ruby community helped DNSimple get other successful businesses using Ruby as customers, and we were able to hire Rubyists from that same community due to our long-time support.”
[**You can read the full interview here.**](https://rubycentral.org/news/company-spotlight-how-ruby-shaped-dnsimples-growth/)
---
## Community Spotlights 💡
Here are some exciting news and projects from the Ruby community! While these projects aren’t directly affiliated with Ruby Central, we love highlighting the amazing work happening in the ecosystem. **If you would like to be featured,** [**please apply here!**](https://forms.gle/rSyEWejw1Znrxa7A8?ref=rubycentral.org)
### Nadia Odunayo of The StoryGraph Interviewed on TODAY
Nadia Odunayo, the CEO and developer behind The StoryGraph, was one of our keynote speakers at RubyConf 2024.
**This month, she was featured in a segment on TODAY! 🤩** We loved hearing her story of growing to 3.7M+ users. [**Check it out here.**](https://www-today-com.cdn.ampproject.org/c/s/www.today.com/today/amp-video/mmvo231154757691?ref=rubycentral.org)
(We also interviewed Nadia after her keynote in November—[**watch here!**](https://www.youtube.com/watch?v=r19dAknjv-I&ref=rubycentral.org))
### Rails Camp in Alaska (Aug 18-21)
Rails Camp US (est. 2015) is an annual summer camp for the software community to connect and unwind in nature—this year, they’re heading to Kenai Lake, Alaska! You can find out more and [**buy tickets here.**](https://west.railscamp.us/2025?ref=rubycentral.org)
### The Ode to RailsConf Podcast
With RailsConf coming to a close this year, host David Hill created this podcast as a way to highlight the impact the conference has had over the years. He releases new episodes every Monday, featuring conversations with guests about their experiences at RailsConf. [**Listen here!**](https://www.odetorailsconf.com/?ref=rubycentral.org)
---
## Other News & Updates
### Join us on Slack
Did you know that Ruby Central has a Slack community? While it originally started as a space for conference attendees, it’s now open to all. [**Please join us here!**](https://join.slack.com/t/rubycentralcommunity/shared%5Finvite/zt-2uh1lvotg-227RO9FJYT%5FC9RLNiA8Bng?ref=rubycentral.org)
### Local Meetup Grants
In collaboration with Fastly, Ruby Central has been providing grants for Ruby and Rails meetups and events all over the world! **In February, our grants supported meetups like Ruby AI in NYC, Madrid.rb, Geneva.rb, Boulder Ruby, Web Dev Talks in Colima, Mexico, and many more.**
We will make another announcement via our newsletter, Slack, and social media channels when grant applications open again (date TBD).
### Marty Haught on the Maintainable Software Podcast
Our Director of Open Source, Marty Haught, was a guest on the Maintainable Software Podcast! [**Listen here**](https://maintainable.fm/episodes/marty-haught-rethinking-technical-debtis-it-really-just-drift?ref=rubycentral.org) for a discussion on the sustainability of open source projects, the challenges of maintaining RubyGems, and why the metaphor of technical debt may not fully capture how software ages.
### Become a Ruby Central Corporate Sponsor
Your company can support the security and growth of the Ruby ecosystem by becoming a sponsor of Ruby Central. As a sponsor, you’ll support Ruby’s core open source tools and community development work, be recognized as a community leader, and can get a seat at the table by joining a working group or advisory board.
**Send sponsorship inquiries to Tom Chambers at sponsors@rubycentral.org.**
### Open Source Program News
For Open Source Program news, check out our dedicated newsletter, [**The OSS Changelog,**](https://rubycentral.org/news/ruby-centrals-oss-changelog-february-2025/) and **subscribe** [**here.**](https://rubycentral.org/news/ruby-centrals-oss-changelog-february-2025/#/portal/signup)
### TIL in CFP Coaching: How to Submit a Talk Proposal
URL: https://rubycentral.org/news/til-in-cfp-coaching-how-to-submit-a-talk-proposal/
Last updated: 2026-02-24T01:05:17.000Z
*Updated for all Ruby Central hosted Conferences: 2/23/2026*
[RubyConf 2026](https://rubyconf.org/?ref=rubycentral.org) planning is in full swing! With our program committee selected, a theme decided on, and preparations underway, we’re working hard to make RubyConf an unforgettable experience. **But the heart of any great conference isn’t just the organizers—it’s you, the Ruby and Rails community.**
That’s why the [Call for Proposals (CFP)](https://sessionize.com/rubyconf-2026/?ref=rubycentral.org) is so important. It’s a chance for community members to share fresh ideas, showcase their expertise, and contribute to the conversations shaping the future of Ruby and Rails. Talks at RailsConf and RubyConf reach hundreds—if not thousands—of engaged developers, both in person and through recorded sessions.
Speaking at a conference can feel like a big step, but it shouldn’t be intimidating. Whether you’re a first-time speaker or a seasoned presenter, this guide will walk you through crafting a compelling CFP submission that stands out to the program committee and that will resonate with attendees.
This guide includes takeaways from our CFP coaching sessions, led by previous speakers including Sage Griffin, Brandon Weaver, Joël Quenneville, Noel Rappin, Jade Dickinson, Mayra Lucia Navarro, Aji Slater, and Kevin Murphy.
**REMINDER: The deadline for RubyConf 2026 Las Vegas CFPs is March 15th. Don't miss out!**
[Submit Today](https://sessionize.com/rubyconf-2026/?ref=rubycentral.org)
## **Understanding the Review Process**
**One of the most important things to know is that the review process is mostly anonymous in the initial stages.** This means:
- Your name, profile image, and personal details are **hidden from reviewers to keep things unbiased.**
- Avoid self-identifying details in your talk description, like your company name or a well-known project you've led.
- Your speaker biography won’t be reviewed during selection but will be public-facing once accepted—so make it engaging!
- If you want to change something after your proposal is accepted, don’t worry—you’ll have the chance to refine your title and description before the event.
## **Structuring Your Proposal in** [**Sessionize**](https://sessionize.com/rubyconf-2026/?ref=rubycentral.org)
Each CFP submission has the following fields:
### **1\. Title**
- Remember to keep it **concise and engaging**.
- Make it **clear what attendees will learn**.
### **2\. Description (Abstract)**
The description is your **public pitch**—it should clearly explain what your talk is about and hook the audience and the program committee.
> "If someone is in the hall at the conference and they look at the description, and then somebody else shouts, ‘Hey, what's that talk about?’ that person should be able to answer in a sentence after having read it." - Aji Slater
- **Start with a problem.** What challenge does your talk address?
- **Explain the solution.** How does your talk help solve the problem?
- **Highlight key takeaways.** What will attendees walk away knowing?
- Keep it **easy to summarize**—if someone read your abstract in the hallway, could they explain it in a sentence?
> "By far, the biggest thing I'm always looking for \[when reviewing proposals\] is thought given to the audience takeaway." – Sage Griffin
### **3\. Additional Notes (For Reviewers Only)**
- Include a **loose outline** of what you plan to cover.
- Provide **extra details** that wouldn’t fit in the abstract but will help reviewers understand your approach.
## **How to Craft a Strong Proposal**
### **Know Your Audience**
It’s crucial to define **who your talk is for** and their level.
> "One of the big mistakes people make is saying their talk is for everyone. Be specific—are you speaking to beginners, intermediates, or advanced engineers?" – Brandon Weaver
- **Beginner:** Newcomers to Ruby, juniors, or those exploring a topic for the first time.
- **Intermediate:** Team leads, senior developers, or those with prior experience.
- **Advanced:** Experienced Rubyists, framework/library authors, or engineers focused on performance.
### **Create a Compelling Abstract**
- **Hook the reader early** with a problem statement.
- **Tell a story**—engage your audience and make them care.
- **Keep your focus clear** so the committee and attendees know exactly what to expect.
> "What is the problem you're trying to solve? \[The structure of your abstract should\] start with a problem (i.e., here's the thing that's going to be annoying for you) and then how you’re going to make the audience’s life better." – Joël Quenneville
### **Consider Your Positioning**
- **What’s trending in the Ruby community?** Look at past talks, what’s being talked about on social media and in forums, and, of course, the theme for this conference.
- **Check talk descriptions from previous conferences**—this can provide clues on what the organizers might want.
### A Note on Using AI
It's fine to use AI tools to help you think through your proposal, brainstorm angles, or proofread your writing. But when it comes to the actual content and voice of your proposal, it should come from you. Proposals that are written or heavily rewritten by AI tend to have a bland, generic feel. When many submissions read that way, they blend into the noise rather than standing out. The program committee is looking for your perspective, your experience, and your authentic voice. AI can support your process, but it can't replace what makes your talk uniquely yours.
## Common Mistakes to Avoid
- Don't submit a **vague or generic** talk.
- Don’t focus too much on **what you will cover—**instead, lean into **why people should care.**
- Don’t write an abstract that’s **too long or hard to skim.**
- Don’t forget to speak to your **intended audience**—clarity is key.
And if you’re **on the fence, apply anyway!** Don’t talk yourself out of submitting.
> "If speaking at RailsConf \[or another Ruby Central event\] has ever been a goal for you, now is the time to do it!" – Kevin Murphy
---
## **Helpful Resources**
- [RubyConf Schedule](https://rubyconf.org/schedule/?ref=rubycentral.org) – See how accepted talks are presented.
- Brandon Weaver’s CFP Examples [(Example 1)](https://gist.github.com/baweaver/f49cecf63bd123d69b7b698c250341d7?ref=rubycentral.org) [(Example 2)](https://gist.github.com/baweaver/5e5a632568c4996f1f4d83e5b78841c4?ref=rubycentral.org) – Example proposals for different conference styles.
- [Joël Quenneville’s CFP Guide](https://thoughtbot.com/blog/conference-talk-proposal-examples?ref=rubycentral.org) – How to structure your talk proposal effectively.
- [Sarah Mei on Writing a Strong CFP](http://www.sarahmei.com/blog/2014/04/07/what-your-conference-proposal-is-missing/?ref=rubycentral.org) – A deep dive into refining your submission.
- [Noel Rappin on What Makes a Good Proposal](https://noelrappin.com/blog/2014/03/what-i-learned-from-reading-429-conference-proposals/?ref=rubycentral.org) – Insights from a program committee reviewer.
- [RubyVideo.dev](https://www.rubyvideo.dev/?ref=rubycentral.org) – Videos from previous Ruby and Rails conferences and events.
**Best of luck—we can’t wait to review your proposals!**
### Company Spotlight: How Ruby Shaped DNSimple’s Growth
URL: https://rubycentral.org/news/company-spotlight-how-ruby-shaped-dnsimples-growth/
Last updated: 2025-02-20T05:42:39.000Z
[DNSimple,](https://dnsimple.com/?ref=rubycentral.org) a long-time Ruby Central sponsor, helps businesses simplify domain management, including registration and DNS hosting across multiple providers. **Their roots trace back to RubyConf 2010, where CEO Anthony Eden introduced the company to the Ruby community—and the world.** Earlier this month, he sat down with us to discuss the growth of DNSimple and how Ruby and Rails and the community have played a key role.
“When I started DNSimple, I was working as a full-time Ruby developer,” Eden explained. “I knew the Ruby community well, having attended and presented at many events. I knew that I could present a demo during a lightning talk that would resonate with Rubyists, showing a simple Ruby command-line tool where I could register a domain name, so I took the opportunity.” Eden’s decision to launch DNSimple at RubyConf made perfect sense, as it gave him the chance to connect directly with Rubyists, a community that would ultimately help propel the company forward.
The decision to build with Ruby was equally strategic. “In the beginning of DNSimple, we were only two people. I had been working exclusively with Ruby on Rails to build web applications for some time… \[and\] I knew Rails would get us from zero to launch quickly.” Ruby’s speed of development allowed Eden and his team to keep things lean and efficient, a critical factor for the success of an early-stage company.
Reflecting on how Ruby has continued to help DNSimple grow, Eden highlighted the language’s ability to enable rapid iteration and scalability. **“The speed of development that Ruby enabled let DNSimple stay lean and profitable throughout its earliest days, where it really mattered to be efficient.”** He also credits the Ruby community with opening doors to new customers and talent. “As DNSimple grew, my connections with the Ruby community helped DNSimple get other successful businesses using Ruby as customers, and we were able to hire Rubyists from that same community due to our long-time support.”
Today, DNSimple’s tech team is structured into two main areas: an application development team and a platform team. The application development team continuously improves the dnsimple.com web application as well as all of the other applications used to integrate DNSimple with both internal and external services.
**When it comes to the team, Eden has prioritized three core values: solving customer pain around domain management, building lean systems and automating them, and fostering respect and care for teammates.** These are values that also align with Ruby and its community. “Ruby, particularly with frameworks like Rails, enables us to deliver effective solutions without unnecessary complexity,” Eden explains. “It helps us solve customer problems quickly, and we can use Ruby to automate tasks with simple scripts. Ruby also has MINASWAN (Matz is nice, and so we are nice), which aligns well with our focus on caring for our teammates.”
Finally, Eden discussed how the company is exploring new technologies like generative AI—though with caution. “We are investigating whether or not there is value for our customers in using generative AI \[in our product\],” he said. “But first, we are more focused on how it could potentially help with public information we provide, like support documentation.”
Through their sponsorship of Ruby Central, DNSimple is not only supporting the community that helped them grow but also contributing to the continued success and stability of the Ruby ecosystem. “One of our sponsorship goals is to ensure that the Ruby ecosystem continues to grow and thrive. **We depend on Ruby heavily, and thus, a strong and stable community is very important to us,”** Eden concluded.
For startups and companies looking to build products efficiently, Eden advocates for Ruby: “Ruby is a solid language for developing software quickly. There are existing open source projects for almost anything you could want to do with Ruby, and of course, there is Rails, which I believe is still one of the best, if not the best, web frameworks available.”
For DNSimple, Ruby continues to be the foundation that allows them to deliver great products to their customers. You can meet members of their team at RailsConf 2025 this summer (July 8–10).
### Ruby Central's OSS Changelog: February 2025
URL: https://rubycentral.org/news/ruby-centrals-oss-changelog-february-2025/
Last updated: 2025-02-19T17:01:50.000Z
**Hello! Welcome to the February newsletter—now known as Ruby Central’s OSS Changelog.**
As mentioned in our previous newsletter, we will now be sending out separate updates for the Open Source Program and general Ruby Central organization and community news.
You can expect our general Ruby Central newsletter (the Ruby Central README) in your inbox later this month.
Read on for announcements about our Open Source Program and a report of the OSS work we’ve done from the previous month...
# Open Source Program Announcements
### Want to support Ruby Central and our Open Source Program?
2024 was a landmark year for project work, as highlighted in [our first Annual Open Source Report](https://rubycentral.org/news/ruby-centrals-first-annual-oss-report-2024/).
This was largely thanks to a few unique funding opportunities provided by some of our amazing partners.
**However, as we kick off the new year, we’re back into lean maintenance mode as we actively work to raise funds before starting on some exciting new projects.** Our 2025 project goals include:
- The public launch of Organizations, which will help teams and businesses manage gems and users under a single umbrella.
- An infrastructure modernization effort that will improve our security posture while addressing gaps in disaster recovery.
- Preparations for the EU’s Cyber Resilience Act, which will impact the compliance requirements for software products using open source.
**But we need support to help us bring it all to life.**
Our corporate sponsors and sustaining members drive all of the work we do, and we can’t continue to grow without that support. With additional funding, we will be positioned to not just maintain and secure the tools we all rely on but continue to enhance and expand them.
**If you’d like to support Ruby Central as a sustaining member, please explore** [**our membership options and benefits**](https://rubycentral.org/support/)**.** Membership starts at just $50/year, and every contribution helps us continue our important work.
**We also have corporate sponsorship opportunities for businesses.** Sponsorship is a direct investment in RubyGems, Bundler, and the core infrastructure that your technology relies on. Please reach out to our team at [sponsorship@rubycentral.org](mailto:sponsorship@rubycentral.org) to learn more about how you can get involved.
**We look forward to sharing more of our 2025 roadmap soon and starting to roll out more updates with your support.**
Until then, we’ll stay lean and focused on providing a secure and reliable RubyGems experience for all of you.
– Marty Haught, Director of Open Source at Ruby Central
### Our Security Engineer in Residence’s year in review
[Samuel Giddins](https://github.com/segiddins?ref=rubycentral.org) has published a [review of his 2024 work](https://traveling.engineer/posts/2024-in-review/?ref=rubycentral.org) as Security Engineer in Residence at [Ruby Central](https://rubycentral.org/). It was a busy year with the [sigstore](https://www.sigstore.dev/?ref=rubycentral.org) work as the centerpiece. He finishes with an overview of what he’ll focus on in 2025.
## RubyGems News
In January, we released RubyGems [3.6.3](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#363--2025-01-16) and Bundler [2.6.3.](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#263-january-16-2025) These releases bring a series of enhancements and bug fixes designed to improve the overall developer experience with RubyGems. Notable improvements include adding the [credentials file path to gem env](https://github.com/rubygems/rubygems/pull/8375?ref=rubycentral.org), preventing [fallback to evaluating YAML gemspecs as Ruby code](https://github.com/rubygems/rubygems/pull/8404?ref=rubycentral.org), adding [support for the Mise version manager file](https://github.com/rubygems/rubygems/pull/8356?ref=rubycentral.org), and including [Ruby 3.5 in Gemfile DSL platform values](https://github.com/rubygems/rubygems/pull/8365?ref=rubycentral.org) for better compatibility.
Some other important accomplishments from the team this month include:
[**Improvements to the Bundler documentation site**](https://bundler.io/docs.html?ref=rubycentral.org)
- The end-of-year Bundler release required documentation updates, but the process was challenging due to warnings, outdated dependencies, and minor issues. Additionally, longstanding problems (such as poor SEO and broken links caused by recent structural changes in the [rubygems/rubygems](https://github.com/rubygems/rubygems?ref=rubycentral.org) repository) needed attention.
- To improve the site, we addressed build warnings, upgraded all dependencies, fixed broken links, and enhanced SEO to make the Bundler documentation easier to find and navigate.
[**Improved “multi-Ruby” lockfile support**](https://github.com/rubygems/rubygems/pull/8401?ref=rubycentral.org)
- In Bundler 2.6 we implemented several changes to allow the same lockfile to be used across different Ruby versions, however, a minor issue was reported related to this functionality.
- To address this, we introduced an additional update to minimize lockfile changes when switching between Ruby versions, reducing unnecessary modifications and improving stability.
[**Bundler support for ARM architecture on Windows**](https://github.com/rubygems/rubygems/pull/8428?ref=rubycentral.org)
- Windows RubyInstaller2 added support for running Ruby on ARM architecture and we received a community contribution to enable Bundler compatibility. However, the existing Windows support code was somewhat cumbersome, making it difficult for the contributor to complete the implementation.
- To resolve this, we reworked how `platform: :windows` is handled in the Gemfile, which was the primary blocker. We also refactored the logic to ensure that the `:windows` value can accommodate similar scenarios in the future.
## [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) News
The updates made this month to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform. Sponsored hosting for [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) in January was provided by [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Fastly](https://www.fastly.com/?ref=rubycentral.org) and [Datadog](https://www.datadoghq.com/?ref=rubycentral.org).
The following are highlights of what the team worked on this month:
[**Fixed endless 5xx responses leading to pages**](https://github.com/rubygems/rubygems.org/pull/5392?ref=rubycentral.org)
- Rails returned response headers exceeding Nginx’s 4KB limit, triggering an `upstream sent too big header` error and causing persistent **502 Bad Gateway** responses. The issue stemmed from the `Redirector middleware`, which generated **301 redirects** with excessively long **Location headers**, particularly for `api.rubygems.org`. Debugging was further complicated by a logging issue that hid these errors.
- We fixed the logging pipeline to correctly capture errors and updated the middleware to prevent oversized headers. This fix was tested and verified in staging, successfully resolving the 502 errors.
**Upgraded to Ruby 3.4.1**
- We upgraded [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) to Ruby 3.4.1 to ensure compatibility with the latest Ruby version and take advantage of performance improvements and security updates.
[**Removed the** **Forwarded and X-Forwarded-Host headers**](https://github.com/rubygems/rubygems.org/pull/5409?ref=rubycentral.org)
- We removed the `Forwarded` and `X-Forwarded-Host` headers to enhance security and mitigate the risk of header spoofing attacks.
## **RubyGems Ecosystem News**
This is where we highlight other exciting updates made to Ruby infrastructure projects that support our RubyGems work.
[**RubyGems.org**](http://rubygems.org/?ref=rubycentral.org) **stats back up**
- After a year or two of empty graphs, we got [stats.rubygems.org](http://stats.rubygems.org/?ref=rubycentral.org) back up and running!
- All historical data is still present—only displaying the data stopped working, and we were finally able to figure that out and resolve it.
- Now, it is once again easy to see the Ruby, RubyGems, Bundler, and CI versions that are installing the most gems from [RubyGems.org](http://rubygems.org/?ref=rubycentral.org).
## Thank You
A huge thank you to all the contributors to RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) this month! We deeply appreciate your support and dedication.
### Contributors to RubyGems:
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@soda92](https://github.com/soda92?ref=rubycentral.org) Maple
- [@kyanagi](https://github.com/kyanagi?ref=rubycentral.org) Kouhei Yanagita
- [@Vasfed](https://github.com/Vasfed?ref=rubycentral.org) Vasily Fedoseyev
- [@joshleblanc](https://github.com/joshleblanc?ref=rubycentral.org) Josh LeBlanc
- [@rykov](https://github.com/rykov?ref=rubycentral.org) Michael Rykov
- [@johnnyshields](https://github.com/johnnyshields?ref=rubycentral.org) Johnny Shields
- [@the-spectator](https://github.com/the-spectator?ref=rubycentral.org) Akshay Birajdar
- [@edouard-chin](https://github.com/Edouard-chin?ref=rubycentral.org) Edouard Chin
- [@ntkme](https://github.com/ntkme?ref=rubycentral.org) なつき
- [@larskanis](https://github.com/larskanis?ref=rubycentral.org) Lars Kanis
### Contributors to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org):
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@w-masahiro-ct](https://github.com/w-masahiro-ct?ref=rubycentral.org) Masahiro
- [@huacnlee](https://github.com/huacnlee?ref=rubycentral.org) Jason Lee
- [@gemmaro](https://github.com/gemmaro?ref=rubycentral.org) Gemmaro
- [@kairoaraujo](https://github.com/kairoaraujo?ref=rubycentral.org) Kairo Araujo
- [@adrianthedev](https://github.com/adrianthedev?ref=rubycentral.org) Adrian Marin
- [@MilaZhou22](https://github.com/MilaZhou22?ref=rubycentral.org) MilaZhou22
- [@skatkov](https://github.com/skatkov?ref=rubycentral.org) Stanislav (Stas) Katkov
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
*If we missed you, please let us know so we can include you in our shout out!*
### January 2025 Newsletter
URL: https://rubycentral.org/news/january-2024-newsletter/
Last updated: 2025-01-29T19:19:53.000Z
Welcome to the January newsletter. Read on for announcements from Ruby Central and a report of the OSS work we’ve done from the previous month.
# Ruby Central Updates
## Chris Oliver Joining Ufuk Kayserilioglu as RailsConf 2025 Co-Chair
🚨Big news for RailsConf 2025! 🚨 We’re thrilled to announce that **Chris Oliver** (CEO of GoRails) will be joining **Ufuk Kayserilioglu** (Engineering Manager at Shopify) as our Co-Chairs for the final RailsConf in Philadelphia, PA. 🎉
Chris has been a cornerstone of the Rails community for over a decade. As CEO of GoRails, he has created essential tutorials to help Ruby and Rails developers grow in their careers. With his dedication to education and enhancing the ecosystem, we’re excited to collaborate with him to make our final RailsConf an unforgettable experience.
**As Co-Chairs, Chris and Ufuk will be working with Ruby Central to:**
- Set the vision and theme for RailsConf, making sure it’s inclusive, innovative, and reflective of the latest trends in Rails development.
- Shape the program content, from proposing tracks to reviewing Call for Proposals (CFPs).
- Lead the overall planning and execution of the event, helping to create an unforgettable experience.
“RailsConf has always been one of the highlights of my year,” says Chris. “With RailsConf coming to an end, I couldn’t pass up the opportunity to help make this a memorable last event. I’ve submitted talks and spoken at the conference in the past, but this is my first time helping organize and shape the theme. I have a feeling we will have some pretty great talks to choose from this year!”
**RailsConf Call for Proposals (CFPs) will be opening *very, very* soon, so keep an eye on our social media for updates.**
**Additionally, if you want to relive RubyConf 2024 in Chicago, you can check out this** [**amazing highlight video**](https://www.youtube.com/watch?v=STVaf3yYL1A&ref=rubycentral.org) **from our partners at Confreaks.**
## Ruby Central Hiring New Executive Director
Ruby Central is seeking a new Executive Director (ED) to lead our organization and shape the future of the Ruby ecosystem!
In this role, the ED will oversee RubyConf and RailsConf, help expand our Open Source Program, and drive community engagement, marketing, and fundraising to ensure Ruby Central’s long-term growth and sustainability.
**If you’re passionate about Ruby, its community, and its future, we want to hear from you! You can** [**learn more and apply here.**](https://www.linkedin.com/jobs/view/4131441592/?ref=rubycentral.org)
## Election of New Ruby Central Board Officers
Ruby Central is thrilled to announce the election of four new officers to our Board of Directors!
**Our newly elected officers are:**
**💎 President:** Valerie Woolard, Principal Software Engineer at Heroku
**💎 Vice President:** Kinsey Durham Grace, Product Infrastructure Engineer at GitHub
**💎 Treasurer:** Freedom Dumlao, CTO at Vestmark
**💎 Secretary:** Naijeria Toweett, Technical Manager at Girl Effect
In a year full of celebrations and transitions, we are excited to bring fresh energy to our board and collaborate on driving greater impact through our events, open source initiatives, and community development efforts.
## The Ruby Central Newsletter is Evolving
Starting in February, we are changing how we deliver updates to you!
We’ll be sending you two monthly emails: one focused on our Open Source Program and another dedicated to news about our organization, conferences, community highlights, and Ruby-related news.
**If you’re reading this, you’re already subscribed to both newsletters.** We’re excited to have you on this journey as we evolve and grow in 2025!
# Open Source Program
December was a slower month as the team enjoyed time off during the holiday season, but we’re happy to share the progress we made nonetheless. In December, Ruby Central's open source work was supported by Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org), [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Alpha-Omega](https://alpha-omega.dev/?ref=rubycentral.org), and Ruby Central memberships from 29 other companies, including Partner-level member [Sidekiq](https://sidekiq.org/?ref=rubycentral.org). In total, we were supported by 191 members. Thanks to all of our members for making everything that we do possible. <3
## Expansion of Open Source Program With Support From Alpha-Omega
Ruby Central is continuing to expand our Open Source Program this year with support from the [Alpha-Omega Project!](https://alpha-omega.dev/?ref=rubycentral.org)
This includes adding a full-time role for Marty Haught as our Director of Open Source, focusing on infrastructure reliability, security, and community engagement.
Additionally, our Security Engineer in Residence, Samuel Giddins, will continue to enhance the security of our open source tools and infrastructure. [You can read more details here.](https://rubycentral.org/news/alpha-omega-supports-ruby-centrals-expansion-of-open-source-leadership-security/)
## OSS News changes
This year we’re excited to make some changes to how we bring you OSS news, starting with making our newsletter more concise, to make it even easier to stay in the loop with our team and our work.
**Refining our reporting**
We’ll be cutting our reporting on monthly OSS spending ("Total Spent") and the monthly RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) GitHub repo summary, in favor of quarterly and annual reports published separately by Ruby Central. These reports will allow us to provide more detail on how we spend our OSS funds, and a more expansive view into the volume and impact of our security work for the Ruby community. Let us know what you think of these changes, and stay tuned for more to come!
## RubyGems News
In December, we released RubyGems [3.6.0](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#360--2024-12-16), [3.6.1](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#361--2024-12-17), [3.6.2](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#362--2024-12-23) and Bundler [2.6.0](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#260-december-16-2024), [2.6.1](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#261-december-17-2024), [2.6.2](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#262-december-23-2024) by mid-December, addressing and resolving identified regressions, and coordinating with the Ruby core team to ensure the new versions were integrated with Ruby ahead of its December 25th release. Ultimately, we shipped RubyGems 3.6.2 and Bundler 2.6.2 alongside Ruby 3.4, resolving several regressions from the initial releases.
The release of [Bundler 2.6](https://bundler.io/blog/2024/12/19/bundler-v2-6.html?ref=rubycentral.org) and [RubyGems 3.6](https://blog.rubygems.org/2024/12/16/3.6.0-released.html?ref=rubycentral.org) \*\*\*\*is the culmination of previous years’ work, particularly in regard to the lockfile checksum’s feature that we decided to delay and not ship with Bundler 2.5.
Other notable improvements include fixing an issue where [gem info tagged some non-default gems as default](https://github.com/rubygems/rubygems/pull/8321?ref=rubycentral.org), adding [a \--attestation option to gem push](https://github.com/rubygems/rubygems/pull/8239?ref=rubycentral.org) for improved security, [introducing bundle lock --add-checksums](https://bundler.io/blog/2024/12/19/bundler-v2-6.html?ref=rubycentral.org) to add checksums to existing lockfiles and [fixing JRuby warnings when using bundler/setup with Ruby's \-w flag](https://github.com/rubygems/rubygems/pull/8205?ref=rubycentral.org).
## [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) News
The updates made this month to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform. Sponsored hosting for [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) in December was provided by [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Fastly](https://www.fastly.com/?ref=rubycentral.org), and [DataDog](https://www.datadoghq.com/?ref=rubycentral.org).
The following are highlights of what the team worked on this month:
[**An update to RubyGems 3.6 and Bundler 2.6**](https://github.com/rubygems/rubygems.org/pull/5349?ref=rubycentral.org)
- This update includes the release of RubyGems 3.6 and Bundler 2.6, delivering enhancements and fixes to improve the overall developer experience.
- Key changes address minor regressions and stability improvements introduced in previous versions.
[**Expanded availability of the admin user create button**](https://github.com/rubygems/rubygems.org/pull/5312?ref=rubycentral.org)
- The admin user creation button is now displayed either in local environments or when user signups are disabled.
- This update ensures admins can easily create new users under these specific conditions, improving usability and access control management.
[**An update toPasswordsControllerTest** **to use modern Rails IntegrationTest**](https://github.com/rubygems/rubygems.org/pull/5291?ref=rubycentral.org)
- During a review of a potential vulnerability report, which was deemed not an issue, test coverage for the `PasswordsController` was increased to ensure robustness.
- Additionally, the tests were migrated to use the modern Rails `IntegrationTest` framework, replacing the older controller tests. This update aligns with current Rails recommendations and improves test reliability and maintainability.
## **RubyGems Ecosystem News**
This is where we highlight other exciting updates made to Ruby infrastructure projects that support our RubyGems work.
**Ruby Toolbox**
[\*\*Keeping the Ruby Toolbox Up to Date and Stable](https://github.com/rubytoolbox/rubytoolbox/pull/1524?ref=rubycentral.org):\*\* to ensure Ruby Toolbox remains modern and stable, we’ve upgraded the application to Rails 8 and Ruby 3.4.
## Thank you
Thank you to all the contributors of RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### Contributors to RubyGems:
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@soda92](https://github.com/soda92?ref=rubycentral.org) Maple
- [@st0012](https://github.com/st0012?ref=rubycentral.org) Stan Lo
- [@CamJN](https://github.com/CamJN?ref=rubycentral.org) Camden Narzt
- [@addersuk](https://github.com/addersuk?ref=rubycentral.org) Adam Leach
- [@djoooooe](https://github.com/djoooooe?ref=rubycentral.org) Josef Haider
- [@bquorning](https://github.com/bquorning?ref=rubycentral.org) Benjamin Quorning
- [@luizkowalski](https://github.com/luizkowalski?ref=rubycentral.org) Luiz Eduardo Kowalski
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@kou](https://github.com/kou?ref=rubycentral.org) Sutou Kouhei
### Contributors to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org):
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@Uaitt](https://github.com/Uaitt?ref=rubycentral.org) Lorenzo Zabot
- [@ozovalihasan](https://github.com/ozovalihasan?ref=rubycentral.org) Hasan Özovalı
- [@mehulkar](https://github.com/mehulkar?ref=rubycentral.org) Mehul Kar
- [@Kuanchiliao1](https://github.com/Kuanchiliao1?ref=rubycentral.org) Tony Liao
- [@yob](https://github.com/yob?ref=rubycentral.org) James Healy
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
*If we missed you, please let us know so we can include you in our shout out!*
### Ruby Central Welcomes New Board Members & Announces Officer Appointments
URL: https://rubycentral.org/news/ruby-central-welcomes-new-board-members-announces-officer-appointments/
Last updated: 2025-01-22T22:53:02.000Z
Ruby Central is excited to announce the appointment of two new board members and the election of four new officers to our Board of Directors. These appointments come at a pivotal time for the organization as we embark on the [search for a new Executive Director](https://www.linkedin.com/jobs/view/4131441592/?refId=W05F2FfKH0ognSkggFfvqA%3D%3D&trackingId=W05F2FfKH0ognSkggFfvqA%3D%3D&ref=rubycentral.org) and continue to expand both our [Open Source Program](https://rubycentral.org/open-source/) and community development initiatives.
**Our new board members include Freedom Dumlao and Naijeria Toweett.**
[**Freedom Dumlao**](https://www.linkedin.com/in/freedomdumlao/?ref=rubycentral.org)is a seasoned technology executive with experience at leading companies like Vestmark, Flexcar, Zipcar, Wayfair, and Amazon. **Currently the CTO of Vestmark,** Freedom brings strategic insights that will help drive Ruby Central’s efforts to expand the Ruby ecosystem and build stronger connections with top companies and startups.
[**Naijeria Toweett**](https://www.linkedin.com/in/naijeriatoweett/?ref=rubycentral.org) has a strong background in technical product management and open source community leadership. **Currently a Technical Manager at Girl Effect,** Naijeria is driving innovation in data engineering while advocating for gender equality and inclusivity in the tech industry, aligning with Ruby Central’s mission to foster a more diverse and impactful ecosystem.
**Additionally, the board has voted on the following new officer appointments:**
[**Valerie Woolard,**](https://www.linkedin.com/in/vwoolard/?ref=rubycentral.org) **Principal Software Engineer at Heroku, is taking on the role of President.** As President, Valerie will oversee the strategic direction of Ruby Central and guide the board in making high-level decisions. She will also work closely with our Executive Director to ensure the implementation of board resolutions, assist in new board member orientation, and lead the search for new executive leadership when needed. In her role, Valerie will also periodically assess the performance of board members to ensure alignment with the organization’s goals.
[**Kinsey Durham Grace,**](https://www.linkedin.com/in/kinseyanndurham/?ref=rubycentral.org) **Product Infrastructure Engineer at GitHub, is taking on the role of Vice President.** Kinsey will be ready to step in during the President’s absence, attend all board meetings, participate in the executive committee, and carry out special assignments as requested. Kinsey will play a key role in ensuring that Ruby Central remains committed to fostering diversity and inclusion in the tech industry, and she will actively contribute to board leadership decisions.
**Freedom Dumlao, in addition to joining as a new board member, will serve as Treasurer.** In this role, Freedom will be responsible for overseeing Ruby Central’s financial health. He will manage the organization’s finances, review regular financial reports, and work with our Executive Director and Chief Financial Officer to ensure that financial reports are timely and transparent. He will also present the annual budget to the board for approval and assist in reviewing the organization’s audit.
**Naijeria Toweett, in addition to joining the board, will serve as Secretary.** As Secretary, Naijeria will be responsible for managing official communications with board members, preparing meeting agendas, recording meeting minutes, and maintaining accurate board records. Naijeria will also take on the responsibility of assuming the role of President in the absence of both the President and Vice President.
“We are thrilled to welcome Freedom and Naijeria as new board members, as well as to see Valerie, Kinsey, Freedom, and Naijeria step into officer roles,” said Chelsea Kaufman, Ruby Central’s Transitional Executive Director. “In a year full of celebrations and transitions, we are fortunate to be bringing new energy to our board. All our newly elected officers and board members bring diverse perspectives, technical expertise, and a shared passion for supporting Ruby’s growth. We are excited to work with them to drive greater impact across our events, open source initiatives, and community development efforts.”
With this new leadership team in place, Ruby Central is well-positioned to drive the next phase of growth, innovation, and impact within the Ruby ecosystem. You can stay informed about our progress and upcoming initiatives by [signing up for our newsletter, or support us by becoming a contributing member.](https://rubycentral.org/support/#/portal/signup)
### Alpha-Omega Supports Ruby Central’s Expansion of Open Source Leadership & Security
URL: https://rubycentral.org/news/alpha-omega-supports-ruby-centrals-expansion-of-open-source-leadership-security/
Last updated: 2025-01-14T16:43:19.000Z
Ruby Central is excited to share that with the support of the [Alpha-Omega Project,](https://alpha-omega.dev/?ref=rubycentral.org) we are accelerating our [Open Source Program](https://rubycentral.org/open-source/) by adding a full-time role for our Director of Open Source, Marty Haught, and renewing Samuel Giddins’ position as Security Engineer in Residence. This funding will allow them to continue and expand their work on RubyGems, RubyGems.org, Bundler, and the broader Ruby Central Open Source Program.
# Marty Haught’s Expanded Leadership Role as Director of Open Source
As our Interim Open Source Lead since August 2024, Marty Haught has been instrumental in guiding our open source efforts. We are thrilled for Marty to transition from a part-time to a full-time role as Director of Open Source, where he will provide dedicated leadership for Ruby Central’s Open Source Program.
**Specifically, Marty will focus on:**
- **Leadership of RubyGems and Bundler teams:** Marty will continue to provide leadership for the RubyGems and Bundler teams, overseeing their operations and ensuring that the core infrastructure remains secure, reliable, and adaptable to developer needs. This includes managing day-to-day operations and ensuring the health and sustainability of RubyGems.org.
- **Operationalizing security for RubyGems:** Marty will build a robust security strategy, starting by overseeing the completion of a security inventory of RubyGems’ policies, systems, and services, building on the [Trail of Bits security audit.](https://blog.rubygems.org/2024/12/11/security-audit.html?ref=rubycentral.org)
- **Building a security-minded community:** Marty will spearhead the creation of a security-focused community within the Ruby ecosystem. This includes forming a security working group of Ruby committers, key gem maintainers, and enterprise customers to engage in dialogue around best practices and address security gaps.
# Samuel Giddins’ Continued Role as Security Engineer in Residence
Samuel Giddins, who has served as the Security Engineer in Residence for RubyGems since December 2023, will continue to enhance the security of our open source tools and infrastructure thanks to funding from Alpha-Omega.
In 2024, Samuel made significant strides in improving RubyGems.org’s security posture, including implementing trusted publishing mechanisms and remediating critical vulnerabilities identified through security audits.
This year, Samuel will focus on:
- **Maintaining and improving supply chain security:** Samuel will continue securing RubyGems.org’s supply chain by improving gem signing, advancing build provenance (extending his work on Sigstore), and ensuring that all gems are verifiable and trustworthy from source to installation.
- **Supporting secure gem installation:** Samuel will work on reducing the need for compiled extensions in gems, helping to ensure that gems can be installed securely and efficiently without requiring potentially risky compilation on user machines.
- **Addressing critical security vulnerabilities:** Samuel will continue to identify and remediate security risks within RubyGems.org, responding to new vulnerabilities as they emerge and enhancing the platform’s overall security infrastructure.
# About Ruby Central’s Open Source Program & The Alpha-Omega Project
The mission of Ruby Central’s Open Source Program is to maintain a secure, reliable ecosystem for the Ruby programming language. Our focus is on strengthening and sustaining Ruby’s core tools—including RubyGems.org, Bundler, and other essential infrastructure—to meet the needs of developers at every level, from individual creators to teams within large tech companies.
The Alpha-Omega Project’s mission is to protect society by catalyzing sustainable security improvements to the most critical open source software projects and ecosystems. They aim to build a world where critical open source projects are secure and where security vulnerabilities are found and fixed quickly.
With Alpha-Omega’s support, Ruby Central can continue to lead the way in creating a secure and sustainable open source environment, empowering developers and organizations to build with confidence.
### A Community-Driven Solution to Ruby’s Issue With Mutable Objects
URL: https://rubycentral.org/news/a-community-driven-solution-to-rubys-thorny-issue-with-mutable-objects/
Last updated: 2025-01-09T18:31:44.000Z
RubyConf 2024 will be remembered not just for its amazing talks and social events but for a moment when the community came together to resolve an issue that has frustrated Ruby developers for years.
This issue was raised by Nadia Odunayo (CEO and developer of The StoryGraph) in her closing keynote and centers around Ruby’s handling of new hashes. Thanks to Nadia’s talk and the efforts of the Ruby community, a solution has emerged that both solves the problem and demonstrates the power of open source collaboration.
# Nadia’s Keynote
In her keynote, Nadia revisited her alter ego, Dee Bug — a Ruby private investigator. As Dee Bug, she dug into this issue. **She explained that Ruby’s default argument behavior, where a mutable object (like an array or hash) is initialized only once, often leads to unintended side effects.**
Nadia explained that while this is the intended behavior in Ruby, it’s often unintuitive and confusing for developers—especially for those new to the language.
Nadia Odunayo's keynote, RubyConf 2024
# Building a Solution With RuboCop
Enter RuboCop, a Ruby static code analyzer. Thanks to Brandon Weaver, who had raised the issue of how new Hashes handle default objects in relevant Ruby forums two years ago, there was already broad consensus that this problem required a linter solution. Altering the language itself was not a good option, as it would break the very principles that make Ruby’s behavior predictable for developers. While mutating a shared default object is almost always unintended, creating a new hash should always function the same way, which would make special handling for mutable objects inelegant at the least. Fortunately, RuboCop can distinguish between these scenarios and alert developers when the issue arises.
In response to Nadia’s talk, David Corson-Knowles contributed by opening a pull request, which has now been integrated into RuboCop as a new rule. This rule alerts developers when mutable objects are used as default values in Hash.new, helping prevent the bugs that occur when all keys in a hash share the same mutable object. This ensures that each key receives either a unique or immutable default value.
# A Community-Driven Success
This solution not only resolves a long-standing issue but also helps teach best practices in Ruby. This issue with mutable defaults stems from a fundamental part of Ruby’s object-oriented nature, and understanding how default arguments and object references work is key to writing more predictable, robust code.
**As Nadia said in her keynote, continuous learning, experimentation, and community are at the heart of what makes the developer journey so rewarding.** The resolution of this issue is a perfect example of what can happen when a community comes together to solve a problem.
To learn more about the new RuboCop rule and its impact, you can check out the [pull request](https://github.com/rubocop/rubocop/pull/13463?ref=rubycentral.org) on GitHub.
Aside from this, what are your favorite things to come out of RubyConf? Share and tag Ruby Central on social!
### December 2024 Newsletter
URL: https://rubycentral.org/news/december-2024-newsletter/
Last updated: 2025-01-29T19:08:57.000Z
Hello! Welcome to the December newsletter. Read on for announcements from Ruby Central and a report of the OSS work we’ve done from the previous month.
# Ruby Central Updates
## RailsConf 2025 is official! 🎉
We are excited to officially announce that **RailsConf 2025 will take place from Tuesday, July 8th to Thursday, July 10th, 2025, in Philadelphia, PA.**
After nearly 20 years, RailsConf 2025 will be the final gathering of its kind — a tribute to the incredible legacy of Rails and the community members who have been on this journey with us.
As part of a strategic shift, RailsConf 2025 will be the only conference hosted by Ruby Central in 2025\. **This means there will be no RubyConf in 2025, but we are looking forward to RubyConf 2026, which will take place in the spring and become our flagship event moving forward.** This change lays the foundation for a new trajectory that will emphasize more regional events, grassroots community efforts, and more focused investment in open source projects.
We have not yet started selling early-bird tickets, but if you wish to support us, you can purchase a Supporter Ticket [here](https://ti.to/railsconf/2025?ref=rubycentral.org). Supporter Tickets offer full access to the conference and are sold at a premium to help with additional funding for our programs and operations, including our Scholars and Guides program.
**You can also encourage your organization to become a sponsor!** (Send sponsorship inquiries to sponsors@rubycentral.org)
Read more about RailsConf 2025 and future events [here.](https://rubycentral.org/news/announcing-railsconf-2025-and-a-new-chapter-for-ruby-central-events/)
## Ruby Central welcomes Chelsea Kaufman as transitional Executive Director
We’re excited to announce that [Chelsea Kaufman,](https://www.linkedin.com/in/chelskaufman/?ref=rubycentral.org) our Board President, is stepping into the role of Transitional Executive Director.
Over the past two years, Chelsea has been instrumental in shaping Ruby Central’s strategic direction. In this new role, she’ll guide us through a pivotal period of growth and lead the search for our next permanent Executive Director.
Chelsea is taking over from Adarsh Pandit, whose interim leadership has been instrumental in stabilizing Ruby Central and ensuring the organization’s future viability.
Read more about this leadership update [here.](https://rubycentral.org/news/ruby-central-welcomes-chelsea-kaufman-as-transitional-executive-director/)
## New Board Members: Freedom Dumlao and Naijeria Toweett
Ruby Central is also excited to welcome two new board members: Freedom Dumlao and Naijeria Toweett! 🎉
[Freedom Dumlao](https://www.linkedin.com/in/freedomdumlao/?ref=rubycentral.org) is a seasoned technology executive with experience at leading companies like Vestmark, Flexcar, Zipcar, Wayfair, and Drift. Currently the CTO of Vestmark, Freedom brings strategic insights that will help drive Ruby Central’s efforts to expand the Ruby ecosystem and build stronger connections with top companies and startups.
[Naijeria Toweett](https://www.linkedin.com/in/naijeriatoweett/?ref=rubycentral.org) has a strong background in technical product management, Ruby on Rails, and open source community leadership. Currently a Technical Manager at Girl Effect, Naijeria is driving innovation in data engineering while advocating for gender equality and inclusivity in the tech industry, aligning with Ruby Central’s mission to foster a more diverse and impactful ecosystem.
Our board plays a crucial role in the overall direction, governance, and strategic decisions of Ruby Central. We are excited to work with Freedom and Naijeria to drive greater impact across our events, open source, and community development work in 2025.
## RubyConf photos and videos
RubyConf 2024 was held in Chicago last month, and we now have photos and videos from the event! 🙌
You can find all the sessions and relive highlights on our [YouTube channel.](https://www.youtube.com/playlist?list=PLbHJudTY1K0fFsGc9a2tBFR-iUulnMJM7&ref=rubycentral.org) Perfect for binge-watching over the holiday break!
You can find the event photos [here.](https://drive.google.com/drive/folders/1GpyNQ0pEjBPDGHxTo82-shib3sg22QAk?ref=rubycentral.org)
We’d like to extend a big thank you to [Confreaks](https://confreaks.com/?ref=rubycentral.org) for video production and [Double Sunday Studios](https://doublesunday.co/?ref=rubycentral.org) for photography.
# Open Source Program
In November, Ruby Central's open source work was supported by Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org), [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Alpha-Omega](https://alpha-omega.dev/?ref=rubycentral.org) and Ruby Central memberships from 29 other companies, including Partner-level member [Sidekiq](https://sidekiq.org/?ref=rubycentral.org). In total, we were supported by 191 members. Thanks to all of our members for making everything that we do possible. <3
## Ruby Central supports RubyInstaller’s expansion to ARM64
At Ruby Central, we’re proud to support projects that make open source more accessible. One such initiative is [RubyInstaller,](https://rubyinstaller.org/?ref=rubycentral.org) an essential tool for building Ruby applications on Windows machines.
During RubyConf in November, we learned that Lars Kanis, the maintainer of RubyInstaller, had launched a GoFundMe campaign to purchase a new laptop with a Snapdragon-X chip. The Ruby Central team decided to fund the remaining balance of the campaign, enabling Kanis to expand RubyInstaller’s support for the latest ARM64 architecture.
Kanis has since received the laptop and reports that it’s already a great asset to his work. This investment aligns with our goal of making Ruby development more inclusive, particularly because Windows support is often overlooked in favor of macOS and Linux.
You can read more [here.](https://rubycentral.org/news/ruby-central-supports-rubyinstallers-expansion-to-arm64/)
## RubyGems News
In November, we released RubyGems [3.5.23](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3523--2024-11-05) and Bundler [2.5.23](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2523-november-5-2024). These releases bring a series of enhancements and bug fixes designed to improve the overall developer experience with RubyGems. Notable improvements include [validating the user input encoding for gem CLI arguments](https://github.com/rubygems/rubygems/pull/6471?ref=rubycentral.org) and ensuring the`--enable-load-relative` binstubs prolog works correctly [when Ruby is not installed in the same directory as the binstub](https://github.com/rubygems/rubygems/pull/7872?ref=rubycentral.org). Additionally, we [updated the \--ext=rust option to support compiling native extensions from source](https://github.com/rubygems/rubygems/pull/7610?ref=rubycentral.org) and [resolved an issue where bundle check](https://github.com/rubygems/rubygems/pull/8148?ref=rubycentral.org) could sometimes lock gems under the wrong source.
Some other important accomplishments from the team this month include:
**Welcoming First-Time Contributors**
We’re thrilled to see an influx of new contributors and are focusing on making contributions seamless and enjoyable.
- [**@soda92**](https://github.com/soda92?ref=rubycentral.org), a new Ruby enthusiast working on Windows, contributed extensively by:
- Improving setup documentation for Windows developers.
- Fixing broken links, unifying documentation, and enhancing the README to better explain what RubyGems is.
- Adding debugging instructions for Windows, improving RSpec tests, and fixing a `bundle exec` issue on Windows.
- [**@andrew**](https://github.com/andrew?ref=rubycentral.org) enhanced `bundle fund` by creating its missing man page and extended his work to cover other missing man pages. He also added a spec to ensure all Bundler commands remain fully documented.
- [**@jeromedalbert**](https://github.com/jeromedalbert?ref=rubycentral.org) has been a consistent contributor, helping with issue triaging, documentation, and bug fixes. Notably, he updated the CONTRIBUTING guide link, fixed issues with `bundle remove`, and added the spec for ensuring command documentation.
- [**@marcoroth**](https://github.com/marcoroth?ref=rubycentral.org) and [**@gemmaro**](https://github.com/gemmaro?ref=rubycentral.org) made their first contributions by improving the default output of `bundle gem`.
We deeply appreciate the efforts of all contributors in making RubyGems and Bundler better for everyone! 🎉
**Auditing and Updating Vendored Dependencies to the Latest Versions**
- November and December are dedicated to thorough housekeeping to prepare for the final releases of RubyGems and Bundler. This includes updating all development and test dependencies, either via Dependabot PRs or manually, and ensuring compatibility with the latest Ruby patch levels, including Ruby 3.4\. Daily CI against `ruby-head` has also been verified as green.
- We also improved license management by fixing the weekly automated PR process for new SPDX licenses and updating the license list with the latest additions. These updates ensure a polished and reliable release for all users.
**Bundler 2.6: Lockfile Checksum Verification Now Available**
In more recent news that we couldn’t wait to share before our holiday break: we released Bundler 2.6 this week with an exciting new change.
- With Bundler 2.6, we are introducing **gem checksum verification** in the **Gemfile.lock**, adding an important security feature to ensure your dependencies haven’t been tampered with. When enabled, Bundler will check the checksum of gems before installation, rejecting any mismatched files.
- To enable this feature, run bundle lock --add-checkums or set bundle config lockfile\_checksums true for automatic inclusion in new lockfiles.
- Other notable improvements in Bundler 2.6 include better Ruby version switching, improved handling of git dependencies, enhanced security for gem server credentials, and better support for **bundle exec** on Windows.
- For more details, see the full [blog post.](https://bundler.io/blog/2024/12/19/bundler-v2-6.html?ref=rubycentral.org) Happy bundling!
In November, RubyGems gained [194 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2024-11-01%7D...master@%7B2024-11-31%7D?ref=rubycentral.org) contributed by 18 authors. There were 3,441 additions and 1,360 deletions across 248 files.
## [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) News
The updates made this month to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform. Sponsored hosting for [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) in November was provided by [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Fastly](https://www.fastly.com/?ref=rubycentral.org), and [DataDog](https://www.datadoghq.com/?ref=rubycentral.org).
The following are highlights of what the team worked on this month:
[**Introducing Organizations on RubyGems.org**](https://github.com/rubygems/rubygems.org/pull/5201?ref=rubycentral.org)
- We’re preparing to release the Organizations feature that has been added to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) to help teams and businesses manage gems and users under a single umbrella. The new **Organization Onboarding** feature will simplify migrating gems to an Organization by allowing users to provide organization details, select gems, and assign roles to users.
- After confirming the details, the onboarding process will automatically link gems to the Organization, create Membership records, establish the Organization, and remove outdated Ownership records, streamlining team and business gem management.
[**A Streamlined Profile Update Experience**](https://github.com/rubygems/rubygems.org/pull/5250?ref=rubycentral.org)
- We’ve improved the profile update workflow to prevent unnecessary frustration when a password is missing. Previously, if users updated their email but forgot to include their password, the page would reload, display an error, and require the email to be re-entered.
- Now, when submitting the form without a password, the page will focus on the password field and display a prompt, allowing users to enter their password without losing any previously entered information.
[**Improved Control for Yanked Gems**](https://github.com/rubygems/rubygems.org/pull/5260?ref=rubycentral.org)
- We’ve introduced updates to ensure gem owners retain access to critical controls even when all versions of a gem are yanked.
- Owners can now manage ownerships, trusted publishers, and push new gem versions through a streamlined sidebar view. For non-owners, the adoption option will remain visible if it's currently active. This enhancement helps maintain seamless management and transparency for gem owners.

**An iteration of the new limited sidebar view for yanked gem owners*
In November, [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) gained [81 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2024-11-01%7D...master@%7B2024-11-31%7D?ref=rubycentral.org) contributed by 8 authors. There were 4,802 additions and 695 deletions across 190 files.
## RubyGems Ecosystem News
This is where we highlight other exciting updates made to Ruby infrastructure projects that support our RubyGems work.
### Ruby Toolbox
[**Ruby Toolbox Frontend Stack Update**](https://github.com/rubytoolbox/rubytoolbox/pull/1461?ref=rubycentral.org)
- The Ruby Toolbox frontend now uses `vite-rails` for asset bundling, ensuring compatibility with Rails 8\. This upgrade replaces the previous `Sprockets/Webpacker` setup.
- During the migration, we resolved legacy JavaScript issues and replaced an outdated autocompleter library, streamlining and modernizing the frontend.
## Total Spent
In November, we spent $57,103.66 on development work.
## Thank you
Thank you to all the contributors of RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### Contributors to RubyGems:
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@jeromedalbert](https://github.com/jeromedalbert?ref=rubycentral.org) Jerome Dalbert
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
- [@samisalamiws](https://github.com/samisalamiws?ref=rubycentral.org) Samisalamiws
- [@timon](https://github.com/timon?ref=rubycentral.org) Artem Ignatyev
- [@soda92](https://github.com/soda92?ref=rubycentral.org) Maple
- [@andrew](https://github.com/andrew?ref=rubycentral.org) Andrew Nesbitt
- [@larskanis](https://github.com/larskanis?ref=rubycentral.org) Lars Kanis
- [@adam12](https://github.com/adam12?ref=rubycentral.org) Adam Daniels
- [@mame](https://github.com/mame?ref=rubycentral.org) Yusuke Endoh
- [@gemmaro](https://github.com/gemmaro?ref=rubycentral.org) Gemmaro
- [@djberube](https://github.com/djberube?ref=rubycentral.org) David J Berube
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@corsonknowles](https://github.com/corsonknowles?ref=rubycentral.org) Dave Corson-Knowles
- [@eregon](https://github.com/eregon?ref=rubycentral.org) Benoit Daloze
- [@marcoroth](https://github.com/marcoroth?ref=rubycentral.org) Marco Roth
### Contributors to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org):
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
- [@kairoaraujo](https://github.com/kairoaraujo?ref=rubycentral.org) Kairo Araujo
- [@kinsomicrote](https://github.com/kinsomicrote?ref=rubycentral.org) Kingsley Chijioke
- [@jacklynhma](https://github.com/jacklynhma?ref=rubycentral.org) Jacklyn Ma
*If we missed you, please let us know so we can include you in our shout out!*
### Announcing RailsConf 2025 and a New Chapter for Ruby Central Events
URL: https://rubycentral.org/news/announcing-railsconf-2025-and-a-new-chapter-for-ruby-central-events/
Last updated: 2024-12-20T17:00:33.000Z
We are excited to officially announce that the **final** **RailsConf will be taking place from Tuesday, July 8th to Thursday, July 10th, 2025, in Philadelphia, PA.** 🎉
After nearly 20 years, **RailsConf 2025 will be the last gathering of its kind** — a tribute to the incredible legacy of Rails and the community members who have been on this journey with us.
As part of a strategic shift, RailsConf 2025 will be the *only* conference hosted by Ruby Central in 2025\. **This means there will be no RubyConf in 2025, but we are looking forward to RubyConf 2026, which will take place in the spring and become our flagship event.**
By concentrating on one conference per year, we can create a truly best-in-class experience for our attendees while ensuring Ruby Central’s long-term sustainability. This will also allow us to dedicate more resources to our [Open Source Program,](https://rubycentral.org/open-source/) which oversees the maintenance and expansion of crucial tools like RubyGems, RubyGems.org, and Bundler. Additionally, we’re committed to supporting more regional events and grassroots community efforts (see our recent [grant program for local events](https://docs.google.com/forms/d/e/1FAIpQLSfmXdc1GFqYF2imqP8DFYwt9ytOLXMpbx0mKIqydBlL0x6pKw/viewform?ref=rubycentral.org), which we are expanding in 2025).
While we bid farewell to RailsConf, we want to reassure the community that Rails will continue to have a presence at future events. Although we haven’t solidified programming for future RubyConfs, our current plans are to include a Rails track at RubyConf 2026 and beyond, similar to the successful RubyKaigi track at RubyConf 2024.
We’ve also worked with the Rails Foundation to plan the timing of our conference, ensuring that there will be sufficient space between RailsConf 2025 in July and RailsWorld 2025 in the fall for those who wish to attend both events. Plus, the timing allows for attendees of RubyKaigi in April to participate in all three major Ruby and Rails events without the pressure of back-to-back travel. For future events in 2026 onward, RubyConf will take place every spring, while RailsWorld will take place in the fall.
**We have not yet started selling early-bird tickets for RailsConf, but if you wish to support us, you can purchase a Supporter Ticket** [**here.**](https://ti.to/railsconf/2025?ref=rubycentral.org) Supporter Tickets offer full access to the conference and are priced at a premium to help fund our programs and operations, including the [Scholars and Guides program.](https://rubycentral.org/scholars%5Fguides%5Fprogram/)
**You can also encourage your organization to become a RailsConf sponsor!** Sponsoring this final RailsConf will showcase your company’s dedication to the Rails and Ruby ecosystem, provide unparalleled visibility in the Rails community, and highlight your support for open source and developer education. Please send sponsorship inquiries to Tom Chambers at [sponsors@rubycentral.org](mailto:sponsors@rubycentral.org).
We hope to see you in Philadelphia next year to celebrate the amazing legacy of RailsConf! **Stay tuned for updates on ticket sales, CFPs, and room blocks coming in early 2025\.**
### Ruby Central Supports RubyInstaller’s Expansion to ARM64
URL: https://rubycentral.org/news/ruby-central-supports-rubyinstallers-expansion-to-arm64/
Last updated: 2024-12-19T19:58:59.000Z
At Ruby Central, we’re proud to support projects that make open source more accessible to developers around the globe. One such initiative is [RubyInstaller](https://rubyinstaller.org/?ref=rubycentral.org), an essential tool for building Ruby applications on Windows machines.
RubyInstaller provides developers with a simple and seamless way to install Ruby on Windows, bundling the Ruby language, libraries, and development tools into a single package. RubyInstaller also includes RubyGems and the DevKit, ensuring that developers have everything they need without the complex setup that would otherwise be required on Windows.
**During RubyConf in November, we learned that Lars Kanis, the maintainer of RubyInstaller, had launched a GoFundMe campaign to purchase a new laptop with a Snapdragon-X chip.** The Ruby Central team decided to fund the remaining balance of the campaign, enabling Kanis to expand RubyInstaller’s support for the latest ARM64 architecture.
Kanis has since received the laptop and reports that it’s already a great asset to his work. He has been able to get Ruby and RubyInstaller up and running on the new hardware and added rake tasks for building RubyInstaller-head for ARM64, utilizing the ruby-head version from oneclick/rubyinstaller2-packages#21\. Rails is already running on the new setup and Kanis is working through issues related to DLL loading, fiber switching, and gem installations.
This investment aligns with our goal of making Ruby development more inclusive, particularly because Windows support is often overlooked in favor of macOS and Linux. We’re excited to see how RubyInstaller continues to evolve, ensuring Ruby remains accessible on modern devices.
### Ruby Central Welcomes Chelsea Kaufman as Transitional Executive Director
URL: https://rubycentral.org/news/ruby-central-welcomes-chelsea-kaufman-as-transitional-executive-director/
Last updated: 2024-12-13T14:59:59.000Z
Ruby Central is excited to announce that Chelsea Kaufman is taking on the role of transitional Executive Director. Kaufman is stepping in to guide the organization through a pivotal time of growth and is leading the search for the next permanent Executive Director. For the past two years, she has served as Ruby Central’s Board President and is stepping down from the board to assume this role.
Kaufman is taking over from Adarsh Pandit, who has served as interim Executive Director since May 2023.Pandit led the organization through a period of shifting industry dynamics, marked by pandemic-era impacts on events and economic challenges affecting the tech industry. His leadership has been instrumental in stabilizing Ruby Central, rallying the community around its mission, and ensuring the organization’s future viability.
Reflecting on his time with Ruby Central, Pandit said:
“After six years at Ruby Central and Ruby Together, I’m moving on to my next adventure. I’m deeply thankful for the opportunity to contribute to this amazing community and to meet so many more inspiring Rubyists. Ruby Central is well-positioned for an exciting future, and I look forward to seeing it grow and thrive.”
Over the past two years as Board President, Kaufman has played an important role in shaping Ruby Central’s strategic direction. She also brings a master’s degree in nonprofit management and expertise in guiding organizations through transitions, with a focus on organizational design and leadership development. She has been involved in the Ruby community for over a decade and was the CEO and co-founder of LEARN Academy, a Ruby on Rails boot camp.
Kaufman shared her goals for this transition:
“We are moving quickly to ensure that Ruby Central has the vision and leadership it needs to continue its work, and we’re taking the time needed to bring in the right people to make that happen.”
Over the past year, Ruby Central has been expanding its leadership team with a focus on the Open Source Program and broader ecosystem development.
“I’m very excited about the people coming into the organization,” says Kaufman. “We have people with strong expertise and ties to the Ruby community who will be helping us move into this new stage of growth.”
Over the last five months, Ruby Central has welcomed new key team members:
- **Marty Haught** joined as Open Source Program Director in August 2024 and will expand his role in 2025\. He oversees crucial projects like RubyGems, RubyGems.org, and Bundler. Marty previously served as a director on Ruby Central’s board from 2012 to 2023.
- **Rhiannon Payne** joined in October to lead marketing efforts, with plans to expand the organization’s reach and community engagement across open source, conferences, and general ecosystem development.
With this expanded team and Kaufman’s transitional leadership, Ruby Central is well-positioned to continue its mission of advocating for Ruby, supporting the developer community, and advancing the open source ecosystem.
Stay tuned as Ruby Central embarks on this next chapter, building on its strong foundation to ensure a thriving future for Ruby developers and the companies and organizations that build with Ruby.
### Ruby Central’s Infrastructure Improvements for RubyGems.org
URL: https://rubycentral.org/news/ruby-centrals-infrastructure-improvements-for-rubygems-org/
Last updated: 2024-12-04T19:31:04.000Z
At Ruby Central, we know that RubyGems.org is more than just a tool—it’s a lifeline for Ruby developers worldwide. With millions of daily downloads, RubyGems.org supports developers globally by providing secure, reliable access to Ruby gems. To maintain its resilience and scalability, we’ve embarked on a series of essential infrastructure improvements designed to optimize both performance and cost.
**Here’s how we’re strengthening the foundation of RubyGems.org to serve the Ruby community better:**
## From Rackspace to AWS
RubyGems.org has evolved significantly since its early days. Originally hosted on platforms like Heroku and Rackspace, it was maintained by individuals who volunteered their time and resources. But as demand grew, so did the need for a more scalable, stable infrastructure.
This led us to AWS, where we now leverage a Kubernetes-based architecture that supports high traffic volumes. This flexible, scalable setup ensures RubyGems.org remains reliable as it continues to grow with the community’s needs.
## Addressing Technical Debt for Long-Term Stability
When the new on-call team assumed responsibility for managing RubyGems.org, we inherited technical debt from years of incremental updates. Key infrastructure components required updates to ensure security, stability, and compatibility with modern systems. Here’s a breakdown of the critical upgrades:
### **Kubernetes**
- The version of Kubernetes powering RubyGems.org was approaching end-of-life, necessitating an urgent upgrade to maintain security standards and continued support. We upgraded Kubernetes to the latest version, integrating essential security patches and performance optimizations.
- We also updated core plugins within Kubernetes, such as **CoreDNS** and **kube-proxy**, which are critical in facilitating reliable internal communication across services. These upgrades strengthened the platform’s stability and improved processing speed, benefiting the entire Ruby community.
### **Postgres Database on AWS RDS**
- Our database layer, managed by Postgres on AWS’s Relational Database Service (RDS), was running on a version nearing end-of-life. This posed a security risk and limited our ability to utilize newer database features.
- By upgrading to a newer Postgres version, we enhanced the database’s security and performance while gaining access to advanced features supporting RubyGems.org's long-term stability.
- The on-call team established a process to upgrade our database without any downtime, ensuring uninterrupted service for developers.
### **Datadog for Real-Time Monitoring**
- Datadog is at the core of our monitoring strategy, providing real-time visibility into system health and application performance.
- With the enhanced Datadog setup, we now monitor comprehensive performance metrics, including system health, response times, error rates, and database performance. This enables us to set up automated alerts for critical metrics so our team can detect and address issues proactively—often before users are impacted.
- Thanks to the Datadog agent, the rubygems.org team has gained real-time monitoring and alerting of security and vulnerability exposures. This allows us to triage, task, and apply security patches quickly, ensuring our systems remain secure.
- Additionally, Datadog’s new dashboards and reporting tools provide a unified view of the entire system, allowing us to analyze performance across multiple availability zones and quickly identify areas for improvement. This proactive approach ensures that RubyGems.org remains reliable and performant for millions of developers worldwide.
## Improving Availability and Redundancy Across AWS Availability Zones
Reliability has always been a top priority for RubyGems.org. Previously, certain critical services, such as our OpenSearch-powered search cluster, were housed within a single AWS availability zone. This setup introduced risks: if an issue occurred within that zone—such as a power outage or network problem—our search feature could experience downtime.
**We implemented clustering across multiple availability zones within the same AWS region to improve resilience.** If one zone experiences an issue, another can seamlessly take over, maintaining uptime. This redundancy reduces the risk of service interruptions and ensures that critical features like gem search remain consistently available. By clustering key services across multiple zones, we’re ensuring uninterrupted access for developers worldwide.
## New Tools and Technologies to Enhance Performance
To meet the evolving needs of RubyGems.org’s growing user base, we’re integrating new tools and technologies to improve performance and reliability:
- **Data Management with Amazon S3**: Gems are stored in Amazon S3, which provides scalable, durable storage for the thousands of gems available. S3’s high availability ensures that gems are always accessible and securely stored.
- **Global Distribution with Fastly CDN**: To optimize download speed and minimize latency, RubyGems.org uses Fastly as its content delivery network (CDN). Fastly caches gems across its global network, reducing the load on our primary servers and allowing for faster access. When a gem is requested, it is quickly retrieved from S3, cached, and served to users worldwide, enhancing accessibility and performance. This setup ensures developers can quickly access gems from any location.
- **Reliable Caching with Redis**: We’re migrating from Memcache to Redis for a more robust caching solution. Unlike the single-node Memcache setup, Redis allows for a distributed, multi-node configuration, providing resilience against node failures. This transition to Redis improves redundancy and enhances caching speed.
## Cost Management and Optimization
Operating RubyGems.org on AWS provides the reliability the community expects, but it also requires careful budgeting. We conduct regular cost reviews, **and a recent audit of our S3 storage led us to remove outdated logs, resulting in approximately $1,000 in monthly savings.**
We are also exploring additional cost-saving strategies, such as **tiered storage** within S3\. By analyzing gem access patterns, we can classify infrequently accessed gems for lower-cost storage tiers while keeping high-demand gems readily accessible.
In addition, we’re investigating utilizing **reserved instances** for all of our compute resources to save on predictable workloads. By committing to longer-term AWS capacity, we can control compute costs while ensuring reliable service during peak loads.
## Support from the Sovereign Tech Agency and AWS
These improvements have been made possible through support from the [Sovereign Tech Agency](https://www.sovereign.tech/?ref=rubycentral.org) and AWS. STA funding has enabled us to tackle essential technical debt, enhance reliability, and add durability across the infrastructure. Additionally, AWS provides annual credits, which help offset the cost of redundancy across multiple availability zones.
## Managing a Community-Supported, 24/7 System
Operating RubyGems.org as a 24/7 service brings unique challenges. Although RubyGems.org serves a global community around the clock, much of its maintenance relies on a small team of volunteers. These dedicated contributors are essential to RubyGems.org’s operation, providing expertise and support to keep it running smoothly.
## Looking Ahead: What’s Next for RubyGems.org?
Our commitment to RubyGems.org is ongoing. We’re continuously exploring advanced infrastructure solutions to optimize costs, enhance security, and ensure RubyGems.org remains responsive to the community’s evolving needs. We’re also looking at additional options to improve scalability and redundancy further to future-proof RubyGems.org as the ecosystem grows.
## Thanking our Volunteers, Sponsors, and Ruby Community
With the support of our volunteers, sponsors, and community, we’re building a stronger, more resilient infrastructure that will sustain RubyGems.org for years to come.
Thank you for being part of this journey with us and for supporting our work to keep RubyGems.org dependable for developers worldwide.
### November 2024 Newsletter
URL: https://rubycentral.org/news/november-2024-newsletter/
Last updated: 2025-01-07T11:06:38.000Z
Hello! Welcome to the November newsletter. Read on for announcements from Ruby Central and a report of the OSS work we’ve done from the previous month.
In October, Ruby Central's open source work was supported by Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org), [AWS](https://aws.amazon.com/?ref=rubycentral.org), the [Sovereign Tech Agency (STA)](https://www.sovereign.tech/?ref=rubycentral.org), and Ruby Central memberships from 29 other companies, including Partner-level member [Sidekiq](https://sidekiq.org/?ref=rubycentral.org). In total, we were supported by 186 members. Thanks to all of our members for making everything that we do possible. <3
## Ruby Central News
### RubyConf 2024: Our Biggest Event Since the Pandemic
RubyConf 2024 took place in Chicago last week, bringing together over 600 attendees for three unforgettable days celebrating the Ruby language and community!
**Highlights included an opening keynote from the one-and-only Yukihiro “Matz” Matsumoto** and keynotes from Nadia Odunayo, Brandon Weaver, Nickolas Means, and Drew Bragg. We also had a RubyKaigi-inspired track that brought a taste of Japan stateside, plus a greater focus on technical talks compared to previous conferences.

**Yukihiro “Matz” Matsumoto presenting his keynote at RubyConf 2024\. Photo by* [**Double Sunday Studios*](https://doublesunday.co/?ref=rubycentral.org)**.*
From the incredible talks to game night and other social events, this RubyConf will be living in our heads rent-free til the next one!
Thank you to everyone who participated—including our speakers, sponsors, volunteers, and attendees—and for making this **our biggest event since 2020\.**
Missed it? Keep an eye on our social channels—more photos and videos are coming soon!
### Help Make the Last RailsConf Happen
RailsConf is the longest-running gathering of Rails developers, dedicated to building, managing, and testing Rails applications. **After almost 20 years, RailsConf 2025 will be our final Rails-specific event—**a celebration of the community and the incredible legacy we’ve built together.
**We are aiming to host RailsConf in July in Philadelphia.** We’re working hard to finalize these plans and secure our venue, but we need your support to make this vision a reality.

*Philadelphia, the historic city where we hope you'll join us to create a historic event!*
**Let us know if you’re interested in attending RailsConf 2025 by sharing your email** [**here!**](https://rubycentral.org/news/make-railsconf-happen/)Understanding the level of interest from the community is crucial as we move forward with planning and making this event a success.
**Additionally, you can help by becoming a sponsor, or suggesting your company sponsor!** Sponsoring this final RailsConf will showcase your dedication to the Rails and Ruby ecosystem, provide unparalleled visibility in the global Rails community, and highlight your support for open source and developer education. Email Tom Chambers at sponsors@rubycentral.org for more information.
### Ruby Central Open Source Program Launch
**Ruby Central has established the Open Source Program to ensure the long-term sustainability of Ruby’s core tools: RubyGems, Bundler, and RubyGems.org.** This marks a significant step in formalizing management and processes for maintaining these crucial projects, which are used by developers worldwide every day. The Open Source Program’s mission is to sustainably provide high-quality and secure infrastructure through RubyGems to reliably build Ruby software that enables businesses and our community to thrive.
Early initiatives include Trusted Publishing for secure gem releases and Organization Accounts for better team management, with more improvements on the way. By introducing structured oversight and fostering community collaboration, the Open Source Program is creating a stronger foundation for the Ruby ecosystem and paving the way for a more sustainable future for Rubyists and the technology we all love.
**You can read more about the Open Source Program** [**here.**](https://rubycentral.org/open-source/)
**In case you missed it, you can also read about the history of forming the Open Source Program and role of the Open Source Committee** [**here.**](https://rubycentral.org/news/a-new-chapter-for-rubygems-how-ruby-central-is-building-a-sustainable-future/)
### Read Our First Annual Open Source Report
Ruby Central’s first [Annual Open Source Report is now live,](https://rubycentral.org/news/ruby-centrals-first-annual-oss-report-2024/) offering a detailed look at everything we’ve achieved in the past year!
From November 2023 to November 2024, our Open Source Program has focused on enhancing the infrastructure, security, and usability of core tools like RubyGems, Bundler, and RubyGems.org. **Highlights include:**
- Trusted Publishing for secure gem releases
- \~99.99% uptime on RubyGems.org thanks to expanded 24/7 on-call support
- Upcoming Organization Accounts feature to improve gem management for teams
The report also outlines our vision for 2025, built on the pillars of Security, Stability, and Sustainability. **We’re prioritizing supply chain protections, robust disaster recovery planning, and long-term funding to ensure Ruby remains a top choice for developers worldwide.**
These efforts have been made possible through partnerships with organizations like Shopify, AWS, the Alpha-Omega Project, and the Sovereign Tech Agency, as well as contributions from individual and corporate members.
**You can read the Annual Open Source Report** [**here.**](https://rubycentral.org/news/ruby-centrals-first-annual-oss-report-2024/)
### Catch Up on “The State of RubyGems”
**If you missed our “State of RubyGems” talk at RubyConf, don’t worry—you can see the slides** [**here!**](https://speakerdeck.com/mghaught/state-of-rubygems-2024?ref=rubycentral.org)
Marty Haught (Director of Open Source), Samuel Giddins (Security Engineer in Residence), and Martin Emde (Principal Engineer) shared updates on security, infrastructure improvements, and what’s ahead for RubyGems in 2025\. As a complement to our Annual OSS Report, these slides offer a high-level overview of the work being done to strengthen the Ruby ecosystem and ensure its long-term reliability.

**Highlights of RubyGems.org's new design, featured in this year's State of RubyGems talk.*
We will also share the video as soon as it’s available.
### Fastly Grants for Local Ruby Meetups
[**Fastly**](https://www.fastly.com/?ref=rubycentral.org) **has partnered with Ruby Central to offer grants of up to $300 to support local Ruby meetups worldwide!** Funds can be used to cover expenses like venues, food, speaker costs, and more (excluding alcohol).
Want to bring together Rubyists in your area? [**Apply for a grant!**](https://docs.google.com/forms/d/e/1FAIpQLSfmXdc1GFqYF2imqP8DFYwt9ytOLXMpbx0mKIqydBlL0x6pKw/viewform?ref=rubycentral.org)
### Become a Ruby Central Member
Ruby Central’s [membership program](https://rubycentral.org/support/#/portal/signup) is a simple and impactful way for Rubyists (like you!) to support the tools and infrastructure that keep our ecosystem thriving.
**Member contributions help sustain:**
- RubyGems and Bundler, the backbone of Ruby development
- Support for Ruby local meetups and regional conferences worldwide
- Administrative costs for running our nonprofit organization
[Join us today](https://rubycentral.org/support/#/portal/signup) and help ensure the long-term success of the Ruby ecosystem!
### Follow Ruby Central on BlueSky
Ruby Central is officially on BlueSky! [**Follow us**](https://bsky.app/profile/rubycentral.org?ref=rubycentral.org) for updates on our OSS work and events (including RubyConf and RailsConf), as well as more educational content and community collaborations in the future.
### Communication & Transparency
**We’ve heard your feedback—you want more transparency and better communication from us.**
The good news is that we’ve recently added new marketing support and are working on fresh ways to connect with and engage the community in 2025\. Stay tuned for updates as we release exciting new projects and content!
## RubyGems News
In October, we released RubyGems [3.5.21](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3521--2024-10-03) and [3.5.22](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3522--2024-10-16) along with Bundler [2.5.21](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2521-october-3-2024) and [2.5.22](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2522-october-16-2024). These releases bring a series of enhancements and bug fixes designed to improve the overall developer experience with RubyGems. Notable improvements include [updates to the vendored uri and net-http libraries](https://github.com/rubygems/rubygems/pull/8112?ref=rubycentral.org), fixes to prevent `gem pristine etc` from [resetting twice](https://github.com/rubygems/rubygems/pull/8117?ref=rubycentral.org) and the removal of code that [degraded the accuracy of suggest\_gems\_from\_name](https://github.com/rubygems/rubygems/pull/8083?ref=rubycentral.org).
Some other important accomplishments from the team this month include:
[**Improved Support for Shared GEM\_HOMEs**](https://github.com/rubygems/rubygems/pull/8104?ref=rubycentral.org)
- Sharing `GEM_HOME` across environments, though common, often leads to complex errors tied to native library incompatibilities. These issues are challenging to diagnose and frequently reported by users. Our goal with this update was to reduce these reports, enhance user experience, and free maintainers to focus on other priorities.
- Initially, we aimed to detect and clarify these errors, but their varied nature made precise messaging difficult. Further analysis showed that RubyGems and Bundler already handle such cases by ignoring improperly built extension gems, except when conflicts involved default gems. Recognizing this, we implemented a straightforward bug fix to resolve these edge cases.
[**Enhanced Bundler Integration with RubyGems, Resolving bundle exec Edge Case**](https://github.com/rubygems/rubygems/pull/8165?ref=rubycentral.org)
- A reported issue involved `bundler` failing to run (with a final "r"), prompting a suggested fix. However, the affected code resided within Bundler's monkeypatches applied during `bundle/setup` to RubyGems, which has long been a suboptimal approach. This presented an opportunity to improve Bundler's integration with RubyGems, offering potential long-term maintenance benefits.
- We resolved the issue by eliminating these monkeypatches entirely. This was achieved by correcting Bundler's usage of the RubyGems API for setting gem specifications `Gem::Specification.all=`, which had previously overlooked default gems (including Bundler itself). Once corrected, the other monkeypatches were rendered unnecessary.
- Beyond fixing this edge case, our goal is to gradually integrate Bundler with RubyGems using proper APIs, reducing technical debt and potentially paving the way for a unified library in the future.
[**Improved Webauthn CLI Experience**](https://github.com/rubygems/rubygems/pull/8174?ref=rubycentral.org)
- Recent webauthn support for the CLI encountered issues when `gem push` or other commands required two authenticated requests, such as when an API key had invalid scopes or when signing in before using the gem CLI. This required obtaining or fixing the API key before completing the intended operation.
- The issue arose from reusing the same OTP obtained through webauthn for both requests, which is not permitted. The solution was to perform two separate webauthn requests to generate distinct OTP codes.
In October, RubyGems gained [166 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2024-10-01%7D...master@%7B2024-10-31%7D?ref=rubycentral.org) contributed by 15 authors. There were 1,302 additions and 14,205 deletions across 529 files.
## RubyGems.org News
The updates made this month to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform. Sponsored hosting for [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) in October was provided by [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Fastly](https://www.fastly.com/?ref=rubycentral.org), and [DataDog](https://www.datadoghq.com/?ref=rubycentral.org).
The following are highlights of what the team worked on this month:
[**Released Maintainer Role Feature**](https://blog.rubygems.org/2024/11/07/maintainer-role.html?ref=rubycentral.org)
- Until now, every gem owner on [Rubygems.org](http://rubygems.org/?ref=rubycentral.org) had the same permissions, regardless of their role or trust level within their organization. This highlighted a significant weakness: users with lower levels of trust could potentially cause considerable harm to widely used gems.
- To address this, we’ve introduced a new role field for gem ownerships. This enhancement allows gem owners to assign and configure roles for their gems, better reflecting real-world organizational structures and reducing potential security risks.
[**Converted RubyGems.org to Use Propshaft**](https://github.com/rubygems/rubygems.org/pull/5085?ref=rubycentral.org)
- With Rails 8 adopting Propshaft as the default, we aimed to make the switch. After transitioning to importmaps earlier this year, we were largely ready to move from Sprockets. However, our first attempt led to styles not loading on staging, prompting us to delay.
- While working on a new design, we realized our site’s caching behavior could be longer than expected, and Propshaft might work fine. After thorough staging checks and timing refresh intervals, we deployed to production. Unfortunately, things broke longer than on staging. New assets triggered 404 errors, causing some initial panic before resolving on their own.
- **Lesson learned**: A smoother deploy would have involved loading new assets alongside old ones to allow for gradual cache warming. We underestimated the impact and duration of the disruption—apologies for the temporary issues. All is working fine now!
[**Added bcrypt Password Validation**](https://github.com/rubygems/rubygems.org/pull/5160?ref=rubycentral.org)
- This update introduces bcrypt password validation to enhance security for password handling on [RubyGems.org](http://rubygems.org/?ref=rubycentral.org). It uses byte-size validation to prevent passwords longer than 72 bytes, as bcrypt silently truncates passwords exceeding this length.
In October, [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) gained [106 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2024-10-01%7D...master@%7B2024-10-31%7D?ref=rubycentral.org) contributed by 9 authors. There were 5,008 additions and 2,076 deletions across 288 files.
# Total Spent
In October we spent $99,803.16, on development work.
## Thank you
Thank you to all the contributors of RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### Contributors to RubyGems:
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@jbampton](https://github.com/jbampton?ref=rubycentral.org) John Bampton
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@tompng](https://github.com/tompng?ref=rubycentral.org) Tomoya Ishida
- [@leoarnold](https://github.com/leoarnold?ref=rubycentral.org) Leo Arnold
- [@jeromedalbert](https://github.com/jeromedalbert?ref=rubycentral.org) Jerome Dalbert
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
- [@sue445](https://github.com/sue445?ref=rubycentral.org) Go Sueyoshi
- [@karreiro](https://github.com/karreiro?ref=rubycentral.org) Guilherme Carreiro
### Contributors to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org):
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
- [@manuelmeurer](https://github.com/manuelmeurer?ref=rubycentral.org) Manuel Meurer
- [@kuanchiliao1](https://github.com/Kuanchiliao1?ref=rubycentral.org) Tony Liao
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
*If we missed you, please let us know so we can include you in our shout out!*
### Securing Ruby’s Future: How Ruby Central is Strengthening Security
URL: https://rubycentral.org/news/securing-rubys-future-how-ruby-central-is-strengthening-security/
Last updated: 2024-11-20T17:04:47.000Z
As open source software powers more of the world’s technology, security in the Ruby ecosystem has never been more critical. With billions of downloads per month and over 180,000 gems, RubyGems.org plays a key role in ensuring the reliability of software worldwide. At Ruby Central, we are leading the charge with a comprehensive approach to security, addressing today’s threats while anticipating tomorrow's challenges.
The Ruby Central Open Source Program, now guided by the OSS Committee formed in August 2023, has been at the forefront of our security efforts. The Committee, composed of contributors from across the Ruby community, acts as a steering body, providing oversight and strategic direction for key security initiatives. These projects are made possible by generous contributions from sponsors like [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Shopify](https://www.shopify.com/?ref=rubycentral.org), and the wider Ruby community, alongside support from the [Sovereign Tech Agency (STA)](https://www.sovereigntechfund.de/?ref=rubycentral.org) and partnerships with the Linux Foundation and OpenSSF’s [Alpha-Omega Project](https://alpha-omega.dev/?ref=rubycentral.org).
## Security Initiatives Supported by Generous Donors
Ruby Central’s security work is made possible through the generous support of external donors, who have enabled several critical initiatives to protect the Ruby ecosystem and ensure its long-term stability.
- **AWS-funded Security Work**: For the past year, Samuel Giddins’ full-time security-focused position has been entirely funded by AWS, Ruby Central’s cloud provider. One of his key responsibilities is integrating [Sigstore](https://www.sigstore.dev/?ref=rubycentral.org) into RubyGems, Bundler, and RubyGems.org. Sigstore allows developers to securely sign and verify packages without relying on long-lived signing keys, ensuring software integrity and protecting against tampering.
- **Shopify’s Contributions**: Shopify has also made significant contributions to Ruby Central, with a large portion of its funding dedicated to security-related initiatives. This generous support has been crucial in advancing key security improvements and ensuring that RubyGems and Bundler meet the highest security and reliability standards.
- **Automated Gem Scanning**: Mend.io fully funds and operates the automated gem scanning initiative, which continuously monitors newly updated gems for vulnerabilities. This system allows us to quickly identify and address potential security threats, enhancing the overall security of RubyGems.org.
- **Community-Driven Manual Malware Checks**: Besides automated scans, the RubyGems team, supported by the community, conducts manual reviews of newly published or updated gems. These checks help detect and remove malicious code, ensuring that RubyGems remains a trusted platform for developers.
Thanks to the support of AWS, Shopify, and Mend.io, these security initiatives are vital to maintaining the long-term security and stability of RubyGems.org and Bundler, protecting the Ruby community from evolving threats.
## STA-Funded Projects: Strengthening Ruby’s Core Infrastructure
The [**Sovereign Tech Agency (STA)**](https://www.sovereign.tech/?ref=rubycentral.org) has been instrumental in enabling Ruby Central to transition from a reactive security model to a proactive, strategic approach. STA funding has allowed us to implement several key initiatives that strengthen RubyGems.org’s security and reliability.
**Key Security Advancements Through STA Funding:**
- **Bundler Lockfile Checksums**: This feature ensures that the packages used in development are identical in production, preventing tampering and supply chain attacks. Developed over two years, it significantly enhances Ruby’s security without major infrastructural changes.
- **RubyGems.org Infrastructure Upgrades**: STA funding allowed for crucial upgrades to our Kubernetes platform and OpenSearch cluster, improving both stability and security. The implementation of [**Datadog Cloud Security Management (CSM)**](https://www.datadoghq.com/product/cloud-security-management/?ref=rubycentral.org) provides real-time monitoring and helps us proactively address vulnerabilities.
- **Trusted Publishing**: Built on [**OpenID Connect (OIDC**](https://openid.net/developers/how-connect-works/?ref=rubycentral.org)**)**, Trusted Publishing ensures that only verified users can publish or update gems, reducing the risk of unauthorized or malicious changes. This feature secures the gem publication process and strengthens the supply chain.
Thanks to STA, we’ve delivered critical security enhancements that ensure RubyGems.org remains a secure and reliable platform for developers.
## Audit-Driven Improvements: Insights from Alpha-Omega
Ruby Central’s partnership with the [**Alpha-Omega Project**](https://alpha-omega.dev/?ref=rubycentral.org) allowed us to conduct a comprehensive security audit of RubyGems.org, carried out by [**Trail of Bits**](https://www.trailofbits.com/?ref=rubycentral.org). This audit provided invaluable insights into areas where we could improve security across our infrastructure and codebase.
**Key Themes from the Alpha-Omega Security Audit:**
- **Infrastructure Security**: The audit identified opportunities to improve AWS configurations, reduce attack surfaces, and enhance infrastructure resilience.
- **Code Quality**: Recommendations were made to improve code quality, ensuring long-term maintainability and adherence to best practices.
- **Access Controls**: We’re implementing steps to further limit unnecessary privileges, strengthening access management policies across RubyGems.org.
The audit uncovered **33 findings**, including **7 medium-severity** and **1 high-severity** issue. While most findings were low-severity or informational, we’ve already begun implementing fixes for the most critical issues. A full audit report will be published soon, demonstrating our commitment to transparency and ongoing security improvements.
## Response to CVE-2024-21654: Reinforcing Multi-Factor Authentication (MFA)
In December 2023, a vulnerability, [**CVE-2024-21654**](https://nvd.nist.gov/vuln/detail/CVE-2024-21654?ref=rubycentral.org), was discovered, revealing a potential bypass in RubyGems.org’s multi-factor authentication (MFA) process. The Ruby Gems team responded swiftly, overhauling the MFA system to ensure this vulnerability was fully addressed.
**Key updates included:**
- **Stronger MFA Prompts**: We rebuilt MFA prompts to adhere to [**OWASP security guideline**](https://owasp.org/www-project-secure-coding-practices-quick-reference-guide/?ref=rubycentral.org)**s**, enhancing the protection of account recovery, password resets, and login actions.
- **Tightened Controls**: We introduced stricter MFA enforcement, requiring additional authentication factors for any sensitive actions, such as credential changes.
These changes have made RubyGems.org’s authentication process more secure than ever. While the system is robust, we continue encouraging users to enable MFA for their accounts to further protect their credentials and assets.
## Looking Ahead: Building a Secure Future for RubyGems
Ruby Central is dedicated to strengthening both supply chain security and operational resilience in the years ahead. Our vision includes:
- **Supply Chain Security**: At RubyConf, we will unveil a new feature designed to bring transparency and verification to gems uploaded to RubyGems.org. This enhancement will allow gem consumers to verify that the gems they consume were built by the parties they expect to be building them and have not been tampered with since building.
- **Operational Excellence**: Through continued investments in infrastructure, disaster recovery, and failover systems, we are reinforcing RubyGems.org to ensure stability and security, even in the face of unexpected challenges.
## A Call to Action for the Ruby Community
At Ruby Central, we’re committed to securing Ruby's future, but we can’t do it alone. Your involvement, whether enabling MFA on your RubyGems account, contributing to our security projects, or staying engaged with our updates, helps keep our community safe. Together, we can make Ruby a more secure, reliable platform for everyone.
### Help Make RailsConf 2025 Happen
URL: https://rubycentral.org/news/make-railsconf-happen/
Last updated: 2024-11-15T17:28:59.000Z
RailsConf is the longest-running gathering of Rails developers, dedicated to building, managing, and testing Rails applications. After almost 20 years, RailsConf 2025 will be our final conference — a celebration of the Rails community and the incredible legacy we’ve built together.
We are aiming to host RailsConf in July in Philadelphia. We’re working hard to finalize these plans and secure our venue, but we need your support to make this vision a reality.

A crowded hallway of happy developers.
## Here’s how you can help
### Register your interest
Let us know if you’re interested in attending RailsConf 2025 by [sharing your email below](#railsconf-interest)! Understanding the level of interest from the community is crucial as we move forward with planning and making this event a success.
### Become a sponsor
Help make RailsConf 2025 a reality by becoming a sponsor. Early commitments are crucial for us to mitigate financial risks and create a memorable event. Sponsoring this final RailsConf will showcase your company’s dedication to the Rails and Ruby ecosystem, provide unparalleled visibility in the global Rails community, and highlight your support for open source and developer education. Email Tom Chambers at sponsors@rubycentral.org to get involved.
We hope that this final chapter of RailsConf will serve as a tribute to the many developers and organizations who have been part of shaping the Rails ecosystem. Together, we’ll celebrate the legacy of Rails while looking ahead to Ruby Central’s future—with RubyConf as our flagship event, more support for regional conferences, and deeper investments in open source projects like RubyGems and Bundler.
### Ruby Central's First Annual OSS Report (2024)
URL: https://rubycentral.org/news/ruby-centrals-first-annual-oss-report-2024/
Last updated: 2024-12-02T20:40:46.000Z
This is a web preview of Ruby Central's FIRST Annual OSS Report, for 2024, sharing everything we've been working on over the last 12 months and the impact of our work. We will be publishing a finalized report by the end of this year.
# Executive Summary
From November 2023 to November 2024, Ruby Central’s Open Source Program made significant progress in enhancing the infrastructure and security of RubyGems, Bundler, and RubyGems.org, building a stable and resilient foundation for Ruby developers and organizations.
This inaugural open source report is intended to be released annually near the beginning of Q4 and coincide with RubyConf. It highlights our achievements, sponsors, team, and future plans. By sharing insights into our open source work, we aim to attract new funding and partnerships to ensure the long-term success of the Ruby ecosystem.
## Mission
The mission of Ruby Central’s Open Source Program is to maintain a secure, reliable ecosystem for the Ruby programming language. Our focus is on strengthening and sustaining Ruby’s core tools—including RubyGems.org, Bundler, and other essential infrastructure—to meet the needs of developers at every level, from individual creators to teams within large tech companies. By building and supporting key open source projects, we are empowering the Ruby community to work with confidence and ensuring that Ruby remains a top choice for software development.
## Highlights of the Year’s Achievements
This year, Ruby Central’s Open Source Program focused on initiatives to enhance security, stability, and usability across the Ruby ecosystem. Here are three standout achievements:
### Trusted Publishing
Trusted Publishing is a new feature that enables secure, automated gem publishing through OpenID Connect (OIDC), allowing developers to publish directly from trusted environments like GitHub Actions without needing long-lived API tokens. For example, a developer can set up a GitHub Actions workflow to automatically publish a gem after tests pass without manually handling sensitive tokens. This streamlines the publishing workflow and ensures that the code in public repositories matches the released gems, all while meeting organizational security standards. By introducing Trusted Publishing, we are enhancing the security and reliability of the Ruby supply chain on RubyGems.org.
### 24/7 On-Call Support with Secondary Rotation
Over the past year, we achieved \~99.99% uptime on RubyGems.org, with zero major outages and rapid resolution of minor degradations—an important achievement given that all Ruby applications depend on this infrastructure.
To ensure rapid response to any incidents, we provided 24/7 on-call support and strengthened coverage by adding a secondary rotation of on-call engineers. Our focus on monitoring and reliability will help us continue to build the trust and confidence of developers and organizations that deploy and maintain Ruby applications.
### Organization Accounts (Coming Soon)
The upcoming Organization Accounts feature is a highly anticipated release that will give companies and development teams more control over their gems through structured permissions management. With Organization Accounts, teams can assign and adjust roles, ensuring that only authorized users can manage specific gems. As team members change, permissions can be easily updated, helping to prevent disruptions and maintain continuity in gem management. This is especially valuable for large organizations like AWS, which manage hundreds of gems with many contributors.
The release will roll out in two stages: first, with dedicated admin access controls within RubyGems, allowing organizations to manage permissions and add or remove members. The second stage will enable them to officially link their gems to their organization, providing added security and transparency across the ecosystem. We will be sharing a preview of this work at RubyConf.
You can read more about these and other open source achievements in the “Ruby Central Open Source Summary” section below.
## Vision
**Our vision for 2025 centers on three core pillars: Security, Stability, and Sustainability.**
Security remains our highest priority, driving our continued efforts to strengthen supply chain protections and refine our cloud infrastructure controls.
Stability is essential for ensuring uninterrupted service, and we are dedicated to enhancing disaster recovery planning and operational documentation to prepare for any challenge.
Sustainability focuses on establishing stable funding for ongoing maintenance and essential projects, enabling the growth of team contributions, and ensuring that Ruby’s foundational infrastructure is supported for years to come.
## Funding Partners
Ruby Central’s work is supported by our funding partners:
- **Sovereign Tech Agency (**[**Formerly Sovereign Tech Fund**](https://www.sovereign.tech/news/stf-part-of-new-sovereign-tech-agency?ref=rubycentral.org)**):** Funds critical infrastructure and security enhancements, including work on Trusted Publishing.
- **Shopify (Ruby Shield Program):** Supports key development work to improve the reliability and security of Ruby’s core infrastructure, including contributing to Trusted Publishing.
- **AWS:** Sponsors our Security Engineer in Residence, Samuel Giddins, whose work has included developing Sigstore integration for RubyGems, enhancing Trusted Publishing capabilities, refactoring API security, and improving RubyGems performance through optimizations and security patches.
- **Alpha-Omega Project**: Supports specific projects like the Organizations feature and a security audit by Trail of Bits to strengthen RubyGems.
- **Individual and corporate members:** Ongoing contributions from individual and corporate members help sustain essential development and maintenance across Ruby Central’s open source ecosystem.
We’re grateful to all our sponsors and members for their commitment to building a secure and resilient foundation for Ruby’s future.
# About Ruby Central, RubyGems, Bundler, and the OSS Committee
## About Ruby Central
Ruby Central is a non-profit organization dedicated to advancing the Ruby programming language and fostering a welcoming, diverse global community. Since 2001, we have been creating online and offline spaces—such as RubyConf and RailsConf—that allow Rubyists to connect, engage, and learn from each other.
In addition to hosting events, we now support Ruby’s foundational infrastructure through our open source program, which launched in 2022 following our merger with Ruby Together. Through these combined efforts, we are sustaining the core infrastructure and providing essential resources that empower all Ruby developers to build, collaborate, and innovate.
### Core Programs
Ruby Central’s efforts span several core programs designed to support and advance Ruby:
1. **Community support and growth**: We support the Ruby community by organizing events like RubyConf and RailsConf and creating educational resources.
2. **Open source infrastructure**: We maintain and enhance crucial tools like RubyGems.org and Bundler, providing developers with a secure, dependable environment to manage and share Ruby libraries.
3. **Security initiatives**: We are committed to protecting the Ruby ecosystem against evolving threats through initiatives like Trusted Publishing, Sigstore integration, and an external security audit of RubyGems.org.
4. **Funding and partnerships**: We collaborate with corporate sponsors and community stakeholders to secure funding for projects, enabling us to maintain RubyGems.org and support initiatives that drive Ruby’s long-term success.
## RubyGems and Bundler’s Role in the Ruby Ecosystem
For nearly two decades, RubyGems and Bundler have served as the core infrastructure that enables Ruby developers to create, share, and install gem libraries with ease. This infrastructure has become indispensable in Ruby development, particularly for teams working with Rails, where they play a vital role in the setup, deployment, and maintenance of applications.
## A Timeline of RubyGems and Bundler’s Evolution
- **2003:** RubyGems was conceptualized at RubyConf (hosted by Ruby Central), marking the start of a standardized package management system for Ruby.
- **2004:** RubyGems launched, simplifying the installation and management of gem libraries for developers.
- **2009:** Bundler was developed to address dependency conflicts, ensuring compatible libraries within Ruby applications.
- **2010-2014:** Saw widespread adoption of RubyGems and Bundler, with significant contributions from Yehuda Katz, supported by Engine Yard.
- **2015:** Ruby Together was founded by André Arko to support ongoing maintenance of RubyGems and Bundler after Engine Yard stepped back.
- **2019:** Funding and sustainability challenges lead to merger discussions between Ruby Together and Ruby Central.
- **2022:** Ruby Together merged with Ruby Central, creating a unified organization to oversee Ruby’s core infrastructure and community initiatives.
- **2023:** Ruby Central formed the Open Source Software (OSS) Committee to implement a formal governance structure for RubyGems, Bundler, and RubyGems.org.
## The Open Source Committee
The Open Source (OSS) Committee was formed by Ruby Central in 2023, following our merger with Ruby Together. The committee is responsible for long-term strategy, governance, and funding for Ruby’s core open source tools, including RubyGems, Bundler, and RubyGems.org.
Over the past year, the OSS Committee focused on critical infrastructure improvements, bolstering security measures, and building a sustainable contributor pipeline. Key initiatives included implementing structured governance, enhancing alignment with industry security and compliance standards, and securing consistent funding from corporate sponsors and community partners. Through these efforts, the committee is laying a strong foundation for technical advancement and community resilience.
**To learn more about the Open Source Committee, you can** [**read the announcement post on our blog.**](https://rubycentral.org/news/a-new-chapter-for-rubygems-how-ruby-central-is-building-a-sustainable-future/)
# Ruby Central Open Source Summary (Nov 2023 - Nov 2024)
## Major Projects and Developments
### Trusted Publishing and Sigstore Integration
In late 2023, we introduced Trusted Publishing, a feature based on OpenID Connect (OIDC) that enables secure, automated gem publishing from trusted environments like GitHub Actions. By eliminating the need for long-lived API tokens, Trusted Publishing reduces security risks and streamlines the publishing process for developers.
Additionally, we have been focused on ongoing work with Sigstore, with the goal of creating a reliable system for signing and verifying gem attestations without persistent signing keys. Over the past year, we developed the [Sigstore ruby client](https://github.com/sigstore/sigstore-ruby?ref=rubycentral.org) (a task made challenging by our constraint to avoid native code outside the Ruby standard library) and are now working to integrate it into RubyGems, Bundler, and RubyGems.org. Once fully incorporated, Sigstore will enable developers to confirm the authenticity of published gems, establishing a strong foundation for dependency provenance. This work will also help bolster broader industry standards for software provenance through our collaboration with OpenSSF’s Securing Software Repositories working group.
### Security and Multi-factor Authentication (MFA) Enhancements
In response to a reported MFA vulnerability ([CVE-2024-21654](https://nvd.nist.gov/vuln/detail/CVE-2024-21654?ref=rubycentral.org)), RubyGems.org underwent extensive security improvements to its authentication processes. We revised MFA requirements, enhanced test coverage, and aligned with OWASP security guidelines to strengthen user authentication. This has improved security for login, password reset, and email confirmation by enforcing two-factor authentication across the platform.
Looking forward, we are considering implementing mandatory MFA for all users in order to align with industry best practices.
### Infrastructure Upgrades
This year, we implemented a series of targeted infrastructure upgrades to bolster the reliability, security, and scalability of RubyGems.org. Key updates included:
- **Kubernetes platform upgrade:** We transitioned RubyGems’s Kubernetes cluster to the latest version, improving container orchestration, optimizing resource allocation, and enhancing system stability.
- **OpenSearch cluster upgrade:** We upgraded OpenSearch, which significantly improved the resilience and speed of data retrieval. This is critical for handling the ever-growing dataset of Ruby gems and delivering fast search results to users.
- **PostgreSQL versioning:** We upgraded PostgreSQL across major versions through a controlled, manual migration process, ensuring compatibility and security without any downtime.
Additionally, we implemented Datadog Cloud Security Management (CSM), enabling continuous, real-time monitoring of potential vulnerabilities. This allows us to identify and respond to security risks swiftly and provides our team with an added layer of visibility into infrastructure health.
### Bundler Lockfile Checksums
In December 2023, we launched Bundler Lockfile Checksums as an opt-in feature to ensure that production environments deploy the exact dependencies used during development. This is a security feature that protects against supply chain attacks, such as split view and artifact replacement, by verifying that the deployed packages match the authoritative versions provided by RubyGems.org. Essentially, Bundler Lockfile Checksums offer many of the benefits of a binary transparency log but without the need for extensive infrastructure modifications.
Building this feature required nearly two years with the involvement of four engineers. Challenges included managing the variety of gem sources, ensuring authoritative checksums for package versions, and onboarding existing Bundler projects without compromising on security. We adopted this feature in our own production environment for RubyGems to verify dependencies and ensure compatibility with other users.
We have been gathering user feedback throughout the initial rollout and are working to further refine and enhance this feature (such as adding more controls and an interface to streamline usage) before releasing it to the public in December 2024.
### Organization Accounts for RubyGems.org
The new Organization Accounts feature is a powerful permissions management framework that allows teams to manage gem access and roles within a secure, structured environment. This feature is especially useful for large organizations such as AWS that manage extensive gem libraries and require streamlined permission control. Associating gems with an organization also enhances security by mitigating the risk of misrepresentation with gem naming.
This feature marks a significant step forward in aligning RubyGems with enterprise needs. It is also a stepping stone toward future work, such as scoped gems, SAML/OpenID authentication, and other enterprise features that might offer future revenue.
This feature is being rolled out in two phases, with internal permissions launched this year and full organizational connections to gems coming shortly after. This work will be previewed at RubyConf 2024 in Chicago.
## Notable Fixes and Performance Improvements
### Caching Git Gems
In response to challenges highlighted by Github, we have implemented improvements to Git-based gem caching, addressing issues that previously created redundant processing for dependencies stored in Git repositories. These improvements streamline dependency management across complex projects, reducing unnecessary fetch operations and improving efficiency for developers working with Git-managed gems.
### Bundler auto\_install Enhancement
In collaboration with Gusto, we expanded Bundler’s auto\_install feature to operate seamlessly across any command that invokes code updates. Previously limited to specific commands, this improvement reduces repetitive bundle install steps, ensuring that any changes to dependencies are automatically installed. The enhancement has proved particularly valuable for large teams, significantly optimizing their workflows and minimizing redundant manual intervention.
### Project-specific Gem Caches
We made significant updates to project-specific gem caching, enhancing dependency management for environments that require a contained gem cache, such as offline or self-contained setups. By resolving issues with dependencies sourced from Git rather than gem servers, projects can now maintain a local cache without additional scripts or workarounds. Positive feedback from GitHub and other organizations indicates that these changes have greatly simplified workflows for teams relying on isolated gem environments.
### Gem Rebuild
The “[gem rebuild](https://github.com/rubygems/rubygems/pull/4913?ref=rubycentral.org)” command enables verification of a .gem file by confirming it was generated from an expected source (provided that the gem supports reproducible builds and the source is available). This tool is useful for auditing and compliance, allowing developers to ensure that gems remain consistent with their original source code.
## Security Audit
Through support from the Alpha-Omega Project, Ruby Central partnered with Trail of Bits for a comprehensive security audit on the RubyGems.org Rails application and its underlying AWS infrastructure.
The audit identified 33 issues, including seven medium-severity items and one high-severity item. Notably, most of these findings do not constitute actual security breaches. Our team has been addressing each finding and using these insights to bolster RubyGems’s security posture.
Overall, the audit attests to the effort that the core team has put into ensuring RubyGems.org is secure and reinforces that we are working in the right direction with our efforts to implement more of our infrastructure as code and to codify and constrain our access policies.
## Community and Ecosystem Support
### Ruby Toolbox Maintenance and Enhancements
To mark its 15th anniversary, we have made a series of significant updates to Ruby Toolbox, enhancing its functionality and compatibility with current versions of Ruby and Rails. We also had to optimize the backend to handle larger data volumes, as the download count of the Bundler gem exceeded the integer column size that was originally chosen for the Postgres table that stores them.
We also implemented a partial and regularly updated production database dump that can be easily imported into local environments, allowing developers to load a realistic dataset on their machines quickly by running bin/pull\_database. We also configured a default setup for GitHub Codespaces so users can instantly launch a cloud-based development environment for Ruby Toolbox. These updates have made it faster and easier for contributors to explore and work with the codebase.
Additional features will include security vulnerability reports and comparative code size metrics, providing developers with a clearer picture of their gem dependencies. These insights aim to offer a more comprehensive view of library size, dependency trees, and potential security considerations.
### Community Engagement
Over the past year, Ruby Central hosted RubyConf and RailsConf, which served as key events for Rubyists to exchange knowledge, discuss emerging trends, and collaborate on Ruby’s future. Our open source team also focused on building tools and resources that cater to developers of all skill levels, from beginners to advanced contributors. These efforts reinforce Ruby’s reputation as an accessible and resilient programming language and community.
# Impact Summary
Impact of open source from November 1st, 2023 to Oct 31st, 2024:
- **Total number of contributors to RC’s open source projects:**
- 98 unique contributors to RubyGems/Bundler
- 34 unique contributors to RubyGems.org
- **Total number of downloads/installs of RC tools and packages:**
- Over 34 billion gem downloads
- Bundler downloaded 570 million times
- **Total investment:**
- $1,150,000+
# Open Source Team
Our OSS work is driven by these key contributors (listed alphabetically):
**André Arko** is a Ruby and Rails developer with over 20 years of experience. As a key member of the Bundler and RubyGems core teams and author of The Ruby Way, 3rd Ed., André has also built projects like cuberule.com and sunchaser.io, aiming to make life easier for on-call developers.
**Arun Agrawal** is a longtime Ruby developer since 2007, with contributions to the Rails framework and various open source projects. His work spans web applications and infrastructure management for platforms like RubyGems.org.
**Ellen Marie Dash** manages vulnerability reports for RubyGems, coordinating with HackerOne to maintain security across the ecosystem.
**Gift Egwuenu** is a Developer Advocate at Cloudflare with over seven years of web development experience. Specializing in developer relations, Gift contributes actively to open source initiatives, including writing monthly updates for RubyGems, and is passionate about making complex technology accessible.
**Martin Emde** is a Principal Engineer at Cloud City Development and core maintainer of RubyGems.org and Bundler. Known for his collaborative and open-minded approach, Martin values curiosity and inclusive problem-solving. He lives in the mountains of California with his family.
**Samuel Giddins** is the Security Engineer in Residence at Ruby Central, where he leads security efforts for RubyGems and RubyGems.org. With over a decade working in Ruby tooling, Samuel is committed to safeguarding the ecosystem.
**Marty Haught** leads Ruby Central’s Open Source Program as the Director of Open Source. An avid community builder based near Boulder, Colorado, he founded the Boulder Ruby group and has been an active member of the Ruby community since 2005\. Outside of tech, Marty enjoys channeling his creativity into baking and cooking, much to the delight of his family.
**Irene Kannyo** is the managing editor for the Ruby Central Newsletter and serves as the OSS Content Marketing Manager . She provides support with technical writing and editing for the monthly OSS report and other OSS content.
**David Rodríguez** contributes actively to the Bundler and RubyGems ecosystems, strengthening tools that serve the Ruby community.
**Colby Swandale** is a core contributor to RubyGems.org and creator of rubyapi.org. Dedicated to enhancing Ruby tooling, Colby aims to empower developers to build applications with greater ease.
**Josef Šimánek** is a Ruby developer with over 15 years of experience based in Prague, Czech Republic. Passionate about database systems, particularly PostgreSQL, Josef actively collaborates with the community to build tools that make development more impactful.
# Get Involved
There are numerous ways you can get involved with Ruby Central’s Open Source Program:
- Contribute code to RubyGems
- Join the conversation in [the Bundler Slack](https://join.slack.com/t/bundler/shared%5Finvite/zt-1rrsuuv3m-OmXKWQf8K6iSla4~F1DBjQ?ref=rubycentral.org)
- Read our RFCS and provide feedback: [github.com/rubygems/rfcs](http://github.com/rubygems/rfcs?ref=rubycentral.org)
- If you think you've found a security issue, please report it via [HackerOne](https://hackerone.com/rubygems?ref=rubycentral.org)
- Become a sponsor of Ruby Central to help fund our crucial work (details coming soon)
### A New Chapter for RubyGems: How Ruby Central is Building a Sustainable Future
URL: https://rubycentral.org/news/a-new-chapter-for-rubygems-how-ruby-central-is-building-a-sustainable-future/
Last updated: 2024-11-08T20:23:25.000Z
RubyGems and Bundler are the package management systems for Ruby applications used by developers worldwide. They’re also the backbone of a thriving world of Ruby software. For nearly two decades, these tools have simplified how developers develop, share, and install gem libraries, extending the simple Ruby programming language into a powerful and versatile ecosystem.
Software engineers working in Ruby, including Rails, use these tools every day when they initialize their development environment and deploy an application, making them vital to innovation, entrepreneurship, and several aspects of the world economy. However, maintaining this essential infrastructure has been a long and complex adventure that has led to forming a new governance model.
This article explores the historical journey of RubyGems and Bundler, the infrastructure that hosts them, the transition from Ruby Together to Ruby Central, and why a new governance model, spearheaded by the new Open Source Software committee, is essential for ensuring long-term sustainability and growth.
#### Timeline of RubyGems and Bundler Evolution
- **2003** – **RubyGems is conceptualized** at RubyConf, laying the groundwork for a standardized library management system.
- **2004** – **RubyGems** is officially launched, providing Ruby developers with an easy way to install and manage gem libraries.
- **2009** – **Bundler** is created to solve dependency management conflicts, ensuring that the correct versions of libraries are used in Ruby applications.
- **2010-2014**—**Bundler and RubyGems saw widespread adoption** and became essential tools in the Ruby ecosystem, with core contributions from Yehuda Katz. Engine Yard, a cloud services company and software developer, supported the tools.
- **2015**—**André Arko forms Ruby Together** to raise funds and begin paying the maintainers of RubyGems and Bundler after Engine Yard steps back from its technical support role for these tools.
- **2019** – **Ruby Together faces ongoing challenges** with securing consistent funding, prompting discussions of a merger with Ruby Central.
- **2022** – **Ruby Together merges with Ruby Central**, bringing the operational and financial management of RubyGems and Bundler under one organization for greater sustainability.
- **2023—The Ruby Central Open Source Software (OSS) Committee** is formed. Its focus is on formal governance, reducing technical debt, enhancing security, and ensuring the long-term sustainability of RubyGems and Bundler.
## The origins of RubyGems and Bundler
RubyGems was launched in 2004, following its development at RubyConf 2003\. It addressed a critical need by providing a standardized way for Ruby developers to install and manage gem libraries used in their Ruby code. This package manager quickly became integral to Ruby development, allowing for easy distribution and integrating third-party libraries into any Ruby application or script.
As individual applications became more complex and started using more and more gems, simply installing gems often led to conflicts where different gems wanted different versions simultaneously. The core team working on [Merb](https://en.wikipedia.org/wiki/Merb?ref=rubycentral.org) (a Rails competitor) began building a tool to automatically manage gem versions and conflict resolution. Funded by Engine Yard, Yehuda Katz and Carl Lerche built out the concept of Bundler to support their work separating Rails into many separate gems.
In 2009, Bundler launched alongside Rails 3.0 to solve dependency management within applications, ensuring developers and deployments always have the same versions of libraries. Over time, Bundler became indispensable and was eventually merged into the RubyGems project to streamline development work. While they remain distinct tools in usage, they now share a single codebase for greater efficiency, with RubyGems handling gem installations and Bundler managing dependency resolution.
## Early infrastructure and maintenance
RubyGems initially stored gems on RubyForge, a fork of [SourceForge](https://sourceforge.net/?ref=rubycentral.org) written mostly in PHP. Convinced a better website could be made, Nick Quaranto created Gemcutter, a Rails application hosted on Heroku, as a Ruby-native way to host and share gems. Within a few years, Gemcutter had so much momentum within the community that Ruby Central promoted it to become the official RubyGems.org software. While depending entirely on volunteers worked in the early years, the growing Ruby ecosystem outpaced the capabilities of this informal setup. RubyGems needed stability, scalability, and regular maintenance to support the increasing number of gems and developers.
## The transition to Ruby Together
Alarmed by the dwindling volunteer team, André Arko founded Ruby Together in 2015, a non-profit 501(c)6 trade association dedicated to maintaining and developing essential tools like RubyGems and Bundler. Supported by corporate sponsors and many community members contributing a few dollars a month, Ruby Together helped keep these services operational by funding the part-time work of several maintainers of RubyGems, Bundler, RubyGems.org, The Ruby Toolbox, and other projects.
Despite its popularity, Ruby Together faced long-term challenges in securing consistent funding and communicating its mission to the broader community. There was also confusion about the roles of Ruby Together, which funded maintenance, and Ruby Central, which paid for hosting RubyGems.org out of conference profits.
## Ruby Together’s merger with Ruby Central
While Ruby Central covered the hosting costs for RubyGems.org, Ruby Together managed much of the operational and development work. Recognizing the inefficiencies of this divided structure, the boards of directors at Ruby Central and Ruby Together collaborated to unify the organizations. They believed this merger would improve the management of Ruby's infrastructure, simplify non-profit operations, and address Ruby Together’s fundraising challenges.
In 2022, Ruby Together officially merged with Ruby Central, bringing both operational and financial oversight of RubyGems and Bundler under one umbrella. This change aimed to create a more sustainable model for managing these projects while reducing non-profit administrative burdens. During this period, Ruby Central faced difficulties hosting in-person events due to the global pandemic, leading to the postponement of some events and experimentation with online-only and hybrid formats.
At the same time, Ruby Central’s open source work began to receive significant financial support from partners such as [Shopify](https://www.shopify.com/?ref=rubycentral.org), the [Sovereign Tech Agency](https://www.sovereign.tech/?ref=rubycentral.org), [Amazon Web Services](https://en.wikipedia.org/wiki/Amazon%5FWeb%5FServices?ref=rubycentral.org), the [Linux Foundation’s Alpha-Omega Project](https://alpha-omega.dev/?ref=rubycentral.org), [Sidekiq](https://sidekiq.org/?ref=rubycentral.org), and others. Along with these new funding partners, the team took on additional administrative responsibilities, including project management for larger teams, reporting progress to partners, expanding their network at open source events, and publishing updates to enhance transparency.
Coming out of the pandemic era, Ruby Central has refocused on supporting the Ruby Community more broadly, including increasing organizational support for open source work. Former director Marty Haught rejoined Ruby Central in the summer of 2024 to support this new focus and lead the necessary additional work.
## The Ruby Central OSS Committee is formed
The merger of Ruby Together into Ruby Central emphasized the need for a formal governance structure to manage the growing complexity of RubyGems and Bundler. Previously, these projects were overseen informally. However, as the Ruby ecosystem expanded, the community required a structured model to address technical debt—such as outdated code and inefficiencies—and organizational debt, including unclear roles, informal processes, and a lack of oversight. Despite these challenges, RubyGems.org consistently delivered enterprise-level reliability, often achieving extremely low downtime that surpassed that of many commercial services.
To tackle these issues and ensure the long-term sustainability of RubyGems and Bundler, the Open Source Software (OSS) Committee was formed in August 2023\. The founding members were Mike Dalessio, Gabi Stefanini, Ufuk Kayserilioglu, and Marty Haught. Marty resigned as a committee member in August 2024 to take on the OSS Lead role but remains active as a representative for the OSS staff. By formalizing leadership, improving project management, and creating a pipeline for contributors, the committee is laying the groundwork for the continued success of these essential Ruby Central tools. Like any new committee, the members addressed urgent issues while wondering what the group's remit should be. We are excited to share our vision for the future with our community.
The OSS Committee has become crucial for implementing structured governance and providing long-term oversight, especially now that these projects operate fully under the Ruby Central umbrella. A future post will discuss the details of how the committee works, so stay tuned.
## Responsibilities and Goals of the OSS Committee
The Ruby Central OSS Committee is pivotal in sustaining Ruby’s core open source projects—RubyGems, Bundler, and RubyGems.org. By implementing a formal governance model, it provides essential oversight and strategic direction to meet the community's evolving needs and ensure a secure, resilient, and supportive ecosystem.
### Core Responsibilities of the OSS Committee
- **Governance and Oversight:** The committee provides a structured governance framework that guides high-level decisions across Ruby Central’s open source projects. This includes drafting policies, defining roles and responsibilities, managing member rotation, and enhancing accountability and operational stability.
- **Strategic Planning and Prioritization:** In its governance role, the OSS Committee sets strategic priorities for security and infrastructure improvements, aligning with community needs. Through resource allocation and roadmap development, the committee supports long-term growth and resilience.
- **Transparency and Community Engagement:** Committed to transparency, the committee maintains open communication through public roadmaps, RFCs on GitHub, and a feedback mechanism that allows the community to influence Ruby’s development direction actively.
- **Funding and Budget Management:** To support critical initiatives, the OSS Committee manages budget allocation and has secured sustainable funding through grants and donations. Clear guidelines on sponsorships ensure financial support aligns with Ruby Central’s mission, balancing community and corporate interests.
- **Risk and Compliance Management:** In response to evolving regulations, the committee is implementing robust security and compliance protocols, including multi-party approval for production changes and audit trails to uphold security standards, notably in line with regulations like the EU’s Cyber Resilience Act.
### Current OSS Committee Initiatives
- **Operational Continuity and Leadership Sustainability:** To prevent contributor burnout and ensure stability, the committee is establishing succession plans and distributing responsibilities, maintaining resilience across Ruby’s infrastructure.
- **Building a Security-First Culture:** Security remains a top priority. The committee provides a trusted development environment within Ruby's ecosystem through audits, manual malware checks, and community-supported gem scans.
- **Contributor Pipeline and Diversity Initiatives:** To sustain community growth, the OSS Committee is fostering diversity by actively developing a contributor pipeline focused on historically underrepresented developers, enriching the community with diverse perspectives and innovation.
- **Clear Communication and Community Accountability:** The committee promotes transparency and accountability by providing regular updates to the Ruby Central board and community. This provides clear insights into project updates and opens channels for feedback, fostering trust and engagement.
- **Strengthening Community and Corporate Partnerships:** The committee actively engages with both the Ruby community and corporate sponsors to ensure financial sustainability, enhancing RubyGems and Bundler while balancing community and corporate support.
## Looking forward: A new chapter for RubyGems
The formation of Ruby Central’s OSS Committee marks a key milestone in the evolution of RubyGems and Bundler. By formalizing governance, reducing technical debt, and involving community leaders and corporate sponsors, Ruby Central ensures these tools remain secure, stable, and well-maintained for the long term.
This effort goes beyond managing code and servers—it’s about fostering a thriving community, supporting developers, and safeguarding essential tools. With a renewed focus on governance, transparency, and sustainability, Ruby Central is building a more resilient foundation for Ruby’s growing open source ecosystem.
As Ruby Central enters this new chapter, the community can trust that RubyGems and Bundler will continue to thrive. Understanding and sharing the long and sometimes winding path to the present is important to better plan for a more mature and robust future that benefits every Ruby developer. Through the dedication of contributors, sponsors, and community members, Ruby Central is working to ensure the long-term stability and growth of our development environment and our community.
### Ruby Central Joins Eclipse Foundation Working Group for Open Source Security & Compliance
URL: https://rubycentral.org/news/ruby-central-joins-eclipse-foundation-working-group-for-open-source-security-compliance/
Last updated: 2024-11-07T02:01:39.000Z

We’re excited to announce that Ruby Central has become a member of the Eclipse Foundation's newly launched Open Regulatory Compliance (ORC) Working Group. This membership gives us a voice at a critical time as the open source community faces increasing regulatory pressures, particularly with the European Cyber Resilience Act.
# What is the Eclipse Foundation?
The Eclipse Foundation is one of the largest independent nonprofit organizations focused on open source software development. With over 385 members, it provides a platform for software developers, innovators, and businesses worldwide to collaborate on open source projects that drive innovation across various industries.
The Eclipse Foundation hosts Adoptium, Software Defined Vehicle, Jakarta EE, Eclipse IDE, and 420+ open source projects, including runtimes, tools, specifications, and frameworks for enterprise, cloud, edge, automotive, AI, embedded, IoT, systems engineering, open processor designs, and more. Now, with the launch of the Open Regulatory Compliance (ORC) Working Group, it’s addressing the growing need for regulatory compliance in the open source ecosystem.
# Reasons for the ORC Working Group
As open source adoption grows, so do the associated risks and challenges. The open source ecosystem is now under increasing pressure to comply with global regulations surrounding security and data privacy.
One of the most pressing issues is the European Cyber Resilience Act (CRA), which introduces strict security requirements for third-party components used in software development. Many open source projects rely on these third-party dependencies, and it can be challenging to track and ensure the security of every component.
The ORC Working Group was formed to help open source projects navigate this evolving regulatory landscape. By working closely with its members, the group is developing best practices, frameworks, and tools that will help projects like Ruby Central’s RubyGems and Bundler meet new compliance standards.
Additionally, the ORC’s work will help inform governments, the public, and regulatory bodies about how these new regulations will impact open source development and innovation.
# What does this mean for Ruby Central?
As regulatory requirements become more complex, it’s crucial that all third-party dependencies within RubyGems, Bundler, and our other open source projects comply with the latest security standards.
Through our participation in the ORC Working Group, Ruby Central is committed to preparing the Ruby ecosystem for these changes. We’ll have access to resources to help our team navigate security and compliance challenges so that our projects remain resilient. Additionally, we’ll have a voice in shaping processes that will help the wider open source community track vulnerabilities, manage dependencies more securely, and meet the requirements of laws like the CRA.
We look forward to helping shape the future of open source security and compliance. But we can’t do it alone—the more organizations that join the ORC, the stronger our impact will be.
To find more information about the ORC Working Group and how to join, you can visit the [participation page on their website.](https://orcwg.org/participate/?ref=rubycentral.org)
### Announcing Ruby Central's Partnership with Fastly: Enhancing Performance & Stability for Open Source Tools
URL: https://rubycentral.org/news/announcing-ruby-centrals-partnership-with-fastly-enhancing-performance-stability-for-open-source-tools/
Last updated: 2024-11-07T02:02:01.000Z

Ruby Central is thrilled to announce our partnership with Fastly, a leader in edge cloud services, to boost the speed, security, and stability of Ruby’s open source infrastructure.
Fastly has committed over half a million dollars in in-kind services to Ruby Central over the next five years. This support will be crucial for projects like RubyGems and Bundler, ensuring they continue to perform at their highest level as the Ruby ecosystem grows.
# What is Fastly?
Fastly provides an edge cloud platform that makes things happen instantly, anywhere across the internet. It is best known for getting content to many millions of users every day and making many of your favorite sites and apps speedy, personalized, and secure.
If you’ve ever downloaded a Ruby gem in the past several years, Fastly’s infrastructure was likely working behind the scenes. Their network optimizes content delivery while maintaining low-latency responses, which is essential for large-scale applications like RubyGems.
Fastly has also been a strong supporter of open source software for years, contributing its technology to help projects like ours scale.
# What does this mean for Ruby developers?
If you use RubyGems or Bundler, Fastly will continue to enhance their speed and reliability by caching and distributing gem downloads through its global CDN. This means faster downloads, better response times, and less strain on Ruby Central's infrastructure.
Fastly’s platform also includes built-in security features, which will help protect RubyGems from security threats like DDoS attacks.
# Impact on Ruby Central
By covering infrastructure costs in a multi-year commitment, Fastly is helping Ruby Central navigate the ongoing challenges of maintaining large-scale open source package managers like RubyGems.
As the ecosystem grows—both in terms of the number of gems and the developers relying on them—so do the demands on our infrastructure. With Fastly, RubyGems will scale seamlessly to meet these demands, offering stability and sustainability in the long term.
With this partnership, Ruby Central can focus on improving and supporting the tools that power the Ruby community, while the community can remain confident that our infrastructure will keep up with the increasing demand.
### Why Ruby Central Supports the Open Source Pledge
URL: https://rubycentral.org/news/why-ruby-central-supports-the-open-source-pledge/
Last updated: 2024-11-07T02:02:12.000Z
Ruby Central is proud to announce our support of the [Open Source Pledge](http://www.opensourcepledge.com/?ref=rubycentral.org), spearheaded by our OSS sponsor [Sentry](http://sentry.io/?ref=rubycentral.org), which asks companies to pay open source maintainers fairly and make the open source ecosystem more sustainable.
As a member company, Ruby Central has committed to paying for the use of open source software (directly or through a funding organization) and compensating maintainers for the important work they do.
We join many of the most prominent open source organizations across the world in supporting the Pledge, which reflects our deeply felt values and our commitment to maintainers and Rubyists who rely on our open source work (such as RubyGems and Bundler).
As businesses and individuals rely more heavily on OSS, the strain on maintainers to provide timely updates and security patches continues to grow—often without fair compensation for their crucial work. Recent high-profile security incidents like XZ and Log4Shell have put a spotlight on the security challenges developers face against a backdrop of burnout that has reached an all-time high. The Pledge will ultimately support OSS maintainers and inspire a shift toward healthier work-life balance and more robust software security practices.
Ruby Central raises funds through donations and grants, which we use to fund crucial open source projects that support the Ruby software ecosystem. Although the majority of development work is paid for through these donations, some is done through volunteer efforts. We recognize that the model of donated development efforts is unsustainable, contributes to burnout, and results in turnover, which is why we’re dedicated to making this shift.
### **How you can help:**
If you are an organization that uses open source work, join us and Sentry in committing to the Open Source Pledge. The minimum requirement to join is a commitment of $2,000 per year per developer on staff, paid directly to any open source maintainer or Foundation of your choice. Then, call your peers to join the Open Source Pledge and learn more about issues around sustainability in maintaining OSS.
Chad Whitacre, Head of Open Source at Sentry, says it best:
"This isn't just about cutting a check. It's about recognizing the enormous value that open source maintainers provide to the tech community. We’re inviting companies to step up and give back to a system we rely on. We believe this pledge will not only build goodwill with the developer community but more importantly, it will create a safer, more resilient OSS ecosystem for everyone."
“As the non-profit organization dedicated to supporting and advancing the Ruby programming language, Ruby Central understands the importance of a collaborative community and what is needed for a thriving ecosystem,” says Adarsh Pandit, Executive Director at Ruby Central. “We are pleased to see the initial Open Source Pledge members do their part to support the sustainability of open source software and look forward to participating.”
For more information about the Open Source Pledge and how to participate, please visit [osspledge.com](https://osspledge.com/?ref=rubycentral.org).
### October 2024 Newsletter
URL: https://rubycentral.org/news/october-2024-newsletter/
Last updated: 2024-11-25T20:12:33.000Z
Hello! Welcome to the October newsletter. Read on for announcements from Ruby Central and a report of the OSS work we’ve done from the previous month.
In September, Ruby Central's open source work was supported by Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org), [AWS](https://aws.amazon.com/?ref=rubycentral.org), the [Sovereign Tech Fund](https://www.sovereigntechfund.de/?ref=rubycentral.org) (STF), and Ruby Central memberships from 29 other companies, including Partner-level member [Sidekiq](https://sidekiq.org/?ref=rubycentral.org). In total, we were supported by 188 members. Thanks to all of our members for making everything that we do possible. <3
## **Ruby Central News**
### **RubyConf 2024**
Get ready for RubyConf in Chicago from November 13-15—only 4 weeks away! Join your #RubyFriends and dive into the Ruby community, whether you're new or experienced. We’ve also been spotting quite a few of our Ruby Friends out in the wild wearing the official conference merch located on our [Ruby Central Store](https://store.rubycentral.org/?ref=rubycentral.org)!!! Shoutout to Valenzia from [Flagrant](https://www.beflagrant.com/?ref=rubycentral.org) for the amazing designs!
### [**Join us in Chicago!**](https://ti.to/rubyconf/2024?ref=rubycentral.org)
Don't forget: our room block deadline is **October 18th at midnight CST**! Secure your stay at the Hilton Chicago for the ultimate networking experience. [Book your room now!](https://book.passkey.com/event/50806364/owner/2874/home?ref=rubycentral.org)
### **Hack Day on Day 2**
Hack Day is a highlight of RubyConf, offering a chance to collaborate with open source maintainers like Ruby Core members, and contribute to exciting open source projects like Glimmer DSL for LibUI, Clearance, RubyGems, Sublayer, JRuby, Hanami, cancancan, Sidekiq, Camping, Nokogiri, Ruby LSP, Tapioca, and Ruby Cloud Native Buildpacks!
Stay tuned for some special “Ruby Celebrity” pairing opportunities too—details coming soon!
Also, if you have ideas on open source projects that you’d like to bring to the event, contact [hackday@rubycentral.org](mailto:hackday@rubycentral.org) and we can continue the conversations. The more the merrier!!
### **Wishing to get involved?**
Why not sponsor the event? There is still a little time left (**mid-October**) to get your name alongside the other sponsors for the event on our printed signage! **Secure your sponsorship now** to reach all our attendees, showcase your thought leadership, and cultivate invaluable industry relationships by emailing our wonderful sponsorships manager, [Tom](mailto:tom@rubycentral.org).
We’re also looking for sponsors for **RailsConf 2025**. We’d love to have you be with us in our closing celebration of RailsConf and make this event truly magical and memorable for the community that started it all!
We want to give a huge shout-out to our generous sponsors! Alphabetical order. :)
Beyond Finance, Cedarcode, Chime, Cisco/Meraki, Couchbase, Flagrant, GitHub, GitLab, HoneyBadger, PayPal, Reinteractive, Scout APM, Sidekiq, Shopify, Wellsheet, Workforce
## RubyGems News
In September, we released RubyGems [3.5.19](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3519--2024-09-18) and [3.5.20](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3520--2024-09-24) along with Bundler [2.5.19](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2519-september-18-2024) and [2.5.20](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2520-september-24-2024). These releases bring a series of enhancements and bug fixes designed to improve the overall developer experience with RubyGems. Notable improvements include the [removal of temporary .lock files](https://github.com/rubygems/rubygems/pull/7939?ref=rubycentral.org) unintentionally left behind by the gem installer, the rejection of [unknown platforms when running bundle lock --add-platform](https://github.com/rubygems/rubygems/pull/7967?ref=rubycentral.org), and a performance fix that addresses the excessive [slowness of the gem install command](https://github.com/rubygems/rubygems/pull/8006?ref=rubycentral.org).
Some other important accomplishments from the team this month include:
[**Significant Progress on Lockfile Checksums Enablement**](https://github.com/rubygems/rubygems/pull/8029?ref=rubycentral.org)
- [Previously](https://github.com/rubygems/rubygems/pull/7896?ref=rubycentral.org), we implemented checksums in the lockfile to ensure that installed gems have not been tampered with, aligning with standard security measures in other package managers. We are now addressing platform-related issues to enforce strict gem locking and prevent false security assurances.
- The checksums feature is now available in our master branch and is being prepared for inclusion in Bundler 2.6’s December release, allowing users to opt in. It will become the default in Bundler 3, supported by continuous integration testing to guarantee reliability.
[**Fixing Strict Permissions Check in Bundler for GitHub Actions**](https://github.com/rubygems/rubygems/pull/7985?ref=rubycentral.org)
- We resolved permission issues reported in GitHub Actions workflows where Bundler was refusing to delete directories before reinstalling gems, causing workflows to abort. This problem affected both GitHub Actions runner's repositories and the official `ruby/setup-ruby` action, forcing users to manually adjust permissions as a workaround.
- Through investigative efforts, we identified that the Bundler 2.5.12 release began treating default gems as regular gems and explicitly installing them. Since default gems include empty directories in Ruby distributions, Bundler was failing when attempting to remove these empty directories before installation.
- We fixed the issue by modifying Bundler to skip removing empty directories, ensuring smooth gem installations without requiring manual permission adjustments.
[**Enhancing Support for Caching Git Gems in**](https://github.com/rubygems/rubygems/pull/8013?ref=rubycentral.org) [**Cache Specific Project (vendor/cache) Settles**](https://github.com/rubygems/rubygems/pull/8047?ref=rubycentral.org)
- We have improved Bundler's ability to cache git gems in the `vendor/cache` by maintaining a bare clone of the repository within the cache. This enhancement allows users to bundle all dependencies with their applications, facilitating installations in environments without internet access.
- Additionally, we implemented patches to reduce the size of bare clones by removing `.sample` files and ensuring that empty directories are preserved when cloning repositories on different machines. These improvements prevent cache misidentification and enhance the reliability of git gem caching.
[**Improvements in Gem Activation Conflict Prevention**](https://github.com/rubygems/rubygems/pull/7960?ref=rubycentral.org)
- As a dependency manager, Bundler needs to be very careful about having dependencies itself, because those dependencies could interfere with the dependencies of end users. We addressed dependency conflicts by carefully managing Bundler and RubyGem's own dependencies, particularly with the gemification of Ruby's standard library, such as `securerandom` becoming a default gem.
- To prevent conflicts, we vendored the `securerandom` gem under our own namespace in both RubyGems and Bundler, ensuring our dependencies do not interfere with user dependencies and maintaining a stable environment for end users.
- In the particular case of `bundler/inline,` we applied a workaround: rescue the conflict when it happens and retry with an explicit dependency on the user version, so that conflict does not happen the second time.
- We also explored more general solutions to provide robust fixes for common entry points prone to dependency conflicts, such as re-executing the original process after gem installation during `bundler/inline` or installing gems in a subprocess when `auto_install` is set.
[**Improving Suggestions for**](https://github.com/rubygems/rubygems/pull/8083?ref=rubycentral.org) [**and Speeding Up**](https://github.com/rubygems/rubygems/pull/8084?ref=rubycentral.org)[**gem install **](https://github.com/rubygems/rubygems/pull/8083?ref=rubycentral.org)
- Previously, attempting to install a nonexistent gem (e.g., railss) resulted in Bundler suggesting multiple gem names that were over 20 characters long, while the correct gem (rails) was never suggested.
- We recognized that waiting 10 seconds for suggestions when installing a nonexistent gem was more annoying than helpful. By determining that computing the Levenshtein distance was the main performance penalty, we refactored Bundler to avoid computing this distance in as many cases as possible. This significantly speeds up the gem install command for nonexistent gems, enhancing the overall user experience.
**Introduced the New Design for** [**RubyGems.org**](http://rubygems.org/?ref=rubycentral.org)
- We are slowly rolling out a full refresh of the site that aims to meet our goals of modernizing the design and improving the usability of [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) for all of our users.
- The new design aims to support the full range of devices/browser widths and (much to my relief) includes a dark mode theme!
- [Learn more here](https://blog.rubygems.org/2024/10/15/our-new-design.html?ref=rubycentral.org)

**RubyGems.org "About" page, top navigation menu, featuring new design.*

**RubyGems.org "About" page, bottom navigation menu, featuring new design...in dark mode!*
In September, RubyGems gained [168 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2024-9-01%7D...master@%7B2024-9-31%7D?ref=rubycentral.org) contributed by 17 authors. They were 1,852 additions and 802 deletions across 164 files.
## [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) News
The updates made this month to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform. Sponsored hosting for [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) in September was provided by [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Fastly](https://www.fastly.com/?ref=rubycentral.org), and [DataDog](https://www.datadoghq.com/?ref=rubycentral.org).
The following are highlights of what the team worked on this month:
[**Added Length Validations for User-Supplied String Attributes**](https://github.com/rubygems/rubygems.org/pull/5056?ref=rubycentral.org)
- We added length validations for user-supplied string attributes to prevent users from adding a large amount of unexpected data to the pages we render.
- This improvement helps maintain application performance and security by ensuring that input data remains within acceptable limits.
[**Disabled Honeybadger & Datadog in local environments**](https://github.com/rubygems/rubygems.org/pull/5035?ref=rubycentral.org)
- We disabled Honeybadger and Datadog from being initialized in local environments to prevent errors and unnecessary resource usage.
- These monitoring tools are configured and authenticated for production environments only, while local development setups do not have the necessary configurations. This fix ensures that Honeybadger and Datadog are active exclusively in production, maintaining a smooth and error-free experience for developers working in local environments.
In September, [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) gained [92 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2024-9-01%7D...master@%7B2024-9-31%7D?ref=rubycentral.org) contributed by 8 authors. There were 1,643 additions and 1,644 deletions across 157 files.
## Ruby Ecosystem News
Here we outline additional exciting updates made to other projects in the Ruby Ecosystem.
### Ruby Toolbox
These are highlights from the work done in [Ruby Toolbox](https://www.ruby-toolbox.com/?ref=rubycentral.org):
- To keep the Ruby Toolbox application orderly and running smoothly, we updated numerous dependencies on both the Ruby Toolbox Rails main application and the catalog repository, including upgrading to the latest `Ruby 3.3.5` and `Rails 7.2.1`.
- We reviewed and merged the most recent contributions to the catalog, ensuring that submissions are up-to-date and meet quality standards.
### Organization Accounts Update
We are making steady progress and are currently on track to have the new feature ready for users by the end of November. [For details, check out this post.](https://github.com/rubycentral/alpha-omega/blob/update-2024-09/alpha/engagements/2024/RubyCentral/update-2024-09.md?ref=rubycentral.org) Development work on this project was made possible by funding from [Alpha-Omega](https://rubycentral.org/news/ruby-central-receives-alpha-omega-grant/).
## Total Spent
In September we spent $105,446.70 on development work.
## Thank you
Thank you to all the contributors of RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### Contributors to RubyGems:
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@byroot](https://github.com/byroot?ref=rubycentral.org) Jean Boussier
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@marcoroth](https://github.com/marcoroth?ref=rubycentral.org) Marco Roth
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@composerinteralia](https://github.com/composerinteralia?ref=rubycentral.org) Daniel Colson
- [@djberube](https://github.com/djberube?ref=rubycentral.org) David J Berube
- [@jeromedalbert](https://github.com/jeromedalbert?ref=rubycentral.org) Jerome Dalbert
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
- [@voxik](https://github.com/voxik?ref=rubycentral.org) Vít Ondruch
- [@earlopain](https://github.com/earlopain?ref=rubycentral.org) Earlopain
- [@y-yagi](https://github.com/y-yagi?ref=rubycentral.org) Yuuji Yaginuma
- [@jonathanhefner](https://github.com/jonathanhefner?ref=rubycentral.org) Jonathan Hefner
- [@tnir](https://github.com/tnir?ref=rubycentral.org) Takuya N
### Contributors to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org):
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@JuanVqz](https://github.com/JuanVqz?ref=rubycentral.org) Juan Vásquez
*If we missed you, please let us know so we can include you in our shout out!*
### September 2024 Newsletter
URL: https://rubycentral.org/news/september-2024-newsletter/
Last updated: 2024-10-17T19:34:51.000Z
Hello! Welcome to the September newsletter. Read on for announcements from Ruby Central and a report of the OSS work we’ve done from the previous month.
In August, Ruby Central's open source work was supported by Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org), [AWS](https://aws.amazon.com/?ref=rubycentral.org), the [Sovereign Tech Fund](https://www.sovereigntechfund.de/?ref=rubycentral.org) (STF), and Ruby Central memberships from 29 other companies, including Partner-level member [Sidekiq](https://sidekiq.org/?ref=rubycentral.org). In total, we were supported by 185 members. Thanks to all of our members for making everything that we do possible. <3
# Ruby Central News
## RubyConf 2024
RubyConf 24 is just around the corner! November 13-15 at the Chicago Hilton downtown. Join your #RubyFriends and fellow Ruby enthusiasts for keynotes, breakout sessions, workshops, a hack day, a job fair, and more! See the full [Program](https://rubyconf.org/schedule/?ref=rubycentral.org).
### [**Get your ticket!**](https://ti.to/rubyconf/2024?ref=rubycentral.org)
Then, [**get your room in the conference hotel**](https://book.passkey.com/event/50806364/owner/2874/home?ref=rubycentral.org) for the full conference experience. We have a fantastic discounted rate of $219++/night for conference attendees at the Hilton Chicago. It’s such a cool space with a modern twist to its original 1920s architecture incredibly close to fantastic sightseeing spots. The room block closes October 18.
### Want to sponsor???
There is still time to get your name alongside the other sponsors for the event! **Secure your sponsorship now** to reach all our attendees, showcase your thought leadership, and cultivate invaluable industry relationships by [emailing our wonderful sponsorships manager, Tom](http://tom@rubycentral.org/).
**Contact Tom by mid-October** to ensure we can add you to the print signage at the event!
Thank you to our generous sponsors! Alphabetical order. :)
Beyond Finance
Cedarcode
Chime
Cisco
Couchbase
Flagrant
GitHub
GitLab
HoneyBadger
PayPal
Reinteractive
Scout APM
Sidekiq
Shopify
Wellsheet
Workforce
## RubyGems News
In August, we released RubyGems [3.5.17](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3517--2024-08-01) and [3.5.18](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3518--2024-08-26) along with Bundler [2.5.17](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2517-august-1-2024) and [2.5.18](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2518-august-26-2024). These releases bring a series of enhancements and bug fixes designed to improve the overall developer experience with RubyGems. Notable improvements include fixing an issue where [gem uninstall : would fail on shadowed default gems](https://github.com/rubygems/rubygems/pull/7949?ref=rubycentral.org), [enabling lockfile checksums in future Bundler 3](https://github.com/rubygems/rubygems/pull/7805?ref=rubycentral.org) even when there's no previous lockfile, and fixing an issue where `bundle update ` would [fail to upgrade when versions are present in two different sources](https://github.com/rubygems/rubygems/pull/7915?ref=rubycentral.org).
Some other important accomplishments from the team this month include:
[**Fixing an Edge Case Where Bundler Was Removing Platforms Due to Bad Indentation**](https://github.com/rubygems/rubygems/pull/7916?ref=rubycentral.org)
- We resolved an issue where Bundler was removing platforms and associated gems from `Gemfile.lock` because of bad indentation.
- Now, Bundler auto-fixes indentation by properly stripping whitespace, ensuring badly indented platforms are recognized and retained, which prevents broken dependencies and confusion.
[**Fixing a Source Dependency Confusion in bundle update **](https://github.com/rubygems/rubygems/pull/7915?ref=rubycentral.org)
- We fixed an issue where `bundle update ` would confuse the source of `` if an old version existed on a different gem server than specified in the lockfile, allowing smoother gem updates.
- The bug was due to the additional unlocked resolution not using the correct source requirements during `bundle update `. The fix ensures it now uses the same source requirements as the main resolution.
[**Improving Developer Experience When Setting Up RubyGems With an Unsupported Ruby**](https://github.com/rubygems/rubygems/pull/7942?ref=rubycentral.org)
- We added a clearer error message when an unsupported Ruby version is detected and the setup process is aborted, improving the process by preventing new developers from being discouraged by obscure errors.
- This change helps people starting to develop RubyGems by immediately informing them if their Ruby version isn't supported.
[**Fixing gem uninstall :** **Failing When Target Gem is Also a Default Gem**](https://github.com/rubygems/rubygems/pull/7949?ref=rubycentral.org)
- We resolved an issue where `gem uninstall :` would fail with a confusing error if the target gem was also a default gem, providing a smoother CLI experience.
- The fix skips the default copy of the gem during uninstallation, avoiding the "double uninstall" problem.
[**Fixing Issues With the\--prefer-local Flag in bundle install**](https://github.com/rubygems/rubygems/pull/7951?ref=rubycentral.org)
- We resolved problems where the `-prefer-local` flag wasn't working effectively; it didn't fallback to remote gems when local ones didn't satisfy requirements and didn't prefer local gems for sub-dependencies.
- We implemented a solution similar to how we handle prereleases: for each gem, first prefer local versions; if conflicts arise, allow remote versions for those specific gems.
- This was inspired by [@gouravkhunger](https://github.com/gouravkhunger?ref=rubycentral.org), who uses `-prefer-local` to help package Ruby for his Jekyllex project.
[**Helping Appraisals Maintainers Run Tests With Latest Bundler**](https://github.com/rubygems/rubygems/pull/7950?ref=rubycentral.org)
- Ensured that Appraisals, a library for testing against multiple Gemfiles, [works with the latest Bundler](https://github.com/thoughtbot/appraisal/pull/229?ref=rubycentral.org) by proposing updates and fixing a small behavior changes in Bundler 2.4 that affected them.
- Appraisals is tightly coupled to Bundler internals, so it's important it remains compatible to detect potential issues in Bundler itself.
In August, RubyGems gained [77 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2024-8-01%7D...master@%7B2024-8-31%7D?ref=rubycentral.org) contributed by 8 authors. They were 1,163 additions and 151 deletions across 90 files.
## [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) News
The updates made this month to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform. Sponsored hosting for [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) in August was provided by [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Fastly](https://www.fastly.com/?ref=rubycentral.org), and [DataDog](https://www.datadoghq.com/?ref=rubycentral.org).
The following are highlights of what the team worked on this month:
[**Prevented AWS Secrets From Being Printed in Logs or Error Messages**](https://github.com/rubygems/rubygems.org/pull/4968?ref=rubycentral.org)
- We modified the logging and error-handling mechanisms to ensure AWS secrets are sanitized and never outputted.
- Although this issue wasn't occurring in CI, it's crucial to safeguard against future changes that might inadvertently expose sensitive information.
[**Renamed #search\_field** **to Resolve a Naming Conflict With Rails Internals**](https://github.com/rubygems/rubygems.org/pull/4957?ref=rubycentral.org)
- The conflict was causing the Rails info page (`/rails/info/routes`) to raise an error, hindering access to important debugging routes.
- To resolve this we changed the method name to eliminate the conflict, restoring normal functionality to the Rails info page.
[**Fixed a Minor Inefficiency in RubyGems Controller**](https://github.com/rubygems/rubygems.org/pull/4953?ref=rubycentral.org)
- The `GemNameReservation` query was being executed four times per request, leading to potential performance issues.
- We refactored the controller logic to perform the `GemNameReservation` query only once per request, improving efficiency.
[**Fixed Broken Recovery Code Acceptance Tests**](https://github.com/rubygems/rubygems.org/pull/4950?ref=rubycentral.org)
- Tests were failing due to two issues, blocking the CI pipeline. We addressed each:
- *Invalid jQuery Selector Length Check*: We corrected the jQuery selector `$("#recovery-code-list").length` to properly detect the element.
- *Confirmation Dialog Not Triggering on Path Change*: We adjusted the test so that changing the current path triggers the confirm dialog as expected.
[**Optimized API Key Expiration Process by Skipping Already Expired Keys**](https://github.com/rubygems/rubygems.org/pull/4975?ref=rubycentral.org)
- The existing expiration process was inefficient because it looped through all API keys, including those that were already expired.
- To fix this, we modified the API key expiration routine to process only unexpired API keys, thereby avoiding unnecessary iterations over keys that have already expired.
In August, [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) gained [57 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2024-8-01%7D...master@%7B2024-8-31%7D?ref=rubycentral.org) contributed by 6 authors. There were 134 additions and 137 deletions across 15 files.
## Total spent
In August we spent $82,485.16 on development work.
## Thank you
Thank you to all the contributors of RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### Contributors to RubyGems:
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@marcoroth](https://github.com/marcoroth?ref=rubycentral.org) Marco Roth
- [@gouravkhunger](https://github.com/gouravkhunger?ref=rubycentral.org) Gourav Khunger
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@KJTsanaktsidis](https://github.com/KJTsanaktsidis?ref=rubycentral.org) KJ Tsanaktsidis
- [@mattbrictson](https://github.com/mattbrictson?ref=rubycentral.org) Matt Brictson
- [@djberube](https://github.com/djberube?ref=rubycentral.org) David J Berube
- [@jeromedalbert](https://github.com/jeromedalbert?ref=rubycentral.org) Jerome Dalbert
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@byroot](https://github.com/byroot?ref=rubycentral.org) Jean Boussier
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@voxik](https://github.com/voxik?ref=rubycentral.org) Vít Ondruch
- [@sunpoet](https://github.com/sunpoet?ref=rubycentral.org) Po-Chuan Hsieh
- [@eregon](https://github.com/eregon?ref=rubycentral.org) Benoit Daloze
### Contributors to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org):
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@okuramasafumi](https://github.com/okuramasafumi?ref=rubycentral.org) Okura Masafumi
*If we missed you, please let us know so we can include you in our shout out!*
### Ruby Central Welcomes Marty Haught as Interim Lead for RubyGems and Bundler
URL: https://rubycentral.org/news/ruby-central-welcomes-marty-haught-as-interim-lead-for-rubygems-and-bundler/
Last updated: 2024-09-05T16:30:05.000Z
Ruby Central is excited to announce Marty Haught will be joining us on an interim basis to lead our open source work, including the RubyGems and Bundler projects, effective today. We are glad to welcome Marty back - he was previously the co-leader of Ruby Central and is an alumnus of the open source infrastructure company Hashicorp as well as rubygems.org infrastructure sponsor Fastly.
Marty has been part of the Ruby community since 2006, a leader of Ruby Central since 2012, and member of our Open Source committee since its creation last year. His knack for collaboration has helped teams do their best in a friendly and supportive space.
We want to thank André Arko for his many years supporting RubyGems and Bundler projects. Under his leadership, he established a non-profit to support Ruby package management for many years and shepherded bringing Ruby Together over to Ruby Central. In less than two years, they’ve expanded the program from a $220k OSS budget to over $900k for a 348% increase in the program budget! We look forward to continuing to work with André alongside the entire OSS team.
Ruby Central continues to focus on the support and longevity of the Ruby package management infrastructure. This change is designed to bring a fresh perspective to our open source operations and to help us redesign our organization to achieve our ambitious vision. Our goal is to support everyone in the Ruby community well on into the future.
Ruby Central relies on contributions from organizations and individuals to support the software projects, so please consider attending or sponsoring [RubyConf in Chicago](http://rubyconf.org/?ref=rubycentral.org), as well as sponsoring Ruby Central through [individual donations](https://rubycentral.org/#/portal/signin) or [corporate sponsorships](mailto:adarsh@rubycentral.org). For other opportunities to volunteer, [visit our website](https://rubycentral.org/volunteer/).
### August 2024 Newsletter
URL: https://rubycentral.org/news/august-2024-newsletter/
Last updated: 2024-09-26T21:05:54.000Z
Hello! Welcome to the August newsletter. Read on for announcements from Ruby Central and a report of the OSS work we’ve done from the previous month.
In July, Ruby Central's open source work was supported by Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org), [AWS](https://aws.amazon.com/?ref=rubycentral.org), the [Sovereign Tech Fund](https://www.sovereigntechfund.de/?ref=rubycentral.org) (STF), and Ruby Central memberships from 29 other companies, including Partner-level member [Contributed Systems](https://contribsys.com/?ref=rubycentral.org), the company behind Mike Perham’s [Sidekiq](https://sidekiq.org/?ref=rubycentral.org). In total, we were supported by 185 members. Thanks to all of our members for making everything that we do possible. <3
# **Ruby Central News**
## RubyConf 2024 announcements
### Applications to the Scholars & Guides Program are now open for RubyConf 2024!
This is an incredible mentorship opportunity for those new to the community and looking to make professional connections AND for those looking to offer experience and help support our growing [Ruby](https://ruby.social/tags/Ruby?ref=rubycentral.org) community. Apply Now! **The** **application deadline is Monday, August 26, 2024.**
### Tickets for RubyConf 2024 are [on sale now!](https://ti.to/rubyconf/2024?ref=rubycentral.org)
Already booked your ticket? Go ahead and [**book your hotel room**](https://book.passkey.com/event/50806364/owner/2874/home?ref=rubycentral.org) at conference rates too and get a glimpse of our amazing host city on our [website](https://rubyconf.org/?ref=rubycentral.org).
### We’re looking for sponsors for this year’s conference
Want to promote your company at RubyConf in 2024? **Secure your sponsorship now** to reach all our attendees, showcase your thought leadership, and cultivate invaluable industry relationships by [emailing our wonderful sponsorships manager, Tom](http://tom@rubycentral.org/).
## **Check out our Ruby Central Membership Program!**
Ruby Central is forming sustaining partnerships with major companies in our community. [Click here to learn about all the exciting new ways we’ll be engaging with our members and how you can get involved](https://webforms.pipedrive.com/f/6aW4k05dMuwVRUNS7cR5nhHZyJFbhc7hrhQnQ21odD5tYLNhzwTSa9Xu1bguTOzePV?ref=rubycentral.org).
## **Upcoming Conferences:**
- Ruby Central
- RubyConf 2024 will be in Chicago on Nov 13-15th at the Hilton Downtown Chicago.
- RailsConf 2025 [will be our final RailsConf.](https://rubycentral.org/news/anewearforrubycentralevents/) We’ve made a limited number of supporter tickets available [here](https://ti.to/railsconf/2025?ref=rubycentral.org) for purchase — consider contributing to help make this special event the best one yet!
- Community Conferences
- The upcoming lineup of Ruby conferences include: [Osaka RubyKaigi](https://regional.rubykaigi.org/osaka04/?ref=rubycentral.org) (August 24), [Rails Camp USA](https://west.railscamp.us/2024?ref=rubycentral.org) (August 27–30), [Fukuoka RubyistKaigi](https://regional.rubykaigi.org/fukuoka04/?ref=rubycentral.org) (September 7, 2024), [EuRuKo](https://2024.euruko.org/?ref=rubycentral.org) (September 11–13), [Friendly.rb](https://friendlyrb.com/?ref=rubycentral.org) (September 18–19) and [Rails World](https://rubyonrails.org/world/2024?ref=rubycentral.org) (September 26–27).
- Updated information is always available at [rubyconferences.org](https://rubyconferences.org/?ref=rubycentral.org), which includes [a super-handy iCal feed](https://rubyconferences.org/calendar.ics?ref=rubycentral.org).
## **Get Involved:**
- If you'd like to get involved and help make our community and events even better, we'd love to have you join us! Check out our [volunteer page](https://rubycentral.org/volunteer/), and/or feel free to [shoot an email to our executive director, Adarsh](http://adarsh@rubycentral.org/), to find the best way to get plugged in.
- Remember, you can receive exclusive benefits like conference discounts and more by signing up for a Ruby Central [membership](https://rubycentral.org/#/portal/signup). *Check to see if your employer matches donations to Ruby Central, Inc. through* [*Benevity*](https://causes.benevity.org/causes/840-300040446?ref=rubycentral.org) *and double your support!*
## RubyGems News
In July, we released RubyGems [3.5.15](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3515--2024-07-09), [3.5.16](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3516--2024-07-18) and Bundler [2.5.15](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2515-july-9-2024), [2.5.16](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2516-july-18-2024). These releases brings a series of enhancements and bug fixes designed to improve the overall developer experience with RubyGems. Notable improvements included a performance enhancement by using [caller\_locations instead of splitting caller](https://github.com/rubygems/rubygems/pull/7708?ref=rubycentral.org), as collecting all call locations as strings and then extracting and splitting just one was inefficient. Additionally, we resolved issues with loading [nested gemrc configuration keys](https://github.com/rubygems/rubygems/pull/7851?ref=rubycentral.org) when specified as symbols and implemented a file lock to [safeguard the creation of binstubs](https://github.com/rubygems/rubygems/pull/7806?ref=rubycentral.org).
Some other important accomplishments from the team this month include:
**Publishing a** [**basic conformance test for all gem servers**](https://github.com/rubygems/gem%5Fserver%5Fconformance?ref=rubycentral.org)
- This update allows any gem server to be easily tested for compliance with RubyGems standards, significantly impacting both users and developers.
- The conformance test can be accessed and utilized through our [GitHub repository](https://github.com/rubygems/gem%5Fserver%5Fconformance?ref=rubycentral.org).
[**Updating our OpenSearch cluster from 2.11 to 2.13**](https://docs.aws.amazon.com/opensearch-service/latest/developerguide/release-notes.html?ref=rubycentral.org)
- We recently updated our OpenSearch cluster from version 2.11 to 2.13 as part of our regular maintenance routine.
- This upgrade was efficiently executed with a one-click process in our AWS console. The update ensures that our systems continue to run smoothly and benefit from the latest features and improvements. For more details on the update and its benefits, refer to the [AWS OpenSearch release notes](https://docs.aws.amazon.com/opensearch-service/latest/developerguide/release-notes.html?ref=rubycentral.org).
**Confirmed protection against recent OpenSSH Bug**
- Early this month, [a vulnerability was discovered](https://cyberinsider.com/14-million-openssh-servers-potentially-vulnerable-to-regresshion-bug/?ref=rubycentral.org) in certain versions of OpenSSH that could trigger remote code execution.
- The RubyGems security team promptly responded by implementing tests to ensure our software was not exposed to this threat, guaranteeing that our users and developers could continue their work without interruption.
In July, RubyGems gained [171 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2024-7-01%7D...master@%7B2024-7-31%7D?ref=rubycentral.org) contributed by 12 authors. They were 2,827 additions and 1,769 deletions across 113 files.
## [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) News
The updates made this month to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform. Sponsored hosting for [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) in July was provided by [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Fastly](https://www.fastly.com/?ref=rubycentral.org), and [DataDog](https://www.datadoghq.com/?ref=rubycentral.org). The following are highlights of what the team worked on this month:
**Discontinued auto sign-in** [**after email confirmation**](https://github.com/rubygems/rubygems.org/pull/4810?ref=rubycentral.org)[**and password reset**](https://github.com/rubygems/rubygems.org/pull/4811?ref=rubycentral.org)
- The primary goal for this change is to simplify login flows, reducing the likelihood of mistakes or bypasses.
- This change aligns with best practices recommended by [OWASP](https://cheatsheetseries.owasp.org/cheatsheets/Forgot%5FPassword%5FCheat%5FSheet.html?ref=rubycentral.org#user-resets-password) and will enhance security and streamline the login process for both users and developers.
**Presented on** [**RubyGems.org**](http://rubygems.org/?ref=rubycentral.org) **at RedDot Ruby Conference 2024**
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) gave a presentation on ["Scaling RubyGems.org to 1 Trillion Downloads"](https://drive.google.com/file/d/1szfL-qNAa%5FisxsnPqR8d7rDmxwZD1MzJ/view?ref=rubycentral.org).
- The talk was a deep dive into Ruby's package ecosystem, exploring how [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) is maintained and the ongoing efforts of the team ensuring [rubygems.org](http://rubygems.org/?ref=rubycentral.org) remains a healthy and sustainable platform long into the future.
- Colby discussed the latest work and improvements made to the platform and outlined plans for future enhancements.
In July, [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) gained [128 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2024-7-01%7D...master@%7B2024-7-31%7D?ref=rubycentral.org) contributed by 8 authors. There were 2,416 additions and 973 deletions across 167 files.
## Total spent
In July we spent $77,574.26 on development work.
## Thank you
Thank you to all the contributors of RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### Contributors to RubyGems:
- [@jeromedalbert](https://github.com/jeromedalbert?ref=rubycentral.org) Jerome Dalbert
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@ntkme](https://github.com/ntkme?ref=rubycentral.org) Natsuki Times
- [@moofkit](https://github.com/moofkit?ref=rubycentral.org) Dmitriy Ivliev
- [@leetking](https://github.com/leetking?ref=rubycentral.org) Alpha 0x00
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@jasonkarns](https://github.com/jasonkarns?ref=rubycentral.org) Jason Karns
- [@coryspitzer](https://github.com/CorySpitzer?ref=rubycentral.org) Cory Spitzer
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
### Contributors to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org):
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
- [@earlopain](https://github.com/Earlopain?ref=rubycentral.org) Earlopain
- [@robbyrussell](https://github.com/robbyrussell?ref=rubycentral.org) Robby Russell
- [@jenshenny](https://github.com/jenshenny?ref=rubycentral.org) Jenny Shen
*If we missed you, please let us know so we can include you in our shout out!*
### July 2024 Newsletter
URL: https://rubycentral.org/news/july-2024-newsletter/
Last updated: 2024-08-27T20:24:06.000Z
Hello! Welcome to the July newsletter. Read on for announcements from Ruby Central and a report of the OSS work we’ve done from the previous month.
In June, Ruby Central's open source work was supported by Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org), [AWS](https://aws.amazon.com/?ref=rubycentral.org), the [Sovereign Tech Fund](https://www.sovereigntechfund.de/?ref=rubycentral.org) (STF), and Ruby Central memberships from 29 other companies, including Partner-level member [Contributed Systems](https://contribsys.com/?ref=rubycentral.org), the company behind Mike Perham’s [Sidekiq](https://sidekiq.org/?ref=rubycentral.org). In total, we were supported by 189 members. Thanks to all of our members for making everything that we do possible. <3
# **Ruby Central News**
## RubyConf 2024 announcements
### Get your tickets before Early Bird pricing ends on July 31!
Time to join RubyConf 2024 at the best price is running out! [Grab your ticket](https://ti.to/rubyconf/2024?ref=rubycentral.org).
Already booked your ticket? Go ahead and [**book your hotel room**](https://book.passkey.com/event/50806364/owner/2874/home?ref=rubycentral.org) at conference rates too and get a glimpse of our amazing host city on our [website](https://rubyconf.org/?ref=rubycentral.org).
### Welcome two RubyConf 2024 keynote speakers!

[**Nadia Odunayo**](https://nadiaodunayo.com/?ref=rubycentral.org) is the Founder and CEO of [The StoryGraph](https://thestorygraph.com/?ref=rubycentral.org), an app that helps you track your reading and choose your next book based on your mood and favorite topics. She is joining us at RubyConf fresh off her inspiring keynote at RailsConf 2024.

[**Brandon Weaver**](https://dev.to/baweaver?ref=rubycentral.org) is a Senior Staff Software Engineer at One Medical and an artist-turned-programmer. He teaches Ruby with a series of colorful cartoon lemurs going on storybook adventures, a unique approach you may recognize from his entertaining conference talks.
### RubyConf 2024 in your ear!
Check out RubyConf 2024 co-chairs Kinsey Durham Grace and Jim Remsik on recent episodes of [Remote Ruby](https://www.remoteruby.com/2260490/15333111-rubyconf-with-kinsey-durham-grace-and-jim-remsik?ref=rubycentral.org) and [Code and the Coding Coders who Code it](https://podcast.drbragg.dev/episodes/episode-37-kinsey-durham-grace/?ref=rubycentral.org), talking all things RubyConf, their own experiences in the Ruby community, mentorship opportunities and more!
## **Check out our revamped Ruby Central Membership Program!**
Ruby Central is forming sustaining partnerships with major companies in our community. [Click here to learn about all the exciting new ways we’ll be engaging with our members and how you can get involved](https://webforms.pipedrive.com/f/6aW4k05dMuwVRUNS7cR5nhHZyJFbhc7hrhQnQ21odD5tYLNhzwTSa9Xu1bguTOzePV?ref=rubycentral.org).
## **Upcoming Conferences:**
- Ruby Central
- RubyConf 2024 will be in Chicago on Nov 13-15th at the Hilton Downtown Chicago.
- RailsConf 2025 [will be our final RailsConf.](https://rubycentral.org/news/anewearforrubycentralevents/)
- We’d love our community to help us choose the location for this final event. If you have not filled out the [Google Form](https://docs.google.com/forms/d/e/1FAIpQLSeQIVh1Uje6LBHFbkcSgVMliMPUVKt-kVloHAQ8OuVkvYoopw/viewform?usp=sharing&ref=rubycentral.org) to vote please do!
- We’ve made a limited number of supporter tickets available [here](https://ti.to/railsconf/2025?ref=rubycentral.org) for purchase — consider contributing to help make this special event the best one yet!
- Community Conferences
- This summer’s Ruby conference lineup includes: [RubyConf Africa](https://rubyconf.africa/?ref=rubycentral.org) (July 26–27), [Madison+Ruby](https://www.madisonruby.com/?ref=rubycentral.org) (August 1–2), and [Rails Camp USA](https://west.railscamp.us/2024?ref=rubycentral.org) (August 27–30).
- Updated information is always available at [rubyconferences.org](https://rubyconferences.org/?ref=rubycentral.org), which includes [a super-handy iCal feed](https://rubyconferences.org/calendar.ics?ref=rubycentral.org).
## **Get Involved:**
- If you'd like to get involved and help make our community and events even better, we'd love to have you join us! Check out our [volunteer page](https://rubycentral.org/volunteer/), and/or feel free to [shoot an email to our executive director, Adarsh](http://adarsh@rubycentral.org/), to find the best way to get plugged in.
- Want to promote your company at RubyConf in 2024? **Secure your sponsorship now** to reach all our attendees, showcase your thought leadership, and cultivate invaluable industry relationships by [emailing our wonderful sponsorships manager, Tom](http://tom@rubycentral.org/).
- Remember, you can receive exclusive benefits like conference discounts and more by signing up for a Ruby Central [membership](https://rubycentral.org/#/portal/signup). *Check to see if your employer matches donations to Ruby Central, Inc. through* [*Benevity*](https://causes.benevity.org/causes/840-300040446?ref=rubycentral.org) *and double your support!*
## RubyGems News
In June, we released RubyGems [3.5.12](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3512--2024-06-13), [3.5.13](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3513--2024-06-14), and [3.5.14](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3514--2024-06-21) , and Bundler [2.5.12](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2512-june-13-2024), [2.5.13](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2513-june-14-2024), and [2.5.14](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2514-june-21-2024). These releases bring a series of enhancements and bug fixes designed to improve the overall developer experience with RubyGems. Notable improvements include: an improvement to [auto-switch to the locked Bundler version](https://github.com/rubygems/rubygems/pull/7719?ref=rubycentral.org) even when using `binstubs`, a fix for duplicated config keys generated when the `fallback_timeout` URI option is used, and a fix for slow and incorrect resolution when adding `sorbet` to a Gemfile if the lockfile only includes "RUBY" in the platforms section.
Some other important accomplishments from the team this month include:
[**A better out of the box experience when creating new gems with bundle gem**](https://github.com/rubygems/rubygems/pull/7707?ref=rubycentral.org)
- A user alerted us to a potential source of friction in the gem creation process: users needing to edit all the TODOs in the gemspec prior to running Bundler and dummy generated tests.
- The issue was, values like e.g the gem’s homepage, source code and changelog URIs, while important, are not what users have in mind (yet) when they create a new gem. They just want to start working on the new gem. In many cases inputting this information can be delayed until gem build/push time.
- Due to internal RubyGems methods we’ve added to validate gems that have a few different usages — like [RubyGems.org](http://rubygems.org/?ref=rubycentral.org), Bundler and RubyGems — it would have been risky to change validations just for Bundler (and as a result relax validations everywhere). The alternative, adding a new parameter to `Gem::Specification#validate`, felt like complicating things too much. So we went with adding a new `Gem::Specification#validate_for_resolution` method just for Bundler that skips validations that are non essential for Bundler to work with a local gemspec.
[**Fixing longstanding issues with plugins by tracking them in the Gemfile.lock file**](https://github.com/rubygems/rubygems/pull/6957?ref=rubycentral.org)
- A couple of frustrations with plugins specified via Gemfile have been coming up for years: they are constantly reinstalled, and they cause unnecessary resolution metadata to be fetched, even in deployment mode. We want to encourage people to create and use Bundler plugins by ensuring they have a smooth usage experience.
- After a few iterations, we realized we can treat plugins the same as regular gems and therefore avoid all the unnecessary work by having a lockfile. So the solution ended up being simple: including plugins as gems in the lockfile.
- We need to do some backwards compatibility work around making changes to the lockfile but aside from that, we expect this solution to resolve most of the issues.
[**Bundler specs will now use the Compact Index by default**](https://github.com/rubygems/rubygems/pull/7669?ref=rubycentral.org)
- As a first step to providing a way to opt-in to lockfile checksums, we want to make sure most Bundler specs use the compact index (that exercises checksums under the hood).
- Bundler specs currently use the fallback to the full index by default. This is a very rare working mode these days since it requires that all dependency APIs fail. In addition to that, the full index does not provide checkums. Switching to using the compact index by default will give us confidence to enable lockfile checksums.
- It was a very big PR with bulk changes migrating from file:// sources that skip dependency APIs to dummy https sources that do exercise the compact index. It was a bit tricky to get everything passing but we trust it is safe as most of the changes are confined to test code.
In June, RubyGems gained [153 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2024-6-01%7D...master@%7B2024-6-31%7D?ref=rubycentral.org) contributed by 18 authors. They were 5,907 additions and 4,833 deletions across 231 files.
## [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) News
The updates made this month to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform. Sponsored hosting for [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) in June was provided by [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Fastly](https://www.fastly.com/?ref=rubycentral.org), and [DataDog](https://www.datadoghq.com/?ref=rubycentral.org). The following are highlights of what the team worked on this month:
**RubyGems Organization Accounts**
- We are building a new feature for [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) that will allow organization accounts, memberships and increased control over gem permissions. The feature will give gem owners more precise control over ownership of gems and permissions for organization members.
- We know that nuance is required when introducing this additional layer of organization into the existing [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) framework and we plan to introduce the new feature without disrupting existing workflows.
- This month, we created user flows to identify potential challenges and edge cases, refactored permissions models to use the well-known Pundit gem, and added basic models in preparation for the feature.
[**Aligning Authentication on RubyGems.org with best practices**](https://github.com/rubygems/rubygems.org/milestone/17?ref=rubycentral.org)
- Back in January when we released details about [an MFA bypass in the password reset](https://blog.rubygems.org/2024/03/15/password-reset-vulnerability.html?ref=rubycentral.org) process, it became clear that our MFA strategy was not applied uniformly in a way that helped us reduce mistakes. We have some flows that don’t follow [OWASP guidelines for password resets](https://cheatsheetseries.owasp.org/cheatsheets/Forgot%5FPassword%5FCheat%5FSheet.html?ref=rubycentral.org), email tokens, or MFA.
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) has been working to carefully refactor all MFA interaction points in [RubyGems.org](http://rubygems.org/?ref=rubycentral.org), increasing test coverage and unifying MFA processes under a single code path. We have adopted many of the best practices for securing authentication processes as defined by OWASP and other guidelines.
- One example is, we have now stopped our previous practice of auto-sign-in after password changes or email confirmations to ensure that all processes that can result in a session must pass through through the full sign-in process.
## Ruby Ecosystem News
Here we outline additional exciting updates made to other projects in the Ruby Ecosystem.
### Ruby Toolbox
[**Making local setup and codespaces based contributions to the Ruby Toolbox easier**](https://www.ruby-toolbox.com/blog/2024-05-31/devcontainers?ref=rubycentral.org)
- Data dumps are quite large nowadays and importing them locally can take hours. It would be helpful to provide a slim data dump for a realistic but small local development dataset, to create a more accessible way of contributing to the site itself.
- [@colszowka](https://github.com/colszowka?ref=rubycentral.org) has added partial production database exports to the Ruby Toolbox, making it easier to get a realisitc dataset for development purposes. Alongside this, there is now a devcontainer setup for easier local or browser-based development environment setup, for example using Codespaces.
[**Making historical and recent security advisories for RubyGems visible on the Ruby Toolbox**](https://github.com/rubytoolbox/rubytoolbox/issues/1196?ref=rubycentral.org)
- To increase transparency and ensure everyone has the latest database information, work by Christoph is underway to import the Ruby advisory database to the Ruby Toolbox, for displaying security advisories on the site. The data is already being imported, with the remaining step being to actually show it on the UI.
In June, [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) gained [110 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2024-6-01%7D...master@%7B2024-6-31%7D?ref=rubycentral.org) contributed by 11 authors. There were 3,655 additions and 2,518 deletions across 211 files.
## Total spent
In June we spent $93,945.76 on development work.
## Thank you
Thank you to all the contributors of RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### Contributors to RubyGems:
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@tompng](https://github.com/tompng?ref=rubycentral.org) Tomoya Ishida
- [@sobrinho](https://github.com/sobrinho?ref=rubycentral.org) Gabriel Sobrinho
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@MSP-Greg](https://github.com/MSP-Greg?ref=rubycentral.org) MSP Greg
- [@kddnewton](https://github.com/kddnewton?ref=rubycentral.org) Kevin Newton
- [@kateinoigakukun](https://github.com/kateinoigakukun?ref=rubycentral.org) Yuta Saito
- [@Earlopain](https://github.com/Earlopain?ref=rubycentral.org) Earlopain
- [@alexeyschepin](https://github.com/alexeyschepin?ref=rubycentral.org) Alexey Schepin
- [@x-yuri](https://github.com/x-yuri?ref=rubycentral.org) X Yuri
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@ccmywish](https://github.com/ccmywish?ref=rubycentral.org) CCMyWish
- [@thomasmarshall](https://github.com/thomasmarshall?ref=rubycentral.org) Thomas Marshall
- [@jeromedalbert](https://github.com/jeromedalbert?ref=rubycentral.org) Jerome Dalbert
### Contributors to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org):
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
- [@jacklynhma](https://github.com/jacklynhma?ref=rubycentral.org) Jacklyn Ma
- [@nateberkopec](https://github.com/nateberkopec?ref=rubycentral.org) Nate Berkopec
- [@javier-menendez](https://github.com/javier-menendez?ref=rubycentral.org) Javier Menéndez Rizo
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@robbyrussell](https://github.com/robbyrussell?ref=rubycentral.org) Robby Russell
- [@gemmaro](https://github.com/gemmaro?ref=rubycentral.org) Gemmaro
- [@okuramasafumi](https://github.com/okuramasafumi?ref=rubycentral.org) Okura Masafumi
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
*If we missed you, please let us know so we can include you in our shout out!*
### RubyConf 2024 Presale Tickets: UPDATE!
URL: https://rubycentral.org/news/rubyconf-2024-presale-tickets-update/
Last updated: 2024-06-26T22:36:03.000Z
_This post is for subscribers only._
### RubyConf 2024 Presale Tickets Now Available!
URL: https://rubycentral.org/news/rubyconf-2024-presale-tickets-now-available/
Last updated: 2024-06-26T17:36:10.000Z
_This post is for subscribers only._
### RubyConf 2024 Tickets Sales Updates!
URL: https://rubycentral.org/news/rubyconf-2024-tickets-on-sale-soon/
Last updated: 2024-06-21T21:14:40.000Z
RubyConf 2024 ticket sales are coming soon! For full details, [visit the link here](https://mailchi.mp/a852574078d7/exciting-news-rubyconf-2024-presale-live-soon?ref=rubycentral.org).
Get early updates: Join our mailing list [here](https://rubycentral.us13.list-manage.com/subscribe?u=e7e9b891a6914ff2f5acdfd15&id=0a6a1336c5&ref=rubycentral.org).
Mailing list subscribers received this information in advance. Don't miss future announcements!
### June 2024 Newsletter
URL: https://rubycentral.org/news/june-2024-newsletter/
Last updated: 2024-07-25T20:36:09.000Z
Hello! Welcome to the June newsletter. Read on for announcements from Ruby Central and a report of the OSS work we’ve done from the previous month.
In May, Ruby Central's open-source work was supported by Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org), [AWS](https://aws.amazon.com/?ref=rubycentral.org), the [German Sovereign Tech Fund](https://www.sovereigntechfund.de/?ref=rubycentral.org) (STF), and Ruby Central memberships from 29 other companies, including Partner-level member [Contributed Systems](https://contribsys.com/?ref=rubycentral.org), the company behind Mike Perham’s [Sidekiq](https://sidekiq.org/?ref=rubycentral.org). In total, we were supported by 189 members. Thanks to all of our members for making everything that we do possible. <3
## **Ruby Central News**
### RubyConf 2024 announcements

#### ICYMI: We’re thrilled to have confirmed our second RubyConf 2024 keynote speaker, Kent Beck!
[Kent Beck](https://t.co/ydT55rPF49?ref=rubycentral.org) is Chief Scientist at Mechanical Orchard, an Agile Manifesto signatory, a prolific author and creator of Extreme Programming. His work paved the way for many software practices used by the community today.
#### Ticket Sales Updates
**Tickets will be available to the public on July 3!** But you can [join the list](https://rubycentral.us13.list-manage.com/subscribe?u=e7e9b891a6914ff2f5acdfd15&id=0a6a1336c5&ref=rubycentral.org) now to purchase presale tickets starting **June 26.** If you are a Ruby Central member you’ll automatically receive pre-sale access.
A limited number of supporter tickets are on sale now, [here](https://ti.to/rubyconf/2024?ref=rubycentral.org).
#### Book Your Conference Hotel Room
[**Book your hotel room**](https://book.passkey.com/event/50806364/owner/2874/home?ref=rubycentral.org) in our RubyConf room block at conference rates, while they last! The deadline to reserve these rooms is **October 18**.
#### CFP Deadline: July 8
The deadline is getting closer! If you want the chance to join us as a speaker, don’t forget to [**get your CFP submission in**](https://sessionize.com/rubyconf-2024/?ref=rubycentral.org) by July 8.
#### Call for Speaker Mentors
We’re looking for volunteers with conference speaking experience to offer guidance during CFP group coaching sessions and provide one-on-one speaker mentorship. [Learn more and apply here.](https://docs.google.com/forms/d/e/1FAIpQLSc0tbwD-h5Yz%5FYe1dqLKmj9MOYLrx-mYC1D5mLm-8TTe0PXMA/viewform?ref=rubycentral.org)
### **Keep up with Ruby Central’s AWS Software Engineer in Residence**
- Samuel Giddins, [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) lead Security Engineer and our [Software Engineer in Residence](https://rubycentral.org/news/ruby-central-welcomes-new-software-engineer-in-residence-sponsored-by-aws/), has been sharing the highs, lows, and progress updates of his security work on his blog. Last month his development work included:
- Significant refactoring and improvement of the Sigstore Ruby implementation.
- Progress on the RubyGems research tool, mainly involving deploying it to a new kubernetes cluster.
- API security improvements for an easier, more functional and safe user experience.
- Trusted publishing enhancements including a RubyGems plugin for automatically adding trusted publishing to existing gems.
- You can learn more and follow along [here](https://blog.segiddins.me/?ref=rubycentral.org). Thank you to AWS for supporting this work!
### **We’re revamping our Ruby Central Membership Program!**
- Ruby Central is forming sustaining partnerships with major companies in our community. [Click here to learn about all of the exciting new ways we’ll be engaging with our members and how you can get involved](https://webforms.pipedrive.com/f/6aW4k05dMuwVRUNS7cR5nhHZyJFbhc7hrhQnQ21odD5tYLNhzwTSa9Xu1bguTOzePV?ref=rubycentral.org).
### **Upcoming Conferences:**
- Ruby Central
- [RubyConf 2024](https://rubyconf.org/?ref=rubycentral.org) will be in Chicago on Nov 13-15 at the Hilton Downtown Chicago.
- RailsConf 2025 [will be our final RailsConf ever.](https://rubycentral.org/news/anewearforrubycentralevents/)
- We’d love our community to help us choose the location for this final event. If you have not filled out the [Google Form](https://docs.google.com/forms/d/e/1FAIpQLSeQIVh1Uje6LBHFbkcSgVMliMPUVKt-kVloHAQ8OuVkvYoopw/viewform?usp=sharing&ref=rubycentral.org) to vote please do, we’d love to hear from you!
- We’ve made a limited number of supporter tickets available [here](https://ti.to/railsconf/2025?ref=rubycentral.org) for purchase — consider contributing to help make this special event the best one yet!
- Community Conferences
- This summer’s Ruby conference lineup includes: [Brighton Ruby](https://brightonruby.com/?ref=rubycentral.org) (June 28), [Red Dot RubyConf](https://reddotrubyconf.com/?ref=rubycentral.org) (July 25–26), [RubyConf Africa](https://rubyconf.africa/?ref=rubycentral.org) (July 26–27), [Madison+Ruby](https://www.madisonruby.com/?ref=rubycentral.org) (August 1–2), and [Rails Camp USA](https://west.railscamp.us/2024?ref=rubycentral.org) (August 27–30).
- Updated information is always available at [rubyconferences.org](https://rubyconferences.org/?ref=rubycentral.org), which includes [a super-handy iCal feed](https://rubyconferences.org/calendar.ics?ref=rubycentral.org).
### **Get Involved:**
- If you'd like to get involved and help make our community and events even better, we'd love to have you join us! Check out our [volunteer page](https://rubycentral.org/volunteer/), and/or feel free to [shoot an email to our executive director, Adarsh](http://adarsh@rubycentral.org/), to find the best way to get plugged in.
- Want to promote your company at RubyConf 2024? **Secure your sponsorship now** to reach all our attendees, showcase your thought leadership, and cultivate invaluable industry relationships. [Email our wonderful sponsorships manager, Tom](http://tom@rubycentral.org/) to learn more.
- Remember, you can receive exclusive benefits like conference discounts and more by signing up for a Ruby Central [membership](https://rubycentral.org/#/portal/signup). *Check to see if your employer matches donations to Ruby Central, Inc. through* [*Benevity*](https://causes.benevity.org/causes/840-300040446?ref=rubycentral.org) *and double your support!*
## RubyGems News
In May, we released RubyGems [3.5.10](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3510--2024-05-03) and [3.5.11](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3511--2024-05-28) , and Bundler [2.5.10](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2510-may-3-2024) and [2.5.11](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2511-may-28-2024). These releases bring a series of enhancements and bug fixes designed to improve the overall developer experience with RubyGems, including: a security update to [limit the size of the metadata and checksums files](https://github.com/rubygems/rubygems/pull/7568?ref=rubycentral.org) in a gem package, a fix for an issue when [plugin stubs would sometimes not be properly removed](https://github.com/rubygems/rubygems/pull/7631?ref=rubycentral.org) by `gem uninstall`, the [deprecation of Bundler constants](https://github.com/rubygems/rubygems/pull/7653?ref=rubycentral.org) and [the addition of\--glob flag to bundle add](https://github.com/rubygems/rubygems/pull/7557?ref=rubycentral.org). Finally, Ngan Pham, software engineer at Gusto, penned this [guest blog post](https://blog.rubygems.org/2024/05/30/bundler-auto-install-just-got-a-whole-lot-better.html?ref=rubycentral.org) on an exciting improvement to `auto_install` [@technicalpickles](https://github.com/technicalpickles?ref=rubycentral.org) implemented, that is also included in this Bundler release.
Some other important accomplishments from the team this month include:
[**Improve handling of applications with a local cache of gems**](https://github.com/rubygems/rubygems/pull/7680?ref=rubycentral.org)
- Recently we had fixed some issues for gems with a local cache of gems. Unfortunately these fixes created both functionality and performance regressions with this mode of operation. We worked on fixing these issues while also improving Bundler’s internal code organization.
- We made handling the type of gems considered by bundler (locally installed, cached, or remote) more explicit and moved it out of `Bundler::Definition` which is a class with too many responsibilities. This allowed us to simplify the code and fix reported issues about functionality and performance, improving the RubyGems experience for both users and developers.
[**Making default gems behave like regular gems**](https://github.com/rubygems/rubygems/pull/7673?ref=rubycentral.org)
- Handling default gems can be challenging even with minor Ruby updates. This can impact Bundler when switching Ruby versions, leading to missing gems.
- Default gems also require special internal handling. Ideally, we want to treat default gems like regular gems, allowing them to be cached and fully installed in Bundler's configured path. Although we attempted this change for Bundler 2.5, we reverted it just before release due to reports of issues.
- This time, we've tried to learn from past experiences and re-enable the feature, ensuring that default gems are considered a last resort if their regular copies cannot be found. This approach maintains backward compatibility.
[**Fixing a shallow clone bug in Bundler git sources**](https://github.com/rubygems/rubygems/pull/7649?ref=rubycentral.org)
- Bundling a git source could fail if the git server does not support shallow cloning. This issue was a regression from previous versions of Bundler.
- [@llenk](https://github.com/llenk?ref=rubycentral.org) joined us at RailsConf 2024’s Hack Day and helped work on a fix for this. We focused on a bug report about git sources breaking for some users. [@llenk](https://github.com/llenk?ref=rubycentral.org) developed a solution that first attempts an efficient shallow clone and, if that fails, automatically retries with a full git clone.
[**Refactoring the Compact Index Client**](https://github.com/rubygems/rubygems/pull/7678?ref=rubycentral.org)
- The `CompactIndexClient`, Bundler’s high efficiency gem resolution interface to [rubygems.org](http://rubygems.org/?ref=rubycentral.org) and other gem sources, has grown organically over time.
- Previously we had to refactor the updater to make it compatible with other gem sources and to clarify behavior. Increasing the readability of critical code paths makes it easier for new and experienced contributors alike to improve code, find bugs and increase performance.
- Inspired by memory improvements implemented during RailsConf 2024’s Hack Day, we have refactored the client, improved the cache interfaces and extracted a compact index parser.
[**Improving the memory footprint of bundle update**](https://github.com/rubygems/rubygems/pull/7637?ref=rubycentral.org)
- When running `bundle update` and parsing the compact index versions file, an inefficiency caused nearly 70MB of unnecessary memory usage each time.
- This issue was discussed during at session at RailsConf 2024, which led [@jacklynhma](https://github.com/jacklynhma?ref=rubycentral.org) to join us during the conference’s Hack Day and help tackle it. We quickly identified a change to reduce the memory footprint of parsing compact index versions: updating cache checksums. [@jacklynhma](https://github.com/jacklynhma?ref=rubycentral.org) successfully implemented this improvement.
```bash
==> after <==
Total allocated: 689.06 MB (9638226 objects)
Total retained: 237.01 MB (2979180 objects)
==> before <==
Total allocated: 755.64 MB (10379242 objects)
Total retained: 236.94 MB (2977745 objects)
```
[**Fixing a Bundler Error Message Related Bug**](https://github.com/rubygems/rubygems/issues/7681?ref=rubycentral.org#issuecomment-2125887269)
- A user reported that they received a confusing error message during a failed Bundle install of the Crono gem, leading them to open an issue. The error message incorrectly suggested a problem with Bundler, while the actual issue was operating system incompatibility.
- After collaborating with the user to define the problem, the error message was clarified to accurately reflect the operating system incompatibility issue. It now also provides clear guidance on gem naming to help users resolve the problem.
In May, RubyGems gained [131 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2024-5-01%7D...master@%7B2024-5-31%7D?ref=rubycentral.org) contributed by 18 authors. They were 1,961 additions and 864 deletions across 142 files.
## [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) News
The updates made this month to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform. Sponsored hosting for [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) in May was provided by [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Fastly](https://www.fastly.com/?ref=rubycentral.org), and [DataDog](https://www.datadoghq.com/?ref=rubycentral.org). The following are highlights of what the team worked on this month:
[**Set up Users for Trusted Publishing at RailsConf 2024**](https://github.com/rubygems/rubygems.org/pull/4676?ref=rubycentral.org)
- At the end of last year we announced the release of [Trusted Publishing](https://blog.rubygems.org/2023/12/14/trusted-publishing.html?ref=rubycentral.org), a new feature that will help make [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) more secure, and make it easier to automate gem publishing.
- RailsConf 2024’s Hack Day provided contributors with an opportunity to get involved in RubyGems projects and learn how to set up Trusted Publishing. During the event, [@segiddins](https://github.com/segiddins?ref=rubycentral.org) successfully set up a Trusted Publishing API for users, making the process even more accessible.
[**Added a timescaledb to RubyGems.org infrastructure**](https://github.com/rubygems/rubygems.org/pull/4716?ref=rubycentral.org)
- Earlier this year we began work on the [metrics project](https://github.com/rubygems/rubygems.org/issues/4642?ref=rubycentral.org), which seeks to introduce granular tracking and insights of gem downloads for users. To continue momentum on this, we have started the process of adding Timescale DB to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) stack. We plan to use a separate Timescale instance to hold analytics information, like downloads over time.
In May, [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) gained [83 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2024-5-01%7D...master@%7B2024-5-31%7D?ref=rubycentral.org) contributed by 11 authors. There were 1,429 additions and 662 deletions across 135 files.
## Total spent
In May we spent $166,682.86 on development work.
## Thank you
Thank you to all the contributors of RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### Contributors to RubyGems:
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@jenshenny](https://github.com/jenshenny?ref=rubycentral.org) Jenny Shen
- [@kateinoigakukun](https://github.com/kateinoigakukun?ref=rubycentral.org) Yuta Saito
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@voxik](https://github.com/voxik?ref=rubycentral.org) Vít Ondruch
- [@llenk](https://github.com/llenk?ref=rubycentral.org) Ellen Keal
- [@x-yuri](https://github.com/x-yuri?ref=rubycentral.org) X Yuri
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@jacklynhma](https://github.com/jacklynhma?ref=rubycentral.org) Jacklyn Ma
- [@stomar](https://github.com/stomar?ref=rubycentral.org) Marcus Stollsteimer
- [@dkav](https://github.com/dkav?ref=rubycentral.org) Darren Kavanagh
- [@MSP-Greg](https://github.com/MSP-Greg?ref=rubycentral.org) MSP Greg
- [@pascalbetz](https://github.com/pascalbetz?ref=rubycentral.org) Pascal Betz
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@k0kubun](https://github.com/k0kubun?ref=rubycentral.org) Takashi Kokubun
- [@sachin-sandhu](https://github.com/sachin-sandhu?ref=rubycentral.org) S.Sandhu
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
- [@honeyankit](https://github.com/honeyankit?ref=rubycentral.org) Ankit Honey
- [@JRice](https://github.com/JRice?ref=rubycentral.org) Jeremy Rice
### Contributors to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org):
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
- [@jacklynhma](https://github.com/jacklynhma?ref=rubycentral.org) Jacklyn Ma
- [@nateberkopec](https://github.com/nateberkopec?ref=rubycentral.org) Nate Berkopec
- [@javier-menendez](https://github.com/javier-menendez?ref=rubycentral.org) Javier Menéndez Rizo
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
*If we missed you, please let us know so we can include you in our shout out!*
### Performance, AI, Weird Ruby and Matz: The RubyConf 2024 CFP is Open
URL: https://rubycentral.org/news/performance-ai-weird-ruby-and-matz-the-rubyconf-2024-cfp-is-open/
Last updated: 2024-09-04T21:08:16.000Z
*Join a Lineup of Technical Talks and an In-person Keynote by the Ruby Language Creator*
PASADENA, C.A. (June 6, 2024) – Ruby Central, Inc., has just opened the [CFP](https://sessionize.com/rubyconf-2024/?ref=rubycentral.org) for RubyConf 2024\. RubyConf is the world's largest and longest-running gathering of Ruby enthusiasts, practitioners, and companies. This year’s event is happening Wednesday, November 13 to Friday November 15, 2024 in Chicago, IL.
This year, Ruby Central is curating a more technical program than in previous years. Inspired by [Ruby Kaigi](https://rubykaigi.org/?ref=rubycentral.org) in Japan, the conference will feature more technical talks from people contributing to the Ruby language itself. If there is interest, the program committee may even add a Kaigi track.
“We’re looking for talks on any Ruby topic that are technical yet accessible,” said Kinsey Durham Grace, Co-chair, RubyConf 2024\. “Our community loves talks on topics like AI and machine learning with Ruby, and performance optimization. We’re excited to bring them more.”
One keynote speaker has already joined the program. Yukihiro "Matz" Matsumoto, the creator of the [Ruby programming language](https://www.ruby-lang.org/en/?ref=rubycentral.org), will be appearing at the conference in person for the first time since 2019.
“Our community has grown up and is solving bigger business problems,” said Jim Remsik, Co-chair, RubyConf 2024\. “We also don’t want to lose sight of the creative, thoughtful, and weird ways people engage with Ruby.”
Aspiring speakers can start by exploring this year's conference themes of Performance and Scale, Ruby on the Web, Ruby in AI, Data Science and Machine Learning, and Weird Ruby.
The CFP is available [here](https://sessionize.com/rubyconf-2024/?ref=rubycentral.org). Apply before the July 8 deadline.
To learn more about RubyConf 2024, and to be notified when pre-sale tickets open, visit [rubyconf.org](https://rubyconf.org/?ref=rubycentral.org).
###
**About Ruby Central**
Ruby Central is a non-profit organization dedicated to supporting and advancing the Ruby programming language and a welcoming and diverse worldwide Ruby community. To learn more, visit [rubycentral.org](https://rubycentral.org/).
### May 2024 Newsletter
URL: https://rubycentral.org/news/may-2024-newsletter/
Last updated: 2024-06-21T04:47:06.000Z
Hello! Welcome to the May newsletter. Read on for announcements from Ruby Central and a report of the OSS work we’ve done from the previous month.
In April, Ruby Central's open-source work was supported by Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org), [AWS](https://aws.amazon.com/?ref=rubycentral.org), the [German Sovereign Tech Fund](https://www.sovereigntechfund.de/?ref=rubycentral.org) (STF), and Ruby Central memberships from 29 other companies, including Partner-level member [Contributed Systems](https://contribsys.com/?ref=rubycentral.org), the company behind Mike Perham’s [Sidekiq](https://sidekiq.org/?ref=rubycentral.org). In total, we were supported by 187 members. Thanks to all of our members for making everything that we do possible. <3
## **Ruby Central News**
### **Thank you to everyone who attended RailsConf Detroit!**

**Nadia Odunayo, Founder & CEO at The StoryGraph, delivering the opening keynote for RailsConf 2024\. Photo by Alice Heart Photography.*
- We had an amazing time celebrating Rails with you in Detroit! If you were there, we’d love to hear from you about your favorite parts of the event, and what we can do better. Please take our [10-minute survey](https://www.surveymonkey.com/r/D9QZBYH?ref=rubycentral.org) and share your experience.
- Conference photos and headshots are available now, [here](https://aliceheartphotography.passgallery.com/-railsconf2024/gallery?ref=rubycentral.org)! Videos of talks and workshops will be available a bit later. We’ll drop the announcement when they are released on our social media channels, so stay tuned!
- If you weren’t there, you can also browse our [Twitter](https://twitter.com/railsconf?ref=rubycentral.org) to indulge in even more FOMO :).
- Finally, check out these amazing recaps of the event from our community:
- Ruby content creator and RailsConf Detroit program committee member Kevin Murphy shares an organizer’s perspective [https://kevinjmurphy.com/posts/railsconf-2024-recap/](https://kevinjmurphy.com/posts/railsconf-2024-recap/?ref=rubycentral.org)
- RailsConf 2024 Speaker Garrett Dimon journals his thoughts about the Ruby programming language and community as a whole, and a response to our RailsConf 2025 announcement [https://garrettdimon.com/journal/posts/the-bright-future-of-ruby-and-rails](https://garrettdimon.com/journal/posts/the-bright-future-of-ruby-and-rails?ref=rubycentral.org)
- RailsConf 2024 Speaker Talysson Oliveira Cassiano provides a quick snapshot of his experience at the conference [https://blog.codeminer42.com/codeminer42-at-railsconf-2024/](https://blog.codeminer42.com/codeminer42-at-railsconf-2024/?ref=rubycentral.org)
- Robby Russell, of Planet Argon, ohmyz.sh and the Maintainable Software Podcast, shares his journey to, and through, his 11th-ish RailsConf [https://blog.planetargon.com/blog/entries/recap-railsconf-2024-detroit](https://blog.planetargon.com/blog/entries/recap-railsconf-2024-detroit?ref=rubycentral.org)
- Long-time dev but first-time-attendee Phil Smy created a daily video diary capturing his RailsConf Detroit experience [https://www.youtube.com/playlist?list=PLiJC12qFqVo1j0PtcnV4DltUsIRe5rnqA](https://www.youtube.com/playlist?list=PLiJC12qFqVo1j0PtcnV4DltUsIRe5rnqA&ref=rubycentral.org)
- RailsConf 2024 speaker, author and consultant Andrew Atkinson shares his RailsConf 2024 experience, other RailsConf memories and reflections on saying goodbye to RailsConf [https://andyatkinson.com/blog/2024/05/17/railsconf-conference-2024-detroit](https://andyatkinson.com/blog/2024/05/17/railsconf-conference-2024-detroit?ref=rubycentral.org)
- Finally, our intrepid RailsConf 2024 co-chair Andy Croll shares all the ups and downs of his conference organizing experience from first Ruby Central phone calls to final RailsConf bows [https://andycroll.com/ruby/railsconf-detroit-2024-cochairs-perspective/](https://andycroll.com/ruby/railsconf-detroit-2024-cochairs-perspective/?ref=rubycentral.org)
**Keep up with Ruby Central’s AWS Software Engineer in Residence**
- Samuel Giddins, [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) lead Security Engineer and our [Software Engineer in Residence](https://rubycentral.org/news/ruby-central-welcomes-new-software-engineer-in-residence-sponsored-by-aws/), has been sharing the highs, lows, and progress updates of his security work on his blog. Last month his development work included:
- Spending a significant amount of time investigating the impact of the xz/liblzma backdoor on the RubyGems ecosystem, and publishing [a blog post](https://blog.rubygems.org/2024/03/31/rubygems-and-xz.html?ref=rubycentral.org) on his findings. The rubygems-research tool proved invaluable in efficiently analyzing the spread of the vulnerable library within RubyGems. Spoiler: RubyGems was not vulnerable to the backdoor!
- Patching various Denial of Service (DoS) vulnerabilities related to YAML aliases and uploaded gem metadata size in [RubyGems.org](http://rubygems.org/?ref=rubycentral.org), improving the platform by re-introducing avatars with privacy considerations (more on this below), and documenting the compact index API for package repositories.
- You can learn more and follow along [here](https://blog.segiddins.me/?ref=rubycentral.org). Thank you to AWS for supporting this work!
### **We’re revamping our Ruby Central Membership Program!**
- If you’re reading this in your email inbox, you should have already received this news. If not, [check out this announcement](https://mailchi.mp/3405f17377c1/new-ruby-central-member-benefits-fundraising-drive?ref=rubycentral.org) to learn about all of the exciting new ways we’ll be engaging with our members and how you can get involved.
### **Upcoming Conferences:**
- Ruby Central
- RubyConf 2024 will be in Chicago on Nov 13-15th at the Hilton Downtown Chicago.
- A limited number of supporter tickets are on sale now, [here](https://ti.to/rubyconf/2024?ref=rubycentral.org). **If you're on our mailing list you'll be the first to know when general tickets go on sale.**
- If you're not yet, [join the list here](https://rubyconf.org/?ref=rubycentral.org).
- In the meantime, you can [reserve your hotel room at our special conference rate now](https://book.passkey.com/event/50806364/owner/2874/home?ref=rubycentral.org).
- *RailsConf 2025 will be our final RailsConf ever.*
- Read more about why [here](https://rubycentral.org/news/anewearforrubycentralevents/).
- We’ve made a limited number of supporter tickets available [here](https://ti.to/railsconf/2025?ref=rubycentral.org) for purchase — consider contributing to help make this special event the best one yet!
- We’d love our community to help us choose the location for this final event. If you have not filled out the [Google Form](https://docs.google.com/forms/d/e/1FAIpQLSeQIVh1Uje6LBHFbkcSgVMliMPUVKt-kVloHAQ8OuVkvYoopw/viewform?usp=sharing&ref=rubycentral.org) to vote please do, we’d love to hear from you!
- Community Conferences
- [RubyConf Africa](https://rubyconf.africa/?ref=rubycentral.org) has extended their CFP deadline. You can now [submit your talks](https://www.papercall.io/rubyconfafrica2024?ref=rubycentral.org) until May 31!
- Coming up in May: [Blue Ridge Ruby](https://blueridgeruby.com/?ref=rubycentral.org) (May 30-31), [Ruby for Good](https://rubyforgood.org/events?ref=rubycentral.org) (May 30 - June 2), and [RubyDay](https://2024.rubyday.it/?ref=rubycentral.org) (May 31).
- And this summer’s Ruby conference lineup includes: [Ruby Unconf](https://2024.rubyunconf.eu/?ref=rubycentral.org) (June 8–9), [Baltic Ruby](https://balticruby.org/?ref=rubycentral.org) (June 13–15), [Brighton Ruby](https://brightonruby.com/?ref=rubycentral.org) (June 28), [Red Dot RubyConf](https://reddotrubyconf.com/?ref=rubycentral.org) (July 25–26), [RubyConf Africa](https://rubyconf.africa/?ref=rubycentral.org) (July 26–27), [Madison+Ruby](https://www.madisonruby.com/?ref=rubycentral.org) (August 1–2), and [Rails Camp USA](https://west.railscamp.us/2024?ref=rubycentral.org) (August 27–30).
- Updated information is always available at [rubyconferences.org](https://rubyconferences.org/?ref=rubycentral.org), which includes [a super-handy iCal feed](https://rubyconferences.org/calendar.ics?ref=rubycentral.org).
### **Get Involved:**
- If you'd like to get involved and help make our community and events even better, we'd love to have you join us! Check out our [volunteer page](https://rubycentral.org/volunteer/), and/or feel free to [shoot an email to our executive director, Adarsh](http://adarsh@rubycentral.org/), to find the best way to get plugged in.
- Want to promote your company at RubyConf in 2024? **Secure your sponsorship now** to reach all our attendees, showcase your thought leadership, and cultivate invaluable industry relationships by [emailing our wonderful sponsorships manager, Tom](http://tom@rubycentral.org/).
- Remember, you can receive exclusive benefits like conference discounts and more by signing up for a Ruby Central [membership](https://rubycentral.org/#/portal/signup). *Check to see if your employer matches donations to Ruby Central, Inc. through* [*Benevity*](https://causes.benevity.org/causes/840-300040446?ref=rubycentral.org) *and double your support!*
## RubyGems News
In April, we released RubyGems [3.5.8](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#358--2024-04-11) and [3.5.9](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#359--2024-04-12), and Bundler [2.5.8](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#258-april-11-2024) and [2.5.9](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#259-april-12-2024). These releases bring a series of enhancements and bug fixes designed to improve the overall developer experience with RubyGems, including: a security improvement that adheres to [global umask settings when writing files](https://github.com/rubygems/rubygems/pull/7518?ref=rubycentral.org), a fix for the `[NoMethodError` crash linked to issues with corrupt package files\]([https://github.com/rubygems/rubygems/pull/7539](https://github.com/rubygems/rubygems/pull/7539?ref=rubycentral.org)), and a resolution for an error message problem in the resolver [when it runs out of versions due to the use of \--strict --patch filters](https://github.com/rubygems/rubygems/pull/7527?ref=rubycentral.org).
Some other important accomplishments from the team this month include:
[**Avoiding Writing Credentials to Lockfiles the Default**](https://github.com/rubygems/rubygems/pull/7560?ref=rubycentral.org)
- In an effort to enhance security and prevent users from accidentally sharing credentials publicly, we recommend that you do not embed credentials in lockfiles.
- This practice was already uncommon, except in instances where users included credentials directly in their Gemfile—a method we do not recommend. Instead, it's advisable to utilize settings.
- Despite some users opting to use an ENV variable, we consistently ensure that credentials are not stored in the lockfile but are sourced either from the configuration or directly from the Gemfile.
[**Making bundle update specific\_gems Smarter**](https://github.com/rubygems/rubygems/pull/7558?ref=rubycentral.org)
- For years, reports have indicated that `bundle update gem` does not consistently update the gem to its latest available version. Users find that if they delete their lockfile, specify the desired version in the Gemfile, or run `bundle install`, the gem updates as expected. Ideally, such steps shouldn't be necessary for updating a gem—`bundle update gem` should suffice.
- This is also why dependency bots like Dependabot sometimes fail to create PRs to address security alerts. The challenge is that upgrading one gem may require upgrading others to prevent version conflicts. `bundle update gem` currently lacks the capability to handle this complexity.
- To address this, I implemented a fix where a full `bundle update` is first executed to determine the latest resolvable versions, followed by a targeted update that forces these versions, allowing the resolver to manage any conflicts by unlocking conflicting dependencies.
[**Resolving Musl Platform Issues for RubyGems and Bundler**](https://github.com/rubygems/rubygems/pull/7583?ref=rubycentral.org)
- Since introducing support for the musl platform, there's been different issues and regressions with it, leading to hesitancy among gem authors about releasing musl variants. The maintainer of Nokogiri has been actively identifying these issues, including a critical problem he believes to be the last barrier to fully supporting musl precompiled gems. Addressing this issue seemed necessary.
- The non-transitivity of `Gem::Platform#===` with musl was causing missing platforms in the lockfile, leading to resolution errors. The issue has been resolved by specifically accommodating the unique aspects of musl when removing invalid platforms from the lockfile.
In April, RubyGems gained [106 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2024-4-01%7D...master@%7B2024-4-31%7D?ref=rubycentral.org) contributed by 13 authors. There were 1,175 additions and 797 deletions across 106 files.
## [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) News
The updates made this month to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform. Sponsored hosting for [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) in April was provided by [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Fastly](https://www.fastly.com/?ref=rubycentral.org), and [DataDog](https://www.datadoghq.com/?ref=rubycentral.org).
The following are highlights of what the team worked on this month:
[**Re-introducing Avatars to RubyGems.org**](https://github.com/rubygems/rubygems.org/pull/4599?ref=rubycentral.org)
- Originally, profile images were removed from [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) due to privacy concerns, as Gravatar's system exposed user emails, leading to complaints. This change, however, made the site appear anonymous, diminishing the perceived trustworthiness of gem info pages.
- To address this issue, [@segiddins](https://github.com/segiddins?ref=rubycentral.org) has developed a solution that allows images to be safely displayed without compromising privacy. This new method proxies images through [RubyGems.org](http://rubygems.org/?ref=rubycentral.org), maintaining user privacy while enhancing the visual appeal and trust of the platform.
[**Adding RubyGems Yank Limits**](https://github.com/rubygems/rubygems.org/pull/4631?ref=rubycentral.org)
- To reduce the likelihood of disruption caused by a left-pad-like package removal, we've introduced limits on deleting old or highly downloaded gems.
- Gem deletions are primarily for immediate fixes of newly released gems where reverting is the best solution. For other issues, the recommended approach is to release a new version.
- We've set a provisional limit on gems that can be yanked. This policy affects gems with over 100,000 downloads or those older than 30 days, aligning more closely with other ecosystems that restrict deletions.
- We will adjust the policy based on feedback and continue to coordinate yank requests through RubyGems staff, balancing the needs of maintainers and the wider community.
[**An Upgraded Search System from OpenSearch v1 to v2**](https://github.com/rubygems/rubygems.org/pull/4613?ref=rubycentral.org)
- The upgrade from OpenSearch v1 to v2 allows us to benefit from new updates, features, and enhancements.
- Additionally, the introduction of High Availability ensures that our search functionality will remain operational even if an AWS Availability Zone(Data Center) goes offline, providing a robust and resilient service.
**Collaborated with Shopify on a JIT performance-focused Protobuf implementation**
- Earlier this year we began writing a pure Ruby protobuf implementation which is fully compliant. It was [completed last month](https://github.com/segiddins/protobug/pull/1?ref=rubycentral.org). We are coordinating our effort with Shopify, who are already at work on an implementation of protobuf that has different goals.
In April, [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) gained [82 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2024-4-01%7D...master@%7B2024-4-31%7D?ref=rubycentral.org) contributed by 10 authors. There were 1,111 additions and 761 deletions across 150 files.
## Total spent
In April we spent $78,729.06 on development work.
## Thank you
Thank you to all the contributors of RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### Contributors to RubyGems:
- [@andyw8](https://github.com/andyw8?ref=rubycentral.org) Andy Waite
- [@ccutrer](https://github.com/ccutrer?ref=rubycentral.org) Cody Cutrer
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@fatkodima](https://github.com/fatkodima?ref=rubycentral.org) Fatkodima
- [@flavorjones](https://github.com/flavorjones?ref=rubycentral.org) Mike Dalessio
- [@fryguy](https://github.com/Fryguy?ref=rubycentral.org) Jason Frey
- [@gdubicki](https://github.com/gdubicki?ref=rubycentral.org) Greg Dubicki
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@ilyazub](https://github.com/ilyazub?ref=rubycentral.org) ilyazub
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@mensfeld](https://github.com/mensfeld?ref=rubycentral.org) Maciej Mensfeld
- [@ngan](https://github.com/ngan?ref=rubycentral.org) Ngan Pham
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@technicalpickles](https://github.com/technicalpickles?ref=rubycentral.org) Josh Nichols
- [@thedavemarshall](https://github.com/thedavemarshall?ref=rubycentral.org) Dave Marshall
### Contributors to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org):
- [@ahangarha](https://github.com/ahangarha?ref=rubycentral.org) Mostafa Ahangarha
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
- [@dancristianb](https://github.com/dancristianb?ref=rubycentral.org) Dancristianb
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@javier-menendez](https://github.com/javier-menendez?ref=rubycentral.org) Javier Menéndez Rizo
- [@markets](https://github.com/markets?ref=rubycentral.org) Marc Anguera
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
*If we missed you, please let us know so we can include you in our shout out!*
### A New Era for Ruby Central Events
URL: https://rubycentral.org/news/anewearforrubycentralevents/
Last updated: 2024-11-15T16:17:32.000Z
### *A special announcement for the Ruby community*
###
We normally announce next year’s RailsConf location at the end of the conference, but this time we are going to do something a little different and share two pieces of news:
**We are delighted to announce that we want to involve you all in deciding where we will have RailsConf next year.** Please use [this Google Form](https://docs.google.com/forms/d/e/1FAIpQLSeQIVh1Uje6LBHFbkcSgVMliMPUVKt-kVloHAQ8OuVkvYoopw/viewform?usp=sharing&ref=rubycentral.org) to share your feedback.
**We have also decided that RailsConf 2025 will be our final one.** Beyond 2025, we will be focusing on RubyConf as our flagship event, as we deepen our involvement in supporting regional conferences, meetups, and open source development.
RailsConf 2025 will be reimagined to be a more focused celebration of the Rails community and the legacy of RailsConf. This means there will be a few changes including less content, and a smaller number of tickets.
*A limited number of supporter tickets for both conferences will be on sale starting now:*
- [*RailsConf 2025*](https://ti.to/railsconf/2025?ref=rubycentral.org)
- [*RubyConf 2024*](https://ti.to/rubyconf/2024?ref=rubycentral.org)
We know this comes as a surprise to many of you, especially after almost 20 years of producing this conference. Suffice to say, this is a bittersweet announcement to make for those of us who have been involved in running Ruby Central and these conferences for many years.
### Why the change?
Ruby Central’s mission is to tend to the resources and ecosystem of the Ruby community which includes running, maintaining, and securing RubyGems and Bundler for the whole community; and organizing conferences. The landscape of the Ruby community, the open source space and the tech industry as a whole has changed — especially for those of us who put on in person events. For one, the impact of the pandemic on RailsConf and Ruby Central has been very challenging, and our community has been slow to return to in-person events. This is very understandable, but has made organizing sustainable events tough.
We also recognize that our community has many new conference choices available, including new Rails-focused conferences and a resurgence in regional conferences here in the US and internationally.
### What that means for us going forward
Beginning next year, we will concentrate on RubyConf as our flagship event and dedicate more time to expanding the Ruby ecosystem including exciting opportunities like:
- Expanding our support of essential Ruby OSS projects
- Supporting regional conferences in the US and abroad
- Helping to revitalize our meetup network
- Increased support for underrepresented communities
- Education programs to help developers level up their skills
We will also be procuring and dedicating more resources to our open source work, which has been better funded recently than ever before and has opened our eyes to the expanded ways which we can serve our community. With recent funding, we have achieved:
- A full-time security engineer
- Round the clock support for rubygems.org
- Implementation of modern security measures
- And coming soon: organization-level accounts and conduct a formal security audit
And we plan to do much more.
### What you can do
We need your support as we create the future of Ruby Central. If you want to get involved here are the best places to start:
- If you’re at the conference now, come see us at the Ruby Central booth. Tell us how you feel, good or bad, and buy your limited-edition supporter ticket to RailsConf 2025\.
- Buy one of the limited-edition supporter tickets for RubyConf 2024 in Chicago, **featuring Matz joining us in person for the first time since 2019!**
- Ask your employer to sponsor RubyConf 2024 (email sponsors@rubycentral.org).
- Join the Ruby Central Monthly Sustaining Member program.
- Ask your company to sponsor Ruby Central as a core member. Email us at for more information.
We thank you for your continued support and for being a part of our community – and let's keep the conversation going.
### April 2024 Newsletter
URL: https://rubycentral.org/news/april-2024-newsletter/
Last updated: 2024-05-20T22:47:00.000Z
Hello! Welcome to the April newsletter. Read on for announcements from Ruby Central and a report of the OSS work we’ve done from the previous month.
In March, Ruby Central's open-source work was supported by Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org), [AWS](https://aws.amazon.com/?ref=rubycentral.org), the [German Sovereign Tech Fund](https://www.sovereigntechfund.de/?ref=rubycentral.org) (STF), and Ruby Central memberships from 29 other companies, including[ ](https://www.zendesk.com/?ref=rubycentral.org)Partner-level member [Contributed Systems](https://contribsys.com/?ref=rubycentral.org), the company behind Mike Perham’s [Sidekiq](https://sidekiq.org/?ref=rubycentral.org). In total, we were supported by 173 members. Thanks to all of our members for making everything that we do possible. <3
## **Ruby Central News**
**New Jobs Added to Ruby Central Job Board**
- Revela recently posted a few new opportunities! Check it out[here.](https://rubycentral.jobboardly.com/?ref=rubycentral.org)
**Keep up with Ruby Central’s AWS Software Engineer in Residence**
- Samuel Giddins, RubyGems.org lead Security Engineer and our [Software Engineer in Residence](https://rubycentral.org/news/ruby-central-welcomes-new-software-engineer-in-residence-sponsored-by-aws/), has been sharing the highs, lows, and progress updates of his security work on his blog. Last month his development work focused on continuing implementation of the pure-Ruby Sigstore verification library and fixing performance issues on RubyGems.org by identifying and resolving several N+1 query problems. You can learn more and follow along [here](https://blog.segiddins.me/?ref=rubycentral.org). Thank you to AWS for supporting this work!
### **We’re revamping our Ruby Central Membership Program!**
- If you’re reading this in your email inbox, you should have already received this news. If not, [check out this announcement](https://mailchi.mp/3405f17377c1/new-ruby-central-member-benefits-fundraising-drive?ref=rubycentral.org) to learn about all of the exciting new ways we’ll be engaging with our members and how you can get involved!
### **Upcoming Conferences:**
- Ruby Central
- RailsConf Detroit on May 7 - 9 is just over two weeks away!
- New talks and events have been added to the schedule (like lighting talks and the job fair 👀). [Check them out here](https://railsconf.org/schedule/?ref=rubycentral.org) and then [buy yourtickets here](https://ti.to/railsconf/2024?ref=rubycentral.org). We hope you'll join us!
- ***Room reservation cut-off date EXTENDED:*** The LAST DAY to book a room in our RailsConf room block at Detroit Marriott at the Renaissance Center is now MONDAY, APRIL 22\. This will save you some change: the average price online is $235 and our rate is $212\. [Reserve your room here.](https://rubycentral.us13.list-manage.com/track/click?u=e7e9b891a6914ff2f5acdfd15&id=070eb887b5&e=03c074fcb3&utm%5Fsource=RailsConf+Marketing+Long+List%3A+2014+-+2024+%2BSponsors%2C+Members&utm%5Fcampaign=2040323aae-EMAIL%5FCAMPAIGN%5F2024%5F04%5F09%5F08%5F47%5FCOPY%5F01&utm%5Fmedium=email&utm%5Fterm=0%5F-5e0fec9cbb-%5BLIST%5FEMAIL%5FID%5D&mc%5Fcid=2040323aae&mc%5Feid=UNIQID)
- [The RubyConf 2024 website is live](https://rubyconf.org/?ref=rubycentral.org)! This year's RubyConf will be in Chicago on Nov 13-15th at the Hilton Downtown Chicago. If you're on our mailing list you'll be the first to know when tickets go on sale. If you're not yet, [join the list here](https://rubycentral.org/#/portal/signup). In the meantime, you can [reserve your room at our special conference rate now](https://book.passkey.com/event/50806364/owner/2874/home?ref=rubycentral.org).
- Community Conferences
- April is chock-full of Ruby conferences in [Brazil](https://www.tropicalrb.com/?ref=rubycentral.org), [Australia](https://rubyincommon.org/?ref=rubycentral.org), [Australia again(!)](https://2024.rubyconf.au/?ref=rubycentral.org), [Poland](https://2024.wrocloverb.com/?ref=rubycentral.org) and [Bulgaria](https://balkanruby.com/?ref=rubycentral.org). Visit their event websites to find out more.
- [RubyKaigi 2024](https://rubykaigi.org/2024/?ref=rubycentral.org) is happening on May 15th and our very own Security Engineer in Residence Samuel Giddins will be speaking! 👏👏
- Also coming up in May: [Helvetic Ruby](https://helvetic-ruby.ch/?ref=rubycentral.org) (May 17), [Blue Ridge Ruby](https://blueridgeruby.com/?ref=rubycentral.org) (May 30-31), [Ruby for Good ](https://rubyforgood.org/events?ref=rubycentral.org)(May 30 - June 2), and [RubyDay](https://2024.rubyday.it/?ref=rubycentral.org) (May 31).
- Updated information is always available at [rubyconferences.org](https://rubyconferences.org/?ref=rubycentral.org), which includes [a super-handy iCal feed](https://rubyconferences.org/calendar.ics?ref=rubycentral.org).
### **Get Involved:**
- If you'd like to get involved and help make our community and events even better, we'd love to have you join us! Check out our [volunteer page](https://rubycentral.org/volunteer/), and/or feel free to [shoot an email to our executive director, Adarsh](http://adarsh@rubycentral.org/), to find the best way to get plugged in.
- Want to promote your company at RailsConf or RubyConf in 2024? **Secure your sponsorship now** to reach all our attendees, showcase your thought leadership, and cultivate invaluable industry relationships by [emailing our wonderful sponsorships manager, Tom](http://tom@rubycentral.org/).
- Remember, you can receive exclusive benefits like conference discounts and more by signing up for a Ruby Central [membership](https://rubycentral.org/#/portal/signup). *Check to see if your employer matches donations to Ruby Central, Inc. through* [*Benevity*](https://causes.benevity.org/causes/840-300040446?ref=rubycentral.org) *and double your support!*
## **RubyGems News**
This month, RubyGems released RubyGems[ 3.5.7](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#357--2024-03-22) and Bundler[ 2.5.7](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#257-march-22-2024). These updates introduce a range of enhancements and bug fixes, all aimed at enhancing the developer experience. They include: [the introduction of an attribute](https://github.com/rubygems/rubygems/pull/7464?ref=rubycentral.org) in `Gem::SafeYAML.safe_load` to control whether YAML aliases is enabled, [a warning mechanism](https://github.com/rubygems/rubygems/pull/5010?ref=rubycentral.org) for when the `required_ruby_version` specification attribute is empty, and [the removal of unnecessary configurations](https://github.com/rubygems/rubygems/pull/7478?ref=rubycentral.org) in the RuboCop setup generated by `bundle gem`.
Some other important accomplishments from the team this month include:
[**Making gem install respect the umask of the target system**](https://github.com/rubygems/rubygems/pull/7518?ref=rubycentral.org)**:**
- The goal of this change is to address the issue where RubyGems may install files with permissions that are broader than desired, giving write permissions to users other than the current user. This issue arises when the original packaging of files includes these broad permissions, likely due to an unsafe umask set by the gem's author.
- The solution implemented by [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) was to adopt a more straightforward approach than the previous attempt (which was reverted due to test failures in `ruby core`) by applying the target system’s umask to regular files (excluding directories) before setting their permissions.
[**Fixed Bundler’s application cache misuse**](https://github.com/rubygems/rubygems/pull/7516?ref=rubycentral.org)**:**
- This update resolves an issue in how Bundler was using its cache, leading to odd behavior. Users were seeing unusual updates, like Bundler claiming it was updating to versions that didn’t actually exist (for example, "Updating to 3.0.9").
- The problem was rooted in how Bundler managed cached gems. These gems were mistakenly being considered in situations they shouldn’t have been, which caused not only strange messages but also errors in the lockfile, such as gems appearing under incorrect sources.
- The solution implemented ensures that cached gems are kept separate from those available online, preventing the confusion that was causing these issues. This approach helps maintain clarity and accuracy in Bundler’s operations.
In March, RubyGems gained [67 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2024-3-01%7D...master@%7B2024-3-31%7D?ref=rubycentral.org) contributed by 13 authors. There were 934 additions and 194 deletions across 92 files.
## **RubyGems.org News**
March's updates to RubyGems.org reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform.
The following are highlights of what the team worked on this month:
[**Major PostgreSQL zero downtime upgrade**](https://github.com/rubygems/pg-major-update?ref=rubycentral.org):
- This significant update was carried out to ensure that application dependencies remain up-to-date. Notably, this is the second upgrade effort, moving from PostgreSQL version 12 to 13, following the original upgrade to version 12 in response to the end of life (EOL) for PostgreSQL 11 on Amazon RDS.
- The upgrade process utilized `pgbouncer` and a manually managed blue/green environment to achieve zero downtime. For detailed scripts and an explanation of the procedure, visit the [project’s GitHub page](https://github.com/rubygems/pg-major-update?ref=rubycentral.org).
- A detailed blog post with additional details will be released soon on the [rubygems.org blog](https://blog.rubygems.org/?ref=rubycentral.org).
In March, RubyGems.org gained [69 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2024-2-01%7D...master@%7B2024-2-31%7D?ref=rubycentral.org) contributed by 12 authors. There were 466 additions and 1,263 deletions across 75 files.
## **Total spent**
In March we spent $90,187.39 on development work.
## **Thank you**
Thank you to all the contributors of RubyGems and RubyGems.org for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### **Contributors to RubyGems:**
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@kateinoigakukun](https://github.com/kateinoigakukun?ref=rubycentral.org) Yuta Saito
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@cuishuang](https://github.com/cuishuang?ref=rubycentral.org) Cui Fliter
- [@jez](https://github.com/jez?ref=rubycentral.org) Jake Zimmerman
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
- [@agrobbin](https://github.com/agrobbin?ref=rubycentral.org) Alex Robbin
- [@ccutrer](https://github.com/ccutrer?ref=rubycentral.org) Cody Cutrer
- [@JaneScarlet](https://github.com/JaneScarlet?ref=rubycentral.org) Amanda JC
### **Contributors to RubyGems.org:**
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@jgarber623](https://github.com/jgarber623?ref=rubycentral.org) Jason Garber
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@spk](https://github.com/spk?ref=rubycentral.org) Laurent Arnoud
- [@bradly](https://github.com/bradly?ref=rubycentral.org) Bradly Feeley
- [@joeldrapper](https://github.com/joeldrapper?ref=rubycentral.org) Joel Drapper
- [@ytjmt](https://github.com/ytjmt?ref=rubycentral.org) Yuki Tsujimoto
### 3 Day Flash Sale: RailsConf 2024
URL: https://rubycentral.org/news/railsconf-2024/
Last updated: 2024-04-12T16:33:34.000Z
*Because good things come in threes.*
Surprise! It’s a 3-Day Flash Sale. RailsConf Detroit is just over three weeks away. We'll be in Detroit for three days from May 7 -9\. So for three days only join us at a DISCOUNTED price before we sell out! Sale ends Monday.
**Grab your discounted tickets** [**HERE**](https://buff.ly/4avx7nf?ref=rubycentral.org)**!**
### RailsConf 2024 Speaker Spotlight + Preview: Chris Oliver
URL: https://rubycentral.org/news/railsconf-2024-speaker-spotlight/
Last updated: 2024-03-29T14:56:27.000Z
RailsConf always boasts an exciting variety of talks that highlight the creativity and interdisciplinary nature of the Ruby community. I thought it would be fun to curate a series highlighting our speakers' stories and their experiences in tech. Read on for today’s speaker spotlight…
### Title of Talk
Crafting Rails Plugins
### Speaker
Chris Oliver

### How Did you get into Ruby?
I started with Rails in college working for a professor and then built my senior project in Rails.
### What’s your favorite part about working on Open Source Software?
It's amazing how much you can learn and help other people with open source. Because the code isn't closed, we can achieve so much more.
### What’s your least favorite part about working on OSS?
Sometimes people can be demanding and ungrateful for the hard work and effort you put in.
### What inspired you to give this talk?
I've built a handful of Ruby gems over the years to extend Rails and wanted to help other people do the same. Plus, every Rails app is itself an engine so it will help people understand their own applications more deeply.
### What do you want people to take away from it?
You can build Rails plugins too (you already are!) and it's not that scary!
### What are you most looking forward to at this conference?
Making new friends and catching up with old friends.
### Do you have any other fun plans in Detroit during the in-person conference week?
Nope, just plan to hang out with everyone!
### RailsConf Talk preview!
0:00
/0:49
1×
*Thank you, Chris! See you at RailsConf 2024!*
### [Get your RailsConf tickets here](https://ti.to/railsconf/2024?ref=rubycentral.org).
### March 2024 Newsletter
URL: https://rubycentral.org/news/march-2024-newsletter/
Last updated: 2024-04-23T17:33:19.000Z
Hello! Welcome to the March newsletter. Read on for announcements from Ruby Central and a report of the OSS work we’ve done from the previous month.
In February, Ruby Central's open source work was supported by[ Shopify](https://www.shopify.com/?ref=rubycentral.org),[ AWS](https://aws.amazon.com/?ref=rubycentral.org), the[ German Sovereign Tech Fund](https://www.sovereigntechfund.de/?ref=rubycentral.org) (STF), as well as Ruby Central memberships from 29 other companies, including [ Zendesk](https://www.zendesk.com/?ref=rubycentral.org) and Ruby Shield sponsor and Partner-level member[ Contributed Systems](https://contribsys.com/?ref=rubycentral.org), the company behind Mike Perham’s[ Sidekiq](https://sidekiq.org/?ref=rubycentral.org). In total, we were supported by 174 members. Thanks to all of our members for making everything that we do possible. <3
## **Ruby Central News**
### **Ruby Central Receives Alpha-Omega Grant**
We’re thrilled to announce that we have been awarded a $250,000 grant from[ Alpha-Omega](https://alpha-omega.dev/?ref=rubycentral.org) to support critical open source projects on RubyGems.org, RubyGems and Bundler. Read more about how we’ll be using this funding [here](https://rubycentral.org/news/ruby-central-receives-alpha-omega-grant/).
### **Keep up with Ruby Central’s AWS Software Engineer in Residence**
- Samuel Giddins, RubyGems.org lead Security Engineer and our [Software Engineer in Residence](https://rubycentral.org/news/ruby-central-welcomes-new-software-engineer-in-residence-sponsored-by-aws/), has been sharing the highs, lows, and progress updates of his security work on his blog. Last month his development work included a new security event logging feature, a new gem research tool, a pure Ruby implementation of sigstore verification and more. You can learn more and follow along [here](https://blog.segiddins.me/?ref=rubycentral.org). Thank you to AWS for supporting this work!
### **New Jobs Added to Ruby Central Job Board**
- Did you know that we have a job board? It’s free to use, and finding and posting new positions is simple, quick and easy! Several new opportunities were added last week. Check it out[here.](https://rubycentral.jobboardly.com/?ref=rubycentral.org)
[](https://rubycentral.jobboardly.com/?ref=rubycentral.org)
### **Ruby Meet-ups News**
- **Directory coming soon:** We’re creating a directory of ALL active Ruby meetups to help us connect with one another, and so we can offer resources and support. **Everyone who joins will have their Meetup.com bill covered by Ruby Central!** Over 30 meet-ups have already signed up from Asia, Australia, South America, Europe, and all over North America! Click to fill out the form below and register your Ruby meet-up today.
- **Second Bay Area meetup: March 28!** Our first meetup was a success, so we're hosting another one; this time in collaboration with [Evil Martians](https://evilmartians.com/?ref=rubycentral.org). Join us on Thursday, March 28th, 2024 at GitHub HQ in the US! [RSVP here](https://www.meetup.com/san-francisco-ruby-meetup-group/events/299635202/?ref=rubycentral.org).

### **Upcoming Conferences**
- Ruby Central
- ICYMI the RailsConf program is live! Check it out and then join us this year in Detroit on May 7 - 9\. Conferencetickets are [on sale now](https://ti.to/railsconf/2024?ref=rubycentral.org)! ***Prices will be increasing after March 31st — so get your tickets now to lock in these early rates!***
- SAVE THE DATE. [RubyConf Chicago](https://rubyconf.org/?ref=rubycentral.org) will take place **Nov 13-15th at the Hilton Downtown Chicago!** If you're on our mailing list, you'll be the first to receive access to tickets when they go on sale. So tell all your #RubyFriends to sign up!
- Community Conferences
- April is chock-full of Ruby conferences in [Brazil](https://www.tropicalrb.com/?ref=rubycentral.org), [Australia](https://rubyincommon.org/?ref=rubycentral.org), [Australia again](https://2024.rubyconf.au/?ref=rubycentral.org)(!), [Poland](https://2024.wrocloverb.com/?ref=rubycentral.org) and [Bulgaria](https://balkanruby.com/?ref=rubycentral.org). Visit their event websites to find out more.
- [RubyKaigi 2024](https://rubykaigi.org/2024/?ref=rubycentral.org) (on May 15th) is looking for sponsors! **Apply** [**here**](https://sponsorships.rubykaigi.org/?ref=rubycentral.org) **before the end of March (some packages require an even earlier deadline)**.
- Updated information is always available at [rubyconferences.org](https://rubyconferences.org/?ref=rubycentral.org), which includes [a super-handy iCal feed](https://rubyconferences.org/calendar.ics?ref=rubycentral.org).
### **Get Involved**
- If you'd like to get involved and help make our community and events even better, we'd love to have you! Check out our [volunteer page](https://rubycentral.org/volunteer/), and/or feel free to[ shoot an email to our executive director, Adarsh](http://adarsh@rubycentral.org/), to find the best way to get plugged in.
- Want to promote your company at RailsConf or RubyConf in 2024? **Secure your sponsorship now** to reach all our attendees, showcase your thought leadership, and cultivate invaluable industry relationships by [emailing our wonderful sponsorships manager, Tom](http://tom@rubycentral.org/).
- Remember, you can receive exclusive benefits like conference discounts and more by signing up for a Ruby Central [membership](https://rubycentral.org/#/portal/signup). *Check to see if your employer matches donations to Ruby Central, Inc. through* [*Benevity*](https://causes.benevity.org/causes/840-300040446?ref=rubycentral.org) *and double your support!*
## **RubyGems News**
In February, RubyGems released RubyGems [3.5.6](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#356--2024-02-06) and Bundler [2.5.6](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#256-february-6-2024). These updates include enhancements such as [improved deep copy requirements in Gem::Specification and Gem::Requirement specifications](https://github.com/rubygems/rubygems/pull/7439?ref=rubycentral.org), and [improvements to the gem login scope](https://github.com/rubygems/rubygems/pull/7342?ref=rubycentral.org). These efforts are part of our ongoing commitment to improving the RubyGems development experience.
Another accomplishment from the team this month:
[**Merging a new gem rebuild command**](https://github.com/rubygems/rubygems/pull/4913?ref=rubycentral.org)
- The goal of this feature was to help create a simplified version of gem rebuild command as a standalone tool, so reproducible builds are available for existing RubyGems versions (since RubyGems versions have to match a build to be reproduced properly). The process involved setting up reproducible gem builds as a default, and including the Gem.source\_date\_epoch value into the metadata of built gems.
- The groundwork for this command involved a preliminary rebuild script to assess reproducibility requirements. Special thanks to [@duckinator](https://github.com/duckinator?ref=rubycentral.org) for their significant contributions in developing this feature.
In February, RubyGems gained [97 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2024-2-01%7D...master@%7B2024-2-31%7D?ref=rubycentral.org) contributed by 16 authors. There were 691 additions and 329 deletions across 120 files.
## **RubyGems.org News**
February’s updates to RubyGems.org reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform. Sponsored hosting for [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) in February was provided by [AWS](https://aws.amazon.com/?ref=rubycentral.org), [Fastly](https://www.fastly.com/?ref=rubycentral.org), and [DataDog](https://www.datadoghq.com/?ref=rubycentral.org).
The following are highlights of what the team worked on this month:
**Converted RubyGems.org to Importmap + Stimulus Controllers**
- The goal of adding stimulus controllers is to enable a modern, faster and simpler development experience for devs, and to bring us all the way up to the most modern Rails default.
- We introduced importmaps on RubyGems.org last month [creating a foundation for using stimulus.js](https://github.com/rubygems/rubygems.org/pull/4396?ref=rubycentral.org).
- Now we’ve now begun implementing stimulus controllers one at a time. We have added controllers for [navigation](https://github.com/rubygems/rubygems.org/pull/4419?ref=rubycentral.org), [API keys](https://github.com/rubygems/rubygems.org/pull/4418?ref=rubycentral.org) and [search autocomplete](https://github.com/rubygems/rubygems.org/pull/4468?ref=rubycentral.org).
- We also made a follow-up attempt at Stimulus best practices in the navigation controller. If you’re interested in learning more about some patterns that can improve your stimulus implementation, read some of the references we used[ here](https://www.betterstimulus.com/?ref=rubycentral.org) and [here](https://thoughtbot.com/blog/taking-the-most-out-of-stimulus?ref=rubycentral.org).
**Improving the Design of RubyGems Gems page**
- We are exploring and user testing a new design for the RubyGems.org site and in particular, the gem info page.
- The gem info page on RubyGems ranks as the most visited page of the website (for example, here’s [Bundler’s gem page](https://rubygems.org/gems/bundler?ref=rubycentral.org)). It is crucial to closely examine the needs of Ruby engineers and ensure that the page structure and design align with their objectives.
- Through interviews and discussions with RubyGems power users and stakeholders, we are identifying fundamental values of the interface elements, understand the reasons behind their development, track their evolution, and determine the most beneficial next steps for our broader user base.
- We are excited to start to share some of the new design work as soon as it is ready for a wider audience.
[**Initiating the Gem Research Tool Project**](https://blog.segiddins.me/2024/02/09/residency-update/?ref=rubycentral.org)
- This will be most relevant for RubyGems developers. The team will be able to use this as a playground for features that we want to expose to the public eventually, like browsing gem contents and being able to make queries. We also have been able to use this for security research to assess the impact of particular changes across the entire published gem ecosystem.
- The creation of this tool has involved (and will continue to involve) [a lot of investigation](https://blog.segiddins.me/2024/02/09/residency-update/?ref=rubycentral.org), experimentation and steps like renting a dedicated server from Hetzner to host the gem research tool, after repeatedly running out of disk space!
**Developing a Pure Ruby Sigstore Implementation**
- This project kicked off with a long-term goal of integrating it directly into RubyGems. The team is drawing inspiration from the existing sigstore and The Update Framework (TUF) implementations in Python.
- We intend to focus on meeting the sigstore compliance specifications through continuous iterations. Additionally, by analyzing code and branch coverage, we're identifying sections that need more extensive testing.
- A critical part of this project is creating a protobuf implementation that does not depend on native extensions, ensuring it can be seamlessly incorporated into RubyGems.
In February, RubyGems.org gained [86 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2024-2-01%7D...master@%7B2024-2-31%7D?ref=rubycentral.org) contributed by 13 authors. There were 5,265 additions and 2,022 deletions across 270 files.
## **Total spent**
In February we spent $101,322.02 on development work.
## **Thank you**
Thank you to all the contributors of RubyGems and RubyGems.org for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### **Contributors to RubyGems:**
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@VitaliySerov](https://github.com/VitaliySerov?ref=rubycentral.org) Vitaliy Serov
- [@flavorjones](https://github.com/flavorjones?ref=rubycentral.org) Mike Dalessio
- [@jgarber623](https://github.com/jgarber623?ref=rubycentral.org) Jason Garber
- [@kimesf](https://github.com/kimesf?ref=rubycentral.org) Kim Emmanuel
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@ccutrer](https://github.com/ccutrer?ref=rubycentral.org) Cody Cutrer
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@mame](https://github.com/mame?ref=rubycentral.org) Yusuke Endoh
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@dduugg](https://github.com/dduugg?ref=rubycentral.org) Douglas Eichelberger
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
### **Contributors to RubyGems.org:**
- [@jenshenny](https://github.com/jenshenny?ref=rubycentral.org) Jenny Shen
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
- [@sh0n0](https://github.com/sh0n0?ref=rubycentral.org) sh0n0
- [@coorasse](https://github.com/coorasse?ref=rubycentral.org) Alessandro Rodi
- [@CuddlyBunion341](https://github.com/CuddlyBunion341?ref=rubycentral.org) Daniel Bengl
- [@albertchae](https://github.com/albertchae?ref=rubycentral.org) Albert Chae
- [@bradly](https://github.com/bradly?ref=rubycentral.org) Bradly Feeley
- [@ekyburz](https://github.com/ekyburz?ref=rubycentral.org) EtienneKyburz
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
### Ruby Central Receives Alpha-Omega Grant
URL: https://rubycentral.org/news/ruby-central-receives-alpha-omega-grant/
Last updated: 2024-03-20T19:11:43.000Z
Ruby Central is thrilled to announce that we have been awarded a two part grant from[ Alpha-Omega](https://alpha-omega.dev/?ref=rubycentral.org). The $250,000 grant will support critical open source projects on RubyGems.org, RubyGems and Bundler.
Alpha-Omega is an OpenSSF associated project of the OpenSSF, established in February 2022, funded by Microsoft, Google, and Amazon, and with a mission to protect society by catalyzing sustainable security improvements to the most critical open source software projects and ecosystems.
Ruby Central maintains and operates RubyGems.org and the package tools RubyGems & Bundler. This vital infrastructure supports development across the Ruby ecosystem. RubyGems.org served 2.7 billion gem downloads and 11 million unique IPs last month. RubyGems.org has grown 20-25% per year every year for more than a decade and is accelerating.
**Projects funded**
The Alpha-Omega grant will fund development of one of the most requested RubyGems.org features: Organization Accounts. This will help developers that manage multiple gems to securely centralize gem access controls. This will benefit large gem owners like AWS and Shopify, as well as smaller organizations with fewer gems.
The grant will also fund a Security and Process Audit, which will include hiring a mutually agreed-upon security firm to audit the[ RubyGems.org](http://rubygems.org/?ref=rubycentral.org) servers, project, and processes, and remediate any issues discovered.
This work is in addition to the recent establishment of the [AWS funded Software Engineer in Residence](https://rubycentral.org/news/ruby-central-welcomes-new-software-engineer-in-residence-sponsored-by-aws/) for the RubyGems project.
You can follow this work as it develops, in the RubyGems GitHub organization & the Bundler slack. We will also share some updates on [rubycentral.org/news](https://rubycentral.org/news).You can follow along there or [sign up here](https://rubycentral.org/#/portal/signup) to receive occasional updates by email.
We are grateful to Alpha-Omega for recognizing the importance of Ruby Central’s work within the open source ecosystem and for their generous support.
If you want to inquire about sponsorship opportunities, please contact [oss@rubycentral.org](mailto:oss@rubycentral.org). Please direct media inquiries to media@rubycentral.org.
### A Technical and Practical Program: RailsConf 2024 Speakers Announced!
URL: https://rubycentral.org/news/a-technical-and-practical-program-railsconf-2024-speakers-announced/
Last updated: 2024-05-07T13:53:31.000Z
***This year’s line-up celebrates everyday developers that build with Ruby on Rails***
PASADENA, C.A. (March. 13, 2024) – RailsConf 2024 is the world's largest gathering of Rails developers, brought together to further discussion and learning about building, managing, and testing Rails applications. Long-time conference organizers, Ruby Central, Inc., have just announced the program for the 19th annual RailsConf. [Forty speakers have been chosen](https://railsconf.org/speakers/?ref=rubycentral.org) to present talks or workshops at the conference, which takes place from Tuesday, May 7 to Thursday, May 9 in Detroit, MI.
“This year’s speakers have been selected to give attendees real-life, practical, insights into building and running Rails apps and teams,” said Andy Croll, Co-chair, RailsConf 2024\. “The sort of knowledge folks can take back to their organizations and put into practice immediately.”
Of the 40 total talks, there are four keynote speakers:
- Aaron Patterson: Rails Core member and Shopify Senior Staff Engineer.
- Nadia Odunayo: Founder and CEO at [The StoryGraph](https://thestorygraph.com/?ref=rubycentral.org).
- Irina Nazarova: CEO at[ Evil Martians](https://evilmartians.com/?ref=rubycentral.org), co-founder of AnyCable.
- John Hawthorn: Member of the Ruby Core team, Rails Core team, and the author of Vernier, a new Ruby profiler.
Additional prominent Ruby community members, including members from the Rails Core team, RubyGems.org team, and maintainers of other open-source Rails-related projects will be leading new, hallway track events including a hack day and more. Details on these events will be announced soon.
This is the first year Ruby Central has invited someone from outside the organization to co-chair the conference. Andy Croll, CTO of [CoverageBook](https://coveragebook.com/?ref=rubycentral.org), creator of the [First Ruby Friend](https://firstrubyfriend.com/?ref=rubycentral.org) mentoring program, and organizer of [Brighton Ruby](https://brightonruby.com/?ref=rubycentral.org), joined the team last month. New Ruby Central board member Ufuk Kayserilioglu, Engineering Manager of the Ruby Infrastructure Team at Shopify, is co-chairing the event alongside him.
“Having that external perspective (from Andy) has been invaluable and it shows in the amazing speaker program, and the buzz from people excited to attend,” said Adarsh Pandit, Executive Director, Ruby Central. “Of course, I’m most excited to see RailsConf come to my hometown of Detroit. It’s an amazing city and I’m looking forward to sharing it with everyone.”
The full conference schedule is available [here](https://dd2f5325a2e4437c8198e5431d1df965.sessionize.com/schedule?ref=rubycentral.org). To learn more about RailsConf 2024, including pricing and registration, visit [https://railsconf.org/](https://railsconf.org/?ref=rubycentral.org).
###
**About Ruby Central**
Ruby Central is a non-profit organization dedicated to supporting and advancing the Ruby programming language and a welcoming and diverse worldwide Ruby community. To learn more, visit [https://rubycentral.org](https://rubycentral.org/).
### February 2024 Newsletter
URL: https://rubycentral.org/news/february-2024-newsletter/
Last updated: 2024-03-27T17:08:45.000Z
Hello! Welcome to the February newsletter. Read on for announcements from Ruby Central and a report of the OSS work we’ve done from the previous month. In January, Ruby Central's open source work was supported by 29 different companies, including [Fastly](https://www.fastly.com/?ref=rubycentral.org), [Sentry](https://sentry.io/welcome/?ref=rubycentral.org), Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org), and Partner-level member [Contributed Systems](https://contribsys.com/?ref=rubycentral.org), the company behind Mike Perham’s [Sidekiq](https://sidekiq.org/?ref=rubycentral.org). In total, we were supported by 178 members. Thanks to all of our members for making everything that we do possible. <3
## **Ruby Central News**
### Ruby Meet-ups
- **Directory coming soon!** We’re creating a directory of ALL active Ruby meetups to help us connect with one another, and so we can offer resources and support. Click to fill out the form below and register your Ruby meet-up today!
- **Bay Area meetup in March!** Our first sponsored meetup is starting Friday March 1st, 2024 in the SF Bay Area in the US with a low-key ramen lunch hosted by Ruby Central’s Adarsh Pandit! [RSVP here](https://www.meetup.com/san-francisco-ruby-meetup-group/events/299362383/?ref=rubycentral.org).
[](https://docs.google.com/forms/d/e/1FAIpQLSePGZc9kLJHAsYSSrlFrY5LDje99w8ozepHn2p3QKnAhcBaJQ/viewform?ref=rubycentral.org)
### **RubyConf 2023 Recap Report**
[We published a report last week](https://rubycentral.org/news/a-look-back-at-rubyconf-2023-featuring-the-brand-new-community-day/) capturing every part of RubyConf 2023, from the innovative new additions to the program – Community Day and Open Spaces — to our attendee demographics, to the finances it took to make it happen. Enjoy this walk with us down memory lane to see what you missed, or re-live the fun – pictures included!
### **Upcoming Conferences:**
- Ruby Central
- RailsConf is fast approaching, this year in Detroit on May 7 - 9\. Conferencetickets are [on sale now!](https://ti.to/railsconf/2024?ref=rubycentral.org)
- This year's RubyConf will be in Chicago! Dates and locations are being finalized right now... Stay tuned.
- Community Conferences
- [Sin City Ruby 2024](https://www.sincityruby.com/?ref=rubycentral.org) is taking place March 21–22, 2024 in Las Vegas, NV.
- April is chock-full of Ruby conferences in[ Brazil](https://www.tropicalrb.com/?ref=rubycentral.org),[ Australia](https://rubyincommon.org/?ref=rubycentral.org),[ Australia again(!)](https://2024.rubyconf.au/?ref=rubycentral.org),[ Poland](https://2024.wrocloverb.com/?ref=rubycentral.org) and[ Bulgaria](https://balkanruby.com/?ref=rubycentral.org). Visit their event websites to find out more.
- [RubyKaigi 2024](https://rubykaigi.org/2024/?ref=rubycentral.org) (on May 15th) is looking for sponsors! **Apply**[ **here**](https://sponsorships.rubykaigi.org/?ref=rubycentral.org) **before the end of March (some packages require an even earlier deadline)**.
- Updated information is always available at [rubyconferences.org](https://rubyconferences.org/?ref=rubycentral.org), which includes [a super-handy iCal feed](https://rubyconferences.org/calendar.ics?ref=rubycentral.org).
### **Get Involved:**
- If you'd like to get involved and help make our community and events even better, we'd love to have you! Check out our[ volunteer page](https://rubycentral.org/volunteer/), and/or feel free to [shoot an email to our executive director, Adarsh](http://adarsh@rubycentral.org/), to find the best way to get plugged in.
- Want to share your brand at RailsConf or RubyConf in 2024? **Secure your sponsorship now** to reach over 500 attendees, showcase your thought leadership, and cultivate invaluable industry relationships by [emailing our wonderful sponsorships manager, Tom](http://tom@rubycentral.org/).
- Remember, you can receive exclusive benefits like conference discounts and more by signing up for a Ruby Central[ membership](https://rubycentral.org/#/portal/signup). *Check to see if your employer matches donations to Ruby Central, Inc. through*[ *Benevity*](https://causes.benevity.org/causes/840-300040446?ref=rubycentral.org) *and double your support!*
## **RubyGems News**
In January in RubyGems, we released RubyGems [3.5.5](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#355--2024-01-18) and Bundler [2.5.5](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#255-january-18-2024). These releases included fixes to: [the caching specifictions directory](https://github.com/rubygems/rubygems/pull/7331?ref=rubycentral.org), [development dependency ommission](https://github.com/rubygems/rubygems/pull/7358?ref=rubycentral.org) and [formatting of compact index requests headers](https://github.com/rubygems/rubygems/pull/7352?ref=rubycentral.org), as part of our continuous effort to enhance the Ruby development experience.
Some other important accomplishments from the team this month include:
**Resolution of Bundler issue with Renovatebot**
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) addressed a specific Bundler resolution problem affecting the operation of Renovatebot. We try to place nice with update bots since they contribute to a more healthy and secure ecosystem. Renovate in particular does not seem to use Bundler internals, but runs Bundler directly through well defined CLI flags. This is very good for us, so it’s nice to give back and make sure the CLI flags they use work as expected. The issue happens when Renovatebot first changes the Gemfile and then runs bundle lock –update –patch –strict.
- He first investigated a solution that involved bringing the lockfile up to date but ultimately realized that this approach breaks the --patch --strict contract because it results in that patch level version possibly being upgraded. In the end, he decided to call the current behavior as expected and will focus on improving the error message in the future. - ([7369](https://github.com/rubygems/rubygems/issues/7369?ref=rubycentral.org)).
**Resolution of RubyGems require issue**
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) tackled a challenging issue within RubyGems related to its custom require implementation. The gemification of default gems, especially those with dependencies, unveiled issues post Ruby 3.3 release, affecting user experience. The fix ensures RubyGems require bypasses activating default versions of gems under conflict-prone conditions. For more details, see [#7379](https://github.com/rubygems/rubygems/pull/7379?ref=rubycentral.org).
**Work toward vendoring URI in RubyGems**
- This initiative was part of efforts to smooth out the extraction of default gems from ruby-core, ensuring a seamless transition. The successful vendoring of URI marks a significant step towards mitigating activation conflicts. Information on this update is available in [#7386](https://github.com/rubygems/rubygems/pull/7386?ref=rubycentral.org).
**Addressing an ENV resetting issue in RubyGems**
- Restoring Bundler-related ENV variables to empty prevents downstream issues related to trying to invoke Bundler from subprocesses, as one of our users [Edouard-chin](https://github.com/Edouard-chin?ref=rubycentral.org) pointed out. An investigation led to the identification of a bug related to special casing empty ENV variables. The decision was made to remove this exception and the fix. Its implications are detailed in [#7383](https://github.com/rubygems/rubygems/pull/7383?ref=rubycentral.org).
**Introduction of a Gem Rebuild Command**
- [Ellen Dash](https://github.com/duckinator?ref=rubycentral.org) is leading the development of a gem rebuild command to facilitate reproducible builds. Reproducible builds allow people to identify problems such as compromised build environments or builds not using the published source. For a few years now, it’s been technically possible to reproduce a build if you knew enough about the original build environment. The gem rebuild command’s purpose is to automate as much of this as possible.
In January, RubyGems gained [163 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2024-1-01%7D...master@%7B2024-1-31%7D?ref=rubycentral.org) contributed by 18 authors. There were 6,051 additions and 1,059 deletions across 244 files.
## **RubyGems.org News**
January's updates to [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform.
The following are highlights of what the team worked on this month:
**Resolution of a multi-factor authentication (MFA) bypass on password reset vulnerability**
A vulnerability report from HackerOne brought to our attention a critical flaw in the MFA process during password reset. This issue was addressed and resolved through the collaborative efforts of [Martin Emde](https://github.com/martinemde?ref=rubycentral.org), with significant contributions from [Josef Šimánek](https://github.com/simi?ref=rubycentral.org), [Samuel Giddins](https://github.com/segiddins?ref=rubycentral.org), and [Eric](https://github.com/ericherscovich?ref=rubycentral.org). [Read more about the report here.](https://github.com/rubygems/rubygems.org/security/advisories/GHSA-4v23-vj8h-7jp2?ref=rubycentral.org)
**Audit/Event Logging for Enhanced Security Monitoring**
- We introduced a user-visible log of security events that have happened on their account. This will help maintainers stay on top of how their account is being used, and events that happen on the gems they own, reducing mean time to remediation for unexpected actions. This also helps the [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) security team by providing a trail that can be followed in response to security incidents.
- Critical events such as logins, password changes, email updates, API token generation and revocation, and ruby gem ownership changes are now logged. These logs are user-specific for account activities, while gem-related events are accessible to all owners of the respective gem. Check out [#4367](https://github.com/rubygems/rubygems.org/pull/4367?ref=rubycentral.org) for more information.
**RubyGems.org is now using importmaps**
- **Importmaps** is a modern approach to serving JavaScript utilizing HTTP2 to transfer many smaller files rather than bundling JavaScript into a single large file. The result is a much lighter asset build system and better caching of assets that don’t change very often. During development, [@martinemde](https://github.com/martinemde?ref=rubycentral.org) worked through package management challenges with importmaps (e.g. verifying provenance, pushed upstream here: [importmap-rails#237](https://github.com/rails/importmap-rails/pull/237?ref=rubycentral.org)). You may not have realized that **importmap-rails is a package manager**, like bundler or npm, and should be managed as one. - [(rubygems.org#4396)](https://github.com/rubygems/rubygems.org/pull/4396?ref=rubycentral.org).
**Fixing a bug in rack-test related to Content-Security-Policy nonces**
- During the development work on **importmaps** a small bug in rack-test was identified and fixed. The bug manifested through failing tests triggered when generating Content-Security-Policy nonces from a session\_id. The resolution involved fixing how these cookies are processed in rack-test [(rack-test#343)](https://github.com/rack/rack-test/pull/343?ref=rubycentral.org) and preventing blank cookies from being recorded in rubygems.org.
**Updating to Rails 7.1**
- We updated [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) to Rails 7.1 to keep dependencies of the Rails app up to date. The update involved a long-running pull request that addressed dependency issues. The merge and deployment proceeded smoothly after ensuring all upstream dependencies supported Rails 7.1, along with an update to the Rails configuration to align with 7.1 defaults.
**Soft Deleting User Records**
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) implemented a feature for soft-deleting user records, a foundational step for the audit/event logging system. This ensures the preservation of database relationships for historical records referencing users, even after an account is deleted by the user.
- When a user requests account deletion, we clear out all user information from the user record and mark it as deleted, but leave the row in the database. Deleted records are not shown in queries on the site. Find more information about this update in [#4376](https://github.com/rubygems/rubygems.org/pull/4376?ref=rubycentral.org) and [#3766](https://github.com/rubygems/rubygems.org/pull/3766?ref=rubycentral.org).
**Check out an example of the new audit logging in rubygems.org**

In January, [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) gained [85 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2024-1-01%7D...master@%7B2024-1-31%7D?ref=rubycentral.org) contributed by 8 authors. There were 2,490 additions and 1,238 deletions across 224 files.
## **Total spent**
In January, we spent $65,352.52 on development work.
## **Thank you**
Thank you to all the contributors of RubyGems and [RubyGems.org](http://rubygems.org/?ref=rubycentral.org) for this month! Your contributions are greatly appreciated, and we are grateful for your support. And thank you to the [German Sovereign Tech Fund](https://www.sovereigntechfund.de/?ref=rubycentral.org) (STF) for their generous support of our Bundler and RubyGems work.
### **Contributors to RubyGems:**
- [@mrkn](https://github.com/mrkn?ref=rubycentral.org) Kenta Murata
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@hyuraku](https://github.com/hyuraku?ref=rubycentral.org) hyuraku
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@avdi](https://github.com/avdi?ref=rubycentral.org) Avdi Grimm
- [@ccutrer](https://github.com/ccutrer?ref=rubycentral.org) Cody Cutrer
- [@bravehager](https://github.com/bravehager?ref=rubycentral.org) Brave Hager
- [@stanhu](https://github.com/stanhu?ref=rubycentral.org) Stan Hu
- [@ntkme](https://github.com/ntkme?ref=rubycentral.org) なつき
- [@olleolleolle](https://github.com/olleolleolle?ref=rubycentral.org) Olle Jonsson
- [@ohbarye](https://github.com/ohbarye?ref=rubycentral.org) Masato Ohba
- [@williantenfen](https://github.com/williantenfen?ref=rubycentral.org) Willian Tenfen Wazilewski
- [@m-nakamura145](https://github.com/m-nakamura145?ref=rubycentral.org) Masato Nakamura
### **Contributors to** [**RubyGems.org**](http://rubygems.org/?ref=rubycentral.org)**:**
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@robbyrussell](https://github.com/robbyrussell?ref=rubycentral.org) Robby Russell
- [@a5-stable](https://github.com/a5-stable?ref=rubycentral.org) B3
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
### A Look Back at RubyConf 2023, Featuring the Brand New Community Day!
URL: https://rubycentral.org/news/a-look-back-at-rubyconf-2023-featuring-the-brand-new-community-day/
Last updated: 2024-02-21T20:41:48.000Z

**Catherine Ricafort McCreary, of Artists Who Code, and Ruby veteran Aaron Patterson take their bows after a surprise, Ruby-themed musical number. Photo by San Diego Conference Photography.*
To all of our attendees, speakers, volunteers, sponsors, vendors and the staff at the [Town and Country Resort](https://www.towncountry.com/?ref=rubycentral.org), thanks for helping us make RubyConf 2023, a huge success! Over 500 Rubyists joined us in San Diego from Monday November 13th through Wednesday November 15th for the 23rd annual RubyConf, and experienced our brand new format. Read on to soothe some of your FOMO if you missed it, or relive all the fun you had with us there!
0:00
/1:38
1×
**RubyConf 2023 Recap. Video by ConFreaks.*
**Who attended**
A combined total of 573 people joined us on site for this year’s conference, from 21 different US states and 10 different countries! About 47% of our attendees were senior developers, 19% mid-level developers, 12% junior developers, 8% (people) managers, and 1% students. We were so excited to welcome 20 wonderful [Scholars](https://rubyconf.org/team?ref=rubycentral.org#scholars-guides) to their first RubyConf ever. And we streamed a portion of the talks for 144 virtual attendees who couldn’t join us but wanted to be a part of the live conference experience.
**Community Day**
In response to feedback from attendees at previous events, this year’s RubyConf experimented with a new, innovative format. Instead of three full days of talks, we kicked off on Day One with a day of community building, hacking and collaborating, sprinkled with a few workshops. This Hack Day featured projects led by members of core Ruby teams, including:
- CRuby, led by Jemma Issroff, Kevin Newton, Aaron Patterson, Matt Valentine-House, and Peter Zhu
- Hanami, led by Tim Riley
- Natalie, led by Tim Morgan
- RubyGems.org, led by Sam Giddins and Jenny Shen
- The IRB and Debug core gems led by Stan Lo
- The Ruby LSP, led by Vinicius Stock Alexandre Terrasa and Andy Waite
- The Faker gem, led by Stefanni Brasil and Thiago Araujo

**The Faker Gem Hack Day Table. Photo by San Diego Conference Photography..*
**Conference talks**
RubyConf 2023 featured 21 total talks and workshops, including three keynote speakers:
Yukihiro “Matz” Matsumoto, creator of the [Ruby programming language](https://www.ruby-lang.org/en/?ref=rubycentral.org), discussed how the successes and pitfalls of other popular programming languages over the past few decades, have informed how he designs Ruby. He also offered his advice and vision for the future of Ruby, with or without Matz at the helm!

**Matz's keynote video. Photo by San Diego Conference Photography.*
Sharon Steed, author and founder of [Communilogue](https://www.communilogue.co/?ref=rubycentral.org), told her story about how overcoming her fear of public speaking with a speech impediment was key to mastering, and teaching about, vulnerability and empathy as skills for success in the workplace.

**Sharon Steed's keynote talk. Photo by San Diego Conference Photography.*
Saron Yitbarek, developer, entrepreneur, and founder of [CodeNewbie](https://community.codenewbie.org/?ref=rubycentral.org), shared how the overwhelming challenges of teaching herself to code ignited her journey to creating a more inclusive space, and more effective tools, for new software developers, highlighting the power of Ruby community support that helped her get to where she is today.

**Saron Yitbarek's keynote talk. Photo by San Diego Conference Photography.*
**Open Spaces**
In addition to talks, Open Spaces served as on-site meetups for conference goers with similar passions in the Ruby world to continue the conversations, collaboration and hacking that started on Community Day. Spaces were hosted for Ruby meetup organizers, Ruby content creators, Ruby implementers and Ruby open source teams.

**Rubyists enjoying Open Spaces. Photo by San Diego Conference Photography.*
**Hearing from you!**
Out of the 128 RubyConf 2023 goers who responded to our survey, 46% told us this was your first RubyConf and 27% of you told us this was your first Ruby Central event, ever!
66% of you participated in some combination of Community day and Open Spaces. There was a lot you appreciated about this new conference format. You enjoyed the opportunity to build community, hack and have actual PRs created on some of your projects. Here’s more of what you loved about RubyConf’s new Community Day and Open Spaces events:
- “Please do more community days and open spaces in the future! It's a very interesting format, much more hands-on and collaborative than just watching a talk. Talks are great too, but I also loved the community building aspect of RubyConf.”
- “This was the best part of the conference. I had such a blast hanging out with Ruby luminaries and hacking on cool stuff. I must admit, I was skeptical at first, but I would love to see community day happen again.”
- “It was great to have experts on the same table and being able to ask them questions.”
- “Having the community day first also helped breaking the ice as a first-time attendee.”
We also heard your feedback about what we could do better next time, to make things easier and more productive for you all. We look forward to working on improvements like providing descriptions of the projects available to contribute to during Community Day and Open Spaces, structured facilitation of the Open Spaces sessions and more intentionality with the timing of the hacking and open space sessions to allow for maximum participation in the conference by attendees and Open Spaces hosts alike.
*Live podcast recordings*
As is often the case, we had several Ruby content creators attend the conference and capture their experience, live — which means we got to hear from a few of you as you were taking it all in. Elise Shaffer, of the Ruby on Rails Podcast, talked with several RubyConf first-timers in between conference sessions who shared their favorite conference moments, and advice for new conference goers.
A total of six podcast episodes were recorded live at RubyConf 2023! Check them out:
- [Ruby for All - Live From Rubyconf 2023](https://overcast.fm/+7OLTis6qM?ref=rubycentral.org)
- [The Ruby on Rails Podcast - Live from the hallway track](https://www.therubyonrailspodcast.com/496?ref=rubycentral.org)
- [The Rooftop Ruby Podcast - Live at RubyConf 2023](https://www.rooftopruby.com/2108545/14006920?ref=rubycentral.org)
- [Software Sessions - Mayra Navarro on Getting to RubyConf](https://www.softwaresessions.com/episodes/getting-to-rubyconf/?ref=rubycentral.org)
- [Software Sessions - Mike Perham on Keeping it solo](https://www.softwaresessions.com/episodes/keeping-it-solo/?ref=rubycentral.org)
- [Software Sessions - Sara Jackson on Teaching in Kanazawa](https://www.softwaresessions.com/episodes/teaching-in-kanazawa/?ref=rubycentral.org)
**Finances**
Starting with this conference, we are going to share some of our event finances, to help you understand more about what things cost and how the ticket prices are set. Transparency is an important value for us at Ruby Central and we want to be more open about how things work internally. (Note: these are directional numbers to give you an overall sense of how things work behind the scenes).
*Revenue*
Our total revenue for RubyConf 2023 was $477k, with $301k coming from ticket sales and $176k from our sponsorship partners. Typically, we see equal amounts of revenue from sponsorship and ticket sales. However during 2023 our sponsorship partners were less able to support the event due to economic challenges in the tech industry.
When we have low sponsorship, it makes finances more challenging, but more importantly, we know the attendees feel that loss as well. When event sponsorship is low, we have to make up that loss in revenue by either selling more tickets or increasing our ticket price. Also, it was felt by having a more empty exhibit hall and not as many companies to meet and mingle with. We know that our conference goers want to meet with companies excited to hire them or collaborate with them and it's frustrating or disheartening when they aren't there.
We are hoping for a change in this trend and are preparing as much as we can if it doesn’t change. If your company is interested in sponsoring our next event, please contact our sponsor lead [Tom Chambers](mailto:tom@rubycentral.org) (tom@rubycentral.org).
*Expenses*
On the cost side, we spent $462k altogether producing the event, which made this the first in-person Ruby Central event since 2019 which turned a profit. The biggests costs were catering ($171k), staff for the event ($96k), event production vendors ($83k), and honoraria/scholarships ($48k), with administrative costs including software, WiFi, security, swag, shirts, and travel making up the balance. More than ever before, our team worked very hard to get these expenses down, both to minimize our financial risk as well as reduce our ticket prices as much as we possibly could.
Going forward, we are experimenting with ways to lower our costs while delivering an even more fun event - things like selecting non-traditional venues, trying different lunch ideas like food trucks, offering sponsorships to software vendors in lieu of payment, and using local vendor partners to reduce trucking expenses.
I’m sure you can guess that putting on a conference is a lot of hard work, especially in the past few years, but the team putting on RubyConf 2023 was one of the best we have ever had!
**Thank you!**
For more pictures from RubyConf 2023, [click here](https://www.sandiegoconferencephoto.com/rubyconf-23-full-gallery?ref=rubycentral.org), and check out our [RubyConf twitter page](https://twitter.com/rubyconf?ref=rubycentral.org) for another look back at all the action.
Conference talks and workshop replays are available now! Visit the [Ruby Central YouTube page](https://www.youtube.com/@RubyCentral?ref=rubycentral.org) to watch.
And to get the scoop on even MORE Ruby Central events — including RubyConf 2024 in Chicago — sign up for our [member newsletter](https://rubycentral.org/#/portal/signup) and connect with us on [twitter](https://twitter.com/rubycentralorg?ref=rubycentral.org), [mastodon](https://ruby.social/home?ref=rubycentral.org) and [LinkedIn](https://www.linkedin.com/company/ruby-central-inc/?ref=rubycentral.org). And don’t hesitate to drop us an old fashioned line: [hello@rubycentral.org](mailto:hello@rubycentral.org). We love hearing from you.
Thanks for re-living the magic with us. We can’t wait to connect with you again in 2024!

**The RubyConf 2023 stage. Photo by San Diego Conference Photography.*
### Meet RailsConf 2023 Scholar: Dominic Lizarraga
URL: https://rubycentral.org/news/meet-railsconf-2023-scholar-dominic-lizarraga/
Last updated: 2026-05-05T22:17:15.000Z
Thinking of applying to this year's RailsConf [Scholars and Guides program](https://rubycentral.org/scholars%5Fguides%5Fprogram/)? Read on to hear from last year's Scholars about what it was like and why you should take the leap and apply!

### Name:
Dominic Lizarraga
### Professional Title:
Software Developer
### How did you get into Ruby?
Attending Le Wagon bootcamp.
### Are there any Ruby projects you're working on that you're excited about?
I'm very into Keto, glucose control, morning stretching and want to develop a small app for those topics.
### Why did you decide to join the Scholars/Guides program?
It was a big event and I knew that going on my own would not be easy because English is my second language and also because I'm a junior dev so I thought I can ease the onboarding process by applying to scholar program and it did :)
### What was the highlight of the conference for you?
Meeting new people, juniors, managers, etc and being mindful that the big minds behind rails are humans as well.
### What surprised you, if anything about your RailsConf2023 experience?
The staff is incredible, well-coordinated, always open to answer your questions, the community is accessible, don't matter your background.
### Any advice for first-time conference attendees?
Don't be afraid to talk to someone who you don't know, they are very friendly, they never make you feel bad and who knows maybe there is a potential new employer and partnership.
### Any other final thoughts?
Great experience, I have no words to describe it, every single moment was unforgettable, the community is amazing and I'm really convinced to keep helping in any way I can and hope to be sharing good news soon, thank you all for doing this possible :)
### *Thank you Dominic for sharing your story! Feeling ready to apply to be a Scholar or Guide? Sign up* [*here*](https://rubycentral.org/scholars%5Fguides%5Fprogram/) *today!*
### Meet RailsConf 2023 Scholar: Michelle Yuen
URL: https://rubycentral.org/news/meet-railsconf-2023-scholar-michelle-yuen/
Last updated: 2024-03-01T20:06:18.000Z
Thinking of applying to this year's RailsConf [Scholars and Guides program](https://rubycentral.org/scholars%5Fguides%5Fprogram/)? Read on to hear from last year's Scholars about what it was like and why you should take the leap and apply!

### Name:
Michelle Yuen
### Professional Title:
Backend Developer for Adler Planetarium
### How did you get into Ruby?
I was introduced to Ruby while working on an apprenticeship in Chicago called The Difference Engine. When I landed my first coding job, I left the Ruby world and went into Salesforce Development. I left Salesforce development because I was not happy being limited to the proprietary languages and tools that Salesforce provides. I was looking to do more work in open source, which led me to the Adler Planetarium in Chicago. There I was happy to see that they use Ruby on Rails to build their main backend for the Zooniverse, their citizen science platform.
### Are there any Ruby projects you're working on that you're excited about?
I was truly inspired by Andy Croll's talk on Taylor's Guide to Big Rewrites. Not to give anything away, but I have named this project the Enhanced Running Average Stats Service (ERAS Service for short); and I will be following in the footsteps of someone who currently is on tour with the same tour name. ;)
### Why did you decide to join the Scholars/Guides program?
I learned of the Scholars and Guides program from my First Ruby Friend, Mina. She convinced me that I should apply since the program would aid with some of my professional development goals: mainly networking/making professional connections but also getting advice on how to improve myself as a developer. This was my first RailsConf and I knew pretty much no one and no other developer from my team was attending so it felt like a good opportunity to meet people in a more structured setting.
### What was the highlight of the conference for you?
I have many highlights for this conference from dinners at the Slutty Vegan to chatting with some speakers post their session.
But I think my top highlight was my lightning talk. My guide and his colleague convinced me to sign up for one during the scholars and guides reception (and I'm so glad they did!). After my lightning talk, I got to make a connection with an experienced dev who started their Rails career with the platform that I am currently working on (The Zooniverse). I got to learn more about my team and the Zooniverse infrastructure and how much it has changed in the past 10 years.
### What surprised you, if anything about your RailsConf2023 experience?
I was surprised and pretty shocked to find out that I could understand, or at least follow along to 60-70% of all the more technical talks and to know that even super experienced devs also get the imposter syndrome feeling.
### Any advice for first-time conference attendees?
Don't be afraid to take breaks if needed. A lot of sessions are recorded and the conference can be a bit overwhelming, so feel free to take the time to do what you need to do to recharge.
Dinner is the best place to meet and connect with other people. Someone is always posting about getting a group together for dinner on the RailsConf slack somewhere; feel free to join.
If you're a coffee addict, like myself, and are ok with free conference coffee, know that free coffee is only available in the morning before the keynote and during lunch. Depending on where the conference is held, most places are strict about taking down the coffee stations at the given times. :(
Lots of people like to hang out in the hotel lobby until super late in the night (or even til the wee hours o' morning, hehe), don't feel obligated to stay out late unless you want to. Feel free to say hi and go to bed whenever you want.
### Any other final thoughts?
RailsConf was super fun and I hope to do this again (either as a scholar or as a guide). Check out my [lightning talk](https://youtu.be/k55B4ydueGE?si=JCIpbjKOYSLB0Tar&t=81&ref=rubycentral.org). If you're looking for a volunteering opportunity and interested in helping out in active research projects, check out the https://www.zooniverse.org platform.
### *Thank you Michelle for sharing your story! Feeling ready to apply to be a RailsConf 2024 Scholar or Guide? Sign up* [*here*](https://rubycentral.org/scholars%5Fguides%5Fprogram/) *today! The application deadline is February 20th.*
### Meet RailsConf 2023 Scholar: Rae Stanton
URL: https://rubycentral.org/news/meet-railsconf-2023-scholar-rae-stanton/
Last updated: 2024-02-02T19:00:02.000Z
Thinking of applying to this year's RailsConf [Scholars and Guides program](https://rubycentral.org/scholars%5Fguides%5Fprogram/)? Read on to hear from last year's Scholars about what it was like and why you should take the leap and apply!

### Name:
Rae Stanton
### Professional Title:
Software Developer
### How did you get into Ruby?
I got into Ruby after deciding that I wanted to make a career switch. Ruby/Rails was recommended to me as a great starting point, so that's where the journey began.
### Are there any Ruby projects you're working on that you're excited about?
Currently, I am working on contributing to Ruby for Good open source projects! I love diving into new territory and debugging and solving issues as I grow my skill set.
### Why did you decide to join the Scholars/Guides program?
I wanted to connect with someone during the conference who could give some great personalized insights on the conference and also personally.
### What was the highlight of the conference for you?
Some of the people I met were so great, and we have continued to connect past the conference. There are a few people that really want to elevate newcomer experiences.
### What surprised you, if anything about your RailsConf2023 experience?
I think it was surprising to see just how many people feel the same fears I do, but also just how welcoming the rails space is overall.
### Any advice for first-time conference attendees?
Just go! You never know who you'll meet. Definitely make sure you're staying a hotel close by or at the conference location so you can easily grab dinner or hang out with people. Don't be too afraid to put yourself out there.
### Any other final thoughts?
Conferences like this can be so overwhelming, but RailsConf in particular really brought a good variety of interesting talks and fun opportunities to meet like-minded people. Watch recordings if you need a break and make a note of them so you know which ones to find later. Try to go to talks or workshops that challenge you - it may not stick right away, but you can always make a note and research those things later on. Go out at least once. Fly in a day before and leave the day after if you can swing it - it definitely makes for a less stressful experience so you can focus on connections, learning, and having the best experience you possibly can.
### *Thank you Rae for sharing your story! Feeling ready to apply to be a RailsConf 2024 Scholar or Guide? Sign up* [*here*](https://rubycentral.org/scholars%5Fguides%5Fprogram/) *today! The application deadline is February 20th.*
### Listen to RailsConf 2024 co-chair Andy Croll on Code and the Coding Coders who Code it!
URL: https://rubycentral.org/news/listen-to-railsconf-2024-co-chair-andy-croll-on-code-and-the-coding-coders-who-code-it/
Last updated: 2024-01-31T20:02:16.000Z
Andy Croll joined Drew Bragg on his podcast last week and let us in on what it’s been like diving head-first into planning [RailsConf 2024](https://railsconf.org/?ref=rubycentral.org). He shared what he's doing to bring a little of the Brighton Ruby flavor to this year’s RailsConf, what the team is looking for in the CFP submissions, and more!
Check out the episode [here](https://podcast.drbragg.dev/episodes/episode-32-andy-croll?ref=rubycentral.org), and make sure to [get your CFP submission in](https://sessionize.com/railsconf2024/?ref=rubycentral.org) by **Feb. 13th**.
### Meet RailsConf 2023 Scholar: Kaylah Rose Mitchell
URL: https://rubycentral.org/news/meetrailsconf2023scholarkaylah/
Last updated: 2026-04-28T23:35:30.000Z
Thinking of applying to this year's RailsConf [Scholars and Guides program](https://rubycentral.org/scholars%5Fguides%5Fprogram/)? Read on to hear from last year's Scholars about what it was like and why you should take the leap and apply!

### Name:
Kaylah Rose Mitchell
### Professional Title:
Software Engineer
### How did you get into Ruby?
I got into Ruby after attending the Turing School of Software & Design.
### Are there any Ruby projects you're working on that you're excited about?
I am currently maintaining a travel application that allows you to collaborate with friends, make itineraries based on travel destination, track flights in real time, and more. Additionally, I have begun contributing to Camping, an open-source micro framework.
### Why did you decide to join the Scholars/Guides program?
I decided to join the Scholars/Guides program because I am aligned with the mission to provide opportunities for people who are underrepresented in tech. Additionally, I am excited for the opportunity to one day be a Guide with the program that supported me.
### What was the highlight of the conference for you?
My highlight of the conference was meeting Chris Oliver with GoRails. His work has helped me tremendously during my time in school. I received excellent advice, and encouragement, and made a genuine professional connection.
### What surprised you, if anything about your RailsConf2023 experience?
While the industry has a ways to go, I was overjoyed to see what I believed to be a great deal more diversity and representation at RailsConf compared to the rest of the industry.
### Any advice for first-time conference attendees?
Speak to as many new people as you are able to! Everyone is excited to be there and excited for you to be there also. Ask questions and practice the art of following up!
### Any other final thoughts?
Thank you to the incredible team at Ruby Central for this opportunity. Thank you to the guides for being our anchors and supports, and thank you to the scholars for putting themselves out there.
### *Thank you Kaylah Rose for sharing your story! Feeling ready to apply to be a Scholar or Guide? Sign up* [*here*](https://rubycentral.org/scholars%5Fguides%5Fprogram/) *today!*
### January 2024 Newsletter
URL: https://rubycentral.org/news/january-2023-newsletter/
Last updated: 2024-03-27T17:08:36.000Z
Hello! Welcome to the January newsletter. Read on for announcements from Ruby Central and a report of the OSS work we’ve done from the previous month. In December, Ruby Central's open source work was supported by 29 different companies, including [Fastly](https://www.fastly.com/?ref=rubycentral.org), [Sentry](https://sentry.io/welcome/?ref=rubycentral.org), Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org), and brand-new Partner-level member [Contributed Systems](https://contribsys.com/?ref=rubycentral.org), the company behind Mike Perham’s incredibly popular [Sidekiq](https://sidekiq.org/?ref=rubycentral.org). In total, we were supported by 178 members. Thanks to all of our members for making everything that we do possible. <3
## **Ruby Central News**
### **Upcoming Conferences:**
- Ruby Central
- [The CFP for RailsConf 2024](https://sessionize.com/railsconf2024?ref=rubycentral.org) in Detroit on May 7 - 9 is open!!! **Submit your proposal by Feb 13 to be considered.** Conferencetickets are [on sale now too](https://ti.to/railsconf/2024?ref=rubycentral.org).
- This year's RubyConf will be in Chicago! More details to come in the following months. Stay tuned.
- Community Conferences
- [Ruby Warsaw Community Conference 2024](https://www.rubycommunityconference.com/?ref=rubycentral.org) is happening February 2, 2024 in Warsaw, Poland.
- [Ruby devroom at FOSDEM 2024](https://fosdem.rubybelgium.be/?ref=rubycentral.org) will be held February 3–4, 2024 in Brussels, Belgium.
- [Sin City Ruby 2024](https://www.sincityruby.com/?ref=rubycentral.org) is taking place March 21–22, 2024 in Las Vegas, NV.
- [RubyKaigi 2024](https://rubykaigi.org/2024/?ref=rubycentral.org) (on May 15th) is looking for sponsors! **Apply** [**here**](https://sponsorships.rubykaigi.org/?ref=rubycentral.org) **before the end of March (some packages require an even earlier deadline)**.
### **Get Involved:**
- If you'd like to get involved and help make our community and events even better, we'd love to have you! Check out our [leadership page](https://rubycentral.org/leadership/), and/or feel free to [shoot an email to our executive director, Adarsh](adarsh@rubycentral.org), to find the best way to get plugged in.
- Want to share your brand at RailsConf or RubyConf in 2024? Secure your sponsorship now to reach over 500 attendees, showcase your thought leadership, and cultivate invaluable industry relationships by [emailing our wonderful sponsorships manager, Tom](tom@rubycentral.org).
- Remember, you can receive exclusive benefits like conference discounts and more by signing up for a Ruby Central [membership](https://rubycentral.org/#/portal/signup). **NEW:* Check to see if your employer matches donations to Ruby Central, Inc. through* [*Benevity*](https://causes.benevity.org/causes/840-300040446?ref=rubycentral.org) *and double your support!*
## **RubyGems News**
In December, we released the following version of RubyGems [3.5.0](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#350--2023-12-15), [3.5.1](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#351--2023-12-15), [3.5.2](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#352--2023-12-21), [3.5.3](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#353--2023-12-22), and Bundler [2.5.0](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#250-december-15-2023), [2.5.1](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#251-december-15-2023), [2.5.2](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#252-december-21-2023), [2.5.3](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#253-december-22-2023). These updates mark significant milestones in our continuous effort to enhance the RubyGems development experience.
With the yearly minor version release of RubyGems 3.5 and Bundler 2.5, we have dropped support for Ruby versions less than 3.0.0\. This enables the usage of more modern features of the Ruby language; improving efficiency, performance and memory usage. It also reduces our test runtimes and removes the more error prone Ruby 2.6 and 2.7 tests. We spent time this month modernizing the codebase to take advantage of this change.
A major enhancement was made to the `generate_index command`. It now has the capability to create compact index files. This feature has been integrated into the externally available `rubygems-generate_index` gem ([#7085](https://github.com/rubygems/rubygems/pull/7085?ref=rubycentral.org)). This advancement not only improves efficiency but also extends the command's utility.
The `gem install` command also saw an important update. To better accommodate environments where permissions might be restricted, it now automatically uses the user’s installation directory when the default `gem home` is not writable ([#5327](https://github.com/rubygems/rubygems/pull/5327?ref=rubycentral.org)).
Additionally, [Bundler](https://bundler.io/?ref=rubycentral.org) introduced the `bundle config set version` feature. This allows users to explicitly select the Bundler version they wish to use, adding a layer of customization. It also provides the option to override the lockfile version by setting it to `system` ([#6817](https://github.com/rubygems/rubygems/pull/6817?ref=rubycentral.org)).
Some other improvements that landed into our repo this month that are NOT included in the above releases are:
- an upgraded documentation process, now utilizing [nronn](https://github.com/n-ronn/nronn?ref=rubycentral.org) for generation ([#7227](https://github.com/rubygems/rubygems/pull/7227?ref=rubycentral.org)).
- the use of `Minitest::TestTask` in a template file for minitest streamlining the testing process ([#7234](https://github.com/rubygems/rubygems/pull/7234?ref=rubycentral.org)).
- avoidance of some allocations when evaluating `ruby` Gemfile DSL ([#7251](https://github.com/rubygems/rubygems/pull/7251?ref=rubycentral.org)).
- better install advice when some gems are not found ([#7265](https://github.com/rubygems/rubygems/pull/7265?ref=rubycentral.org)).
- implementation of a fix for the `bundler test` on the Ruby package ([#7298](https://github.com/rubygems/rubygems/pull/7298?ref=rubycentral.org)).
- a call to make `bundle lock` always touch the lockfile (even when nothing changed) to improve Make-style compatibility ([#7220](https://github.com/rubygems/rubygems/pull/7220?ref=rubycentral.org)).
- improved RubyGems and Bundler CI detection ([#7205](https://github.com/rubygems/rubygems/pull/7205?ref=rubycentral.org)).
- streamed output from ext builds when `--verbose` ([#7240](https://github.com/rubygems/rubygems/pull/7240?ref=rubycentral.org)).
- allowing `bundle pristine` to run in parallel, resulting in a remarkable speed improvement ([#6927](https://github.com/rubygems/rubygems/pull/6927?ref=rubycentral.org)).
- ensuring gem install respects system umask ([#7300](https://github.com/rubygems/rubygems/pull/7300?ref=rubycentral.org)).
In December, RubyGems gained [280 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2023-12-01%7D...master@%7B2023-12-31%7D?ref=rubycentral.org) contributed by 17 authors. There were 28,544 additions and 8,338 deletions across 761 files.
## **RubyGems.org News**
December's updates to RubyGems.org reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform.
A significant upgrade made was the complete transition to Ruby 3.3, ([#4320](https://github.com/rubygems/rubygems.org/pull/4320?ref=rubycentral.org)). This update represents a major step in keeping the platform current with the latest Ruby advancements.
We also added improvements to the [trusted publishing](https://blog.rubygems.org/2023/12/14/trusted-publishing.html?ref=rubycentral.org) feature. Notably, the pending publisher link is now visible to everyone in the settings edit section ([#4290](https://github.com/rubygems/rubygems.org/pull/4290?ref=rubycentral.org)). Additionally, we added integration of passkeys as a single factor of authentication, this marks a significant improvement in security of the platform ([#4271](https://github.com/rubygems/rubygems.org/pull/4271?ref=rubycentral.org)).
Some other improvements that landed into our repo this month that are NOT included in the above releases are:
- implementation of `Deletion#version_id` for better version association ([#4273](https://github.com/rubygems/rubygems.org/pull/4273?ref=rubycentral.org)).
- resolution to issues in creating Rubygem trusted publishers when GitHub actions exist ([#4282](https://github.com/rubygems/rubygems.org/pull/4282?ref=rubycentral.org)).
- an added `/profile/me` action that redirects logged-in users to their profile ([#4291](https://github.com/rubygems/rubygems.org/pull/4291?ref=rubycentral.org)).
- an update to Bundler 2.5.1 with the addition of CHECKSUMS ([#4296](https://github.com/rubygems/rubygems.org/pull/4296?ref=rubycentral.org)).
- addition of `ruby/setup-ruby` for switching RubyGems versions ([#4298](https://github.com/rubygems/rubygems.org/pull/4298?ref=rubycentral.org)).
In December, RubyGems.org gained [54 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2023-12-01%7D...master@%7B2023-12-31%7D?ref=rubycentral.org) contributed by 7 authors. There were 4,096 additions and 510 deletions across 139 files.
## **Total spent**
In December, we completed 523 hours of development work and spent $78,333.85.
## **Thank you**
Thank you to all the contributors to RubyGems and RubyGems.org since last month! Your contributions are greatly appreciated, and we are grateful for your support.
### **Contributors to RubyGems:**
- [@nevinera](https://github.com/nevinera?ref=rubycentral.org) Eric Mueller
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@franzliedke](https://github.com/franzliedke?ref=rubycentral.org) Franz Liedke
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@junaruga](https://github.com/junaruga?ref=rubycentral.org) Jun Aruga
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@y-yagi](https://github.com/y-yagi?ref=rubycentral.org) y-yagi
- [@eregon](https://github.com/eregon?ref=rubycentral.org) Benoit Daloze
- [@voxik](https://github.com/voxik?ref=rubycentral.org) Vít Ondruch
- [@osyoyu](https://github.com/osyoyu?ref=rubycentral.org) Daisuke Aritomo
- [@etherbob](https://github.com/etherbob?ref=rubycentral.org) Andrew Stevenson
- [@AndrewSwerlick](https://github.com/AndrewSwerlick?ref=rubycentral.org) Andrew Swerlick
- [@amomchilov](https://github.com/amomchilov?ref=rubycentral.org) Alexander Momchilov
- [@hogelog](https://github.com/hogelog?ref=rubycentral.org) hogelog
- [@takmar](https://github.com/takmar?ref=rubycentral.org) Takuma Yoshida
- [@ekohl](https://github.com/ekohl?ref=rubycentral.org) Ewoud Kohl van Wijngaarden
- [@iuriguilherme](https://github.com/iuriguilherme?ref=rubycentral.org) Iuri Guilherme
- [@MSP-Greg](https://github.com/MSP-Greg?ref=rubycentral.org) MSP-Greg
- [@kenyon](https://github.com/kenyon?ref=rubycentral.org) Kenyon Ralph
### **Contributors to RubyGems.org:**
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@ntkme](https://github.com/ntkme?ref=rubycentral.org) なつき
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@jenshenny](https://github.com/jenshenny?ref=rubycentral.org) Jenny Shen
- [@paracycle](https://github.com/paracycle?ref=rubycentral.org) Ufuk Kayserilioglu
### Ruby Central leadership opportunity: social media volunteers
URL: https://rubycentral.org/news/socialmediavolunteers/
Last updated: 2024-01-23T16:39:11.000Z
Hi #RubyFriends! We’re creating a volunteer-based team to help us get Rubyists excited about RailsConf 2024 and other upcoming events. Please check out the list of positions below to see if any of them speak to you.
- **Social media writer:** \~2-3 hours a week to support our social media process. Your tasks will mostly consist of updating the social copy we have, writing new copy as needed, and occasional related projects. The tools you will use are Asana and Buffer. Experience with these platforms is not necessary as our process is very simple and we’re happy to walk you through it!
- **Social media street team:** as needed support of 2-3 social media campaigns per conference by sharing/boosting - we’ll provide you with guidance on timing and copy.
- **Social media butterfly:** as needed. Make sure we’re following all the right Ruby influencers on our platforms to stay up to date on community conversations. Experience with/knowledge of the Ruby community is preferred for this role.
The only other requirements are a little familiarity with Twitter, Mastodon and LinkedIn and a burning desire to get Rubyists excited about Ruby events :)
**Perks:** Not only will you feel accomplished for contributing to the success of Ruby Central and the Ruby community, as a thank you we will offer you a significant discount to our upcoming RailsConf 2024 and a RailsConf T-shirt!
**Apply:** If you’re interested, please complete this[ volunteer application form](https://docs.google.com/forms/d/e/1FAIpQLSf5EZXRHmcdGw0QTXte9osX3lMY2cI8%5FChh7RK4o93iDLi9Pg/viewform?ref=rubycentral.org) and we’ll follow up with next steps. Feel free to pass this on to anyone else you know who might be a good fit.
Thanks for your support! <3
### State of the Ruby Gems
URL: https://rubycentral.org/news/state-of-the-ruby-gems/
Last updated: 2024-01-17T20:03:08.000Z
We’re proud to say RubyGems.org’s uptime has been uninterrupted for **over 8 and a half years** since Ruby Together, and then Ruby Central, began funding maintenance on RubyGems. With 147,326,326,048 total gem downloads, 181,745 users, and an average of 2 billion requests per weekday as of October 2023, this has been no easy feat. Security Lead on RubyGems and [Ruby Central’s AWS Security Engineer in Residence](https://rubycentral.org/news/ruby-central-welcomes-new-software-engineer-in-residence-sponsored-by-aws/) Samuel Giddins [gave a talk](https://www.youtube.com/watch?v=Hea-x7LHO9Y&ref=rubycentral.org) at RubyConf 2023 outlining the history of the vital gem hosting service used by Rubyists every day, and all that it has taken to “keep the lights on” at RubyGems.org, then and now.

**This graph shows the total bytes served from the Rails app each day (through October). When we disabled the dependency API (not used by Bundler since 2016), we saw an astonishing and unexpected spike in traffic from 8, 9, and 10-year-old versions of Bundler*
In his talk he highlighted, by the numbers, the impact that RubyGems has had on the Ruby ecosystem worldwide, and how it has been maintained from its creation at RubyConf 2004 to its current state in 2023\. He shared the challenges open source contributors have faced through RubyGems’ growing pains, including recurring security issues, precarious infrastructure and the lack of an official, dedicated support team for RubyGems.org.
He also outlined the accomplishments RubyGems/Bundler and RubyGems.org contributors achieved in 2023 in spite of all this — shipping new features, like a beta version of \`bundle compose\`, merging hundreds of pull requests, and migrating towards managing infrastructure as code — all to make the developer experience better for both users and maintainers.
Finally, he shared a vision for new projects and goals that are on the horizon and ready to begin as soon as consistent support is made possible via sponsors and growth of our Ruby central membership. We are on the way to introducing cutting edge best practices around security and code provenance — like [completing our trusted publishing project](https://blog.rubygems.org/2023/12/14/trusted-publishing.html?ref=rubycentral.org) — and projects that improve the quality of life for gem developers, like increased gem information and in-browser gem playgrounds, among several others.
He made clear that the continued growth, security and health of RubyGems is expensive, and relies not only on many groups of consistent volunteer contributors, but server and infrastructure services, paid part-time developers and organizational costs totaling around $500,000 a month — all handled by Ruby Central. These expenses would not be manageable without the support of Ruby Central’s individual and company members, and our Open Source Sustaining Membership sponsors.

**This graph shows Ruby Central's weekly AWS Costs in 2023 (through October)*
The Ruby community has never let us down, and we look forward to continuing to grow and improve the RubyGems service with your support! You can support our work and goals simply by watching and sharing this talk, spreading the word about Ruby Central’s work and events or[ getting even more involved in ways that work for you](https://rubycentral.org/support/). Thanks in advance for helping us improve the Ruby ecosystem for everyone.
### December 2023 Newsletter
URL: https://rubycentral.org/news/december-2023-newsletter/
Last updated: 2024-01-24T15:19:50.000Z
Hello! Welcome to the December newsletter. Read on for announcements from Ruby Central and a report of the OSS work we’ve done from the previous month. In November, Ruby Central's open source work was supported by 35 different companies, including[ Fastly](https://www.fastly.com/?ref=rubycentral.org),[ Sentry](https://sentry.io/welcome/?ref=rubycentral.org), Ruby Shield sponsor[ Shopify,](https://www.shopify.com/?ref=rubycentral.org) and brand-new Partner-level member [Contributed Systems](https://contribsys.com/?ref=rubycentral.org), the company behind Mike Perham’s incredibly popular Sidekiq. In total, we were supported by 187 members. Thanks to all of our members for making everything that we do possible. <3
## **Ruby Central News**
### **RubyConf 2023:**
- The official conference videos are live! Check out all of the talks on our[ youtube channel](https://www.youtube.com/@RubyCentral?ref=rubycentral.org) to relive the RubyConf magic.
### **RubyConfTW 2023:**
- Congratulations to RubyGems/Bundler and [RubyGems.org](https://t.co/vvJD9gGDzF?ref=rubycentral.org) core maintainers Hiroshi Shibata and Samuel Giddins, who presented at RubyConf Taiwan last weekend! Find out more about their talks [here](https://2023.rubyconf.tw/?ref=rubycentral.org).
### **Upcoming Conferences:**
- Ruby Central
- RailsConf 2024 in Detroit on May 7 - 9 will be here in a flash! [Tickets are on sale now](https://ti.to/railsconf/2024?ref=rubycentral.org)!
- Next year's RubyConf will be in...Chicago! More details to come in the following months. Stay tuned.
- Community Conferences
- [Ruby Warsaw Community Conference 2024](https://www.rubycommunityconference.com/?ref=rubycentral.org) is happening February 2, 2024 in Warsaw, Poland.
- [Ruby devroom at FOSDEM 2024](https://fosdem.rubybelgium.be/?ref=rubycentral.org) will be held February 3–4, 2024 in Brussels, Belgium.
- [Sin City Ruby 2024](https://www.sincityruby.com/?ref=rubycentral.org) is taking place March 21–22, 2024 in Las Vegas, NV.
### **Get Involved:**
- If you'd like to get involved and help make our community and events even better, we'd love to have you! Check out our[ leadership page](https://rubycentral.org/leadership/), and/or feel free to [shoot an email to our executive director, Adarsh](mailto:adarsh@rubycentral.org), to find the best way to get plugged in.
- Want to share your brand at RailsConf or RubyConf in 2024? Secure your sponsorship now to reach over 500 attendees, showcase your thought leadership, and cultivate invaluable industry relationships by [emailing our wonderful sponsorships manager, Tom](mailto:tom@rubycentral.org).
- Remember, you can receive exclusive benefits like conference discounts and more by signing up for a Ruby Central[ membership](https://rubycentral.org/#/portal/signup).
## **RubyGems News**
During November in RubyGems, we released RubyGems[ 3.4.22](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3422--2023-11-09) and Bundler[ 2.4.22](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2422-november-9-2023). These updates are part of our continuous effort to enhance the Ruby development experience.
One of the key changes is a boost in performance, achieved by eliminating the need for regular expression matches in `Gem::Platform.local` ([#7104](https://github.com/rubygems/rubygems/pull/7104?ref=rubycentral.org)). Additionally, we shipped an update of the SPDX license list, ensuring that RubyGems is in line with the most recent industry standards ([#7040](https://github.com/rubygems/rubygems/pull/7040?ref=rubycentral.org)).
Another important update: The YAML serializer has been enhanced to correctly handle empty arrays ([#7099](https://github.com/rubygems/rubygems/pull/7099?ref=rubycentral.org)). The search process has also been refined, now effectively ignoring .gem files that are not in tar format ([#7095](https://github.com/rubygems/rubygems/pull/7095?ref=rubycentral.org)). The update also brings a new feature that allows users to uninstall multiple versions of the same gem at once, making gem management more efficient ([#7063](https://github.com/rubygems/rubygems/pull/7063?ref=rubycentral.org)).
Some other improvements that landed into our repo this month that are NOT included in the above releases are:
- an added response body on `fetch_http error` ([#7148](https://github.com/rubygems/rubygems/pull/7148?ref=rubycentral.org)).
- a more robust writability check for gem home ([#7211](https://github.com/rubygems/rubygems/pull/7211?ref=rubycentral.org)).
- an update to the Magnus library in the Rust extension gem template ([#7204](https://github.com/rubygems/rubygems/pull/7204?ref=rubycentral.org)).
- an update to gem uninstall error reporting ([#7149](https://github.com/rubygems/rubygems/pull/7149?ref=rubycentral.org)).
- locked gem versions for C extension dependencies ([#7161](https://github.com/rubygems/rubygems/pull/7161?ref=rubycentral.org)).
- an added `--json` output option to bundle-outdated ([#7167](https://github.com/rubygems/rubygems/pull/7167?ref=rubycentral.org)).
- a fix for invalid platform removal omitting adjacent platforms ([#7170](https://github.com/rubygems/rubygems/pull/7170?ref=rubycentral.org) ).
- fixed universal lockfiles regression ([#7177](https://github.com/rubygems/rubygems/pull/7177?ref=rubycentral.org)).
- dropped Ruby 2.6 and 2.7 support ([#7116](https://github.com/rubygems/rubygems/pull/7116?ref=rubycentral.org)).
- fixed bundle install `--system` deprecation advice ([#7190](https://github.com/rubygems/rubygems/pull/7190?ref=rubycentral.org)).
- no longer remembering cli flags like `--jobs` or `--retry` in configuration ([#7191](https://github.com/rubygems/rubygems/pull/7191?ref=rubycentral.org)).
- an added option for missing `--prefer-local` to Synopsis in bundle-install.1.ronn ([#7194](https://github.com/rubygems/rubygems/pull/7194?ref=rubycentral.org)).
- allowing auto-install to install missing git gems ([#7197](https://github.com/rubygems/rubygems/pull/7197?ref=rubycentral.org)).
- ensuring explicit requirement of `rubygems` ([#7139](https://github.com/rubygems/rubygems/pull/7139?ref=rubycentral.org)).
In November, RubyGems gained[ 113 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2023-11-01%7D...master@%7B2023-11-31%7D?ref=rubycentral.org) contributed by 23 authors. There were 1,875 additions and 56,824 deletions across 1,496 files.
## **RubyGems.org News**
The updates to RubyGems.org in November reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform.
One of the updates made was to upgrade to Postgresql 12 and updated production and staging `DATABASE_URL` to PostgreSQL 12 instance ([#4245](https://github.com/rubygems/rubygems.org/pull/4245?ref=rubycentral.org),[ #4256](https://github.com/rubygems/rubygems.org/pull/4256?ref=rubycentral.org)).
Some other improvements that landed into our repo this month that are NOT included in the above releases are:
- a fix for deletion `version_id` backfill when a user is deleted ([#4259](https://github.com/rubygems/rubygems.org/pull/4259?ref=rubycentral.org)).
- an added `version_id` column to Deletions ([#4254](https://github.com/rubygems/rubygems.org/pull/4254?ref=rubycentral.org)).
- an added[ trusted publishers](https://blog.rubygems.org/2023/12/14/trusted-publishing.html?ref=rubycentral.org) feature to help automate gem publishing ([#4239](https://github.com/rubygems/rubygems.org/pull/4239?ref=rubycentral.org)).
- fixed `api_key_created email` when API key belongs to an OIDC id token ([#4233](https://github.com/rubygems/rubygems.org/pull/4233?ref=rubycentral.org)).
- an added `maintenance_task` to backfill info files into S3 ([#4232](https://github.com/rubygems/rubygems.org/pull/4232?ref=rubycentral.org)).
- use of an uncached query to compute compact index info in jobs ([#4231](https://github.com/rubygems/rubygems.org/pull/4231?ref=rubycentral.org)).
- an added job to refresh all OIDC provider configs every 30m ([#4211](https://github.com/rubygems/rubygems.org/pull/4211?ref=rubycentral.org))
- extraction of verified session logic into a concern ([#4210](https://github.com/rubygems/rubygems.org/pull/4210?ref=rubycentral.org)).
- updated installation instructions OS X ([#4203](https://github.com/rubygems/rubygems.org/pull/4203?ref=rubycentral.org)).
- an upgrade of shoryuken to version 5.x ([#4166](https://github.com/rubygems/rubygems.org/pull/4166?ref=rubycentral.org)).
In November, RubyGems.org gained[ 83 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2023-11-01%7D...master@%7B2023-11-31%7D?ref=rubycentral.org) contributed by 7 authors. There were 950 additions and 501 deletions across 109 files.
## **Total spent**
In November, we completed 450 hours of development work and spent $67,395.73.
## **Thank you**
Thank you to all the contributors of RubyGems and RubyGems.org for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### **Contributors to RubyGems:**
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@hanyang-tony](https://github.com/hanyang-tony?ref=rubycentral.org) Hanyang tony
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@voxik](https://github.com/voxik?ref=rubycentral.org) Vít Ondruch
- [@Paul-Bob](https://github.com/Paul-Bob?ref=rubycentral.org) Paul Bob
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@eregon](https://github.com/eregon?ref=rubycentral.org) Benoit Daloze
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@Bo98](https://github.com/Bo98?ref=rubycentral.org) Bo Anderson
- [@nevinera](https://github.com/nevinera?ref=rubycentral.org) Eric Mueller
- [@Maumagnaguagno](https://github.com/Maumagnaguagno?ref=rubycentral.org) Mau Magnaguagno
- [@olleolleolle](https://github.com/olleolleolle?ref=rubycentral.org) Olle Jonsson
- [@ggmichaelgo](https://github.com/ggmichaelgo?ref=rubycentral.org) Michael Go
- [@adrianthedev](https://github.com/adrianthedev?ref=rubycentral.org) Adrian Marin
- [@kstevens](https://github.com/kstevens715?ref=rubycentral.org) Kyle Stevens
- [@dearblue](https://github.com/dearblue?ref=rubycentral.org) Dearblue
### **Contributors to RubyGems.org:**
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi Shibata
- [@jp524](https://github.com/jp524?ref=rubycentral.org) Jade
### Ruby Central welcomes new board members
URL: https://rubycentral.org/news/ruby-central-welcomes-new-board-members/
Last updated: 2024-01-08T18:22:19.000Z
We’re excited to announce four new members to our board of directors! Please join us in welcoming…

Kinsey Ann Durham, Software Engineer on the Deploys Team at GitHub, will be supporting Ruby Central Major Gifts.

David Corson-Knowles, Staff Engineer at Gusto, will also be supporting Ruby Central Major Gifts.

Ben Greenberg, Head of DevRel at Fuel Network, will be supporting the Ruby Central Membership Program.

Ufuk Kayserilioglu, Engineering Manager of the Ruby Infrastructure Team at Shopify, will be the RailsConf 2024 Co-chair.
These new members will be replacing long-time board members Marty Haught and Jonan Scheffler, who are stepping down from the board after many wonderful years of service. We wish Marty and Jonan a fond farewell, and we look forward to working together with our new team to expand our support of the Ruby community in 2024 and beyond!
### Ruby Central welcomes new Software Engineer in Residence, sponsored by AWS
URL: https://rubycentral.org/news/ruby-central-welcomes-new-software-engineer-in-residence-sponsored-by-aws/
Last updated: 2024-06-21T04:48:33.000Z

Ruby Central is very excited today to announce that Samuel Giddins has joined as the organization’s first open source employee as a Security Engineer in Residence. This residency is made possible thanks to support from [Amazon Web Services](https://aws.amazon.com/?ref=rubycentral.org) (AWS).
Software supply chain security has become increasingly important for companies over the past few years, due to [attackers of all sizes, up to nation-state actors, exploiting supply chain vulnerabilities to breach critical secure systems](https://en.wikipedia.org/wiki/2020%5FUnited%5FStates%5Ffederal%5Fgovernment%5Fdata%5Fbreach?ref=rubycentral.org). Projects like RubyGems and RubyGems.org play a crucial role in providing a secure ecosystem for millions of open source Ruby users around the world.
“The hiring of a full-time W2 employee working on open source software marks a major milestone in the growth of Ruby Central and our community. We are finding sustainable ways to write software for the community, and that’s very exciting for all of us,” said Adarsh Pandit, Ruby Central’s Executive Director.
RubyGems is a package management framework for Ruby. [RubyGems.org](https://rubygems.org/?ref=rubycentral.org) is the Ruby community’s gem hosting service. Historically, RubyGems was staffed by volunteers, then occasionally paid contract contributors, and now regularly paid contract contributors through funding from other entities. This hire marks the first time any individual will be working full-time on RubyGems, and a new era of maturity for the Ruby package ecosystem.
“I’ve been working on RubyGems for almost a decade,” said Giddins. “I’m excited to be able to focus my full attention on combining a focus on security and user experience to help make the Ruby packaging ecosystem the most secure and easiest to use software ecosystem. Full-time work will enable me to both dig into substantial projects that are hard to tackle with scattered time, as well as develop a holistic approach to modernizing the RubyGems ecosystem’s security posture and gain community buy-in and adoption for this work.”
Giddins will spend the next year focused on improving the security posture of the Ruby packaging ecosystem, with a broad focus on making the most secure option the easiest option. His responsibilities will include evangelizing and improving accessibility of security features forRubyGems users, and pushing the RubyGems ecosystem towards adopting industry standard security frameworks (such as Sigstore, SLSA, in-toto, OIDC, webauthn, and many more acronyms).
Much of the work that Giddins will be doing will be in the open, in the RubyGems GitHub organization & the Bundler slack. He will be posting updates to [rubycentral.org/news](https://rubycentral.org/news), so you can follow along there or [sign up here](https://rubycentral.org/#/portal/signup) to receive occasional updates by email.
This role wouldn’t be possible without a generous grant from AWS, the world’s most comprehensive and broadly adopted cloud.
If you want to inquire about sponsorship opportunities, please contact [sponsors@rubycentral.org](mailto:sponsors@rubycentral.org). Please direct media inquiries to [media@rubycentral.org](mailto:iirene@rubycentral.org).
### Adarsh Pandit, Executive Director
URL: https://rubycentral.org/news/executive-director/
Last updated: 2023-12-01T17:01:28.000Z
Adarsh joined us as Executive Director starting in May, 2023\. He is a long time Ruby Central participant and volunteer.
He is the founder and managing partner of the Ruby design studio, Cylinder Digital, where he led a multi-year collaboration with Code for America.
Previously, Adarsh was Managing Director for the San Francisco office of the acclaimed Ruby studio, thoughtbot.
### November 2023 Newsletter
URL: https://rubycentral.org/news/october-2023-monthly-update/
Last updated: 2023-12-27T17:56:40.000Z
Hello! Welcome to the November newsletter. Read on for announcements from Ruby Central and a report of the OSS work we’ve done from the previous month. In October, Ruby Central's open source work was supported by 35 different companies, including[ Fastly](https://www.fastly.com/?ref=rubycentral.org), [Sentry](https://sentry.io/welcome/?ref=rubycentral.org), Ruby member[ Zendesk](https://zendesk.com/?ref=rubycentral.org) and Ruby Shield sponsor[ Shopify](https://www.shopify.com/?ref=rubycentral.org). In total, we were supported by 182 members. Thanks to all of our members for making everything that we do possible. <3
## **Ruby Central News**

### **RubyConf 2023:**
- This year's [RubyConf](http://rubyconf.org/?ref=rubycentral.org) was a success! Thank you all so much for joining us, bringing all your joy and good energy, and helping to make it such a wonderful time.
- The playbacks of the talks will be posted on our [youtube channel](https://www.youtube.com/@RubyCentral?ref=rubycentral.org) in a few weeks, so stay tuned. In the meantime, we'd love to hear your thoughts about the event: what you liked and what we can do to make next year's event even better. [Please fill out this survey](https://www.surveymonkey.com/r/rubyconf23-survey?ref=rubycentral.org) and share your feedback, it means a lot to us.
- You can also relive some of this year's RubyConf vibes via [the Ruby on Rails](https://www.therubyonrailspodcast.com/496?ref=rubycentral.org), [Software Sessions](https://www.softwaresessions.com/?ref=rubycentral.org) and [Rooftop Ruby](https://www.rooftopruby.com/2108545/14006920?ref=rubycentral.org) podcasts, who recorded live episodes on-site. Thank you for helping share the amazing things our Ruby community is doing, with the world.
- Last but not least, thank you to our RubyConf 2023 [sponsors](https://rubyconf.org/sponsors?ref=rubycentral.org)! We couldn't have made this all happen without you.
### **Upcoming Conferences:**
- Ruby Central
- RailsConf 2024 in Detroit on May 7 - 9 will be here in a flash! [Tickets are on sale now](https://ti.to/railsconf/2024?ref=rubycentral.org)!
- Next year's RubyConf will be in...Chicago! More details to come in the following months. Stay tuned.
- Community Conferences
- [RubyConf Taiwan 2023](https://2023.rubyconf.tw/?ref=rubycentral.org) is coming up December 15–16, 2023 in Taipei, Taiwan
- [Ruby Warsaw Community Conference 2024](https://www.rubycommunityconference.com/?ref=rubycentral.org) is happening February 2, 2024 in Warsaw, Poland
- [Ruby devroom at FOSDEM 2024](https://fosdem.rubybelgium.be/?ref=rubycentral.org) will be held February 3–4, 2024 in Brussels, Belgium
### **Get Involved:**
- A lot of you at RubyConf told us you'd like to get involved and help make our community and events even better. We're so excited to hear this! Check out our[ leadership page](https://rubycentral.org/leadership/), and/or feel free to [shoot an email to our executive director, Adarsh](mailto:adarsh@rubycentral.org), to find the best way to get plugged in.
- Want to share your brand at RailsConf or RubyConf in 2024? Secure your sponsorship now to reach over 500 attendees, showcase your thought leadership, and cultivate invaluable industry relationships by [emailing our wonderful sponsorships manager, Tom](mailto:tom@rubycentral.org).
- Remember, you can receive exclusive benefits like conference discounts and more by signing up for a Ruby Central[ membership](https://rubycentral.org/#/portal/signup).
### **New newsletter format!**
- We’ve made a small update to our format. (You may have noticed the slight change to the title already). Our newsletter each month will now include a wider range of updates that may span more than just the previous month. You’ll see this most reflected in our OSS report in the following section.
- This will allow us to bring you ALL of the most up to date news from both Ruby Central’s OSS and operational teams. It will hopefully also improve the quality of the release notes we bring to you, in terms of timing and usefulness. We hope this helps!
## **RubyGems News**
During October in RubyGems, we released RubyGems[ 3.4.21](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3421--2023-10-17) and Bundler[ 2.4.21](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2421-october-17-2023).
A couple of noteworthy updates this month include the introduction of a feature to abort setup.rb for outdated Ruby versions ([#7011](https://github.com/rubygems/rubygems/pull/7011?ref=rubycentral.org)), and efficiency enhancements enabled by removing Dir.chdir from subprocess execution ([#6930](https://github.com/rubygems/rubygems/pull/6930?ref=rubycentral.org)). We also achieved a major configuration improvement by implementing a pure-ruby YAML parser ([#6615](https://github.com/rubygems/rubygems/pull/6615?ref=rubycentral.org)). The documentation also saw significant improvements, with updates to the bindir variable ([#7028](https://github.com/rubygems/rubygems/pull/7028?ref=rubycentral.org)) and fixes to invalid links ([#7008](https://github.com/rubygems/rubygems/pull/7008?ref=rubycentral.org)).
Some other improvements that landed into our repo this month that are NOT included in the above releases are:
- an enhanced continuous integration (CI) by incorporating the latest patch level releases of Ruby, ensuring more robust testing environments ([#7036](https://github.com/rubygems/rubygems/pull/7036?ref=rubycentral.org)).
- updates to the SPDX license list to reflect the latest standards as of October 5, 2023\. This ensures compliance and accuracy in licensing ([#7040](https://github.com/rubygems/rubygems/pull/7040?ref=rubycentral.org)).
- improved formatting and presentation of global source information on the bundle plugin manual page, contributing to better usability and readability ([#7045](https://github.com/rubygems/rubygems/pull/7045?ref=rubycentral.org)).
- significant optimization by reusing the Gem::RemoteFetcher instance within Bundler[ (#7079](https://github.com/rubygems/rubygems/pull/7079?ref=rubycentral.org)).
- modified, more relaxed, pattern matching for Rake versions, allowing for greater flexibility and compatibility in different environments ([#7123](https://github.com/rubygems/rubygems/pull/7123?ref=rubycentral.org)).
- refinements to the recent fix related to force\_ruby\_platform ([#7115](https://github.com/rubygems/rubygems/pull/7115?ref=rubycentral.org)).
- enabled automatic switching to user-level gem installations when GEM\_HOME is unset and the default gem home is not writable ([#5327](https://github.com/rubygems/rubygems/pull/5327?ref=rubycentral.org)).
In October, RubyGems gained[ 160 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2023-10-01%7D...master@%7B2023-10-31%7D?ref=rubycentral.org) contributed by 22 authors. There were 3,940 additions and 1,149 deletions across 197 files.
## **RubyGems.org News**
The updates to RubyGems.org in October reflect a strong commitment to improving user experience, enhancing security, and modernizing the platform. Here's a brief overview of the key improvements in the release:
- implementing a fix for the subscription links on the RubyGems dashboard ([#4111](https://github.com/rubygems/rubygems.org/pull/4111?ref=rubycentral.org)).
- creating a proof-of-concept for integrating Tailwind CSS, aiming to modernize and enhance the frontend design and responsiveness of RubyGems ([#4113](https://github.com/rubygems/rubygems.org/pull/4113?ref=rubycentral.org)).
- resolving ambiguity in ownership uniqueness errors, specifically addressing scenarios where a user is already invited or is an owner ([#4119](https://github.com/rubygems/rubygems.org/pull/4119?ref=rubycentral.org)).
- addressing a critical issue where users who had pushed gems with associated API keys faced difficulties with account deletion. This fix ensures smoother user account management and security ([#4130](https://github.com/rubygems/rubygems.org/pull/4130?ref=rubycentral.org)).
- fixing timestamp fields options feature, refining user interface elements and data accuracy ([#4132](https://github.com/rubygems/rubygems.org/pull/4132?ref=rubycentral.org)).
In October, RubyGems.org gained[ 60 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2023-10-01%7D...master@%7B2023-10-31%7D?ref=rubycentral.org) contributed by 12 authors. There were 4,532 additions and 2,184 deletions across 181 files.
## **Total spent**
In October, we completed 436 hours of development work and spent $65,431.60.
## **Thank you**
Thank you to all the contributors of RubyGems and RubyGems.org for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### **Contributors to RubyGems:**
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@mgmarlow](https://github.com/mgmarlow?ref=rubycentral.org) Graham Marlow
- [@harshalbhakta](https://github.com/harshalbhakta?ref=rubycentral.org) Harshal Bhakta
- [@composerinteralia](https://github.com/composerinteralia?ref=rubycentral.org) Daniel Colson
- [@manuraj17](https://github.com/manuraj17?ref=rubycentral.org) Manu
- [@intrip](https://github.com/intrip?ref=rubycentral.org) Jacopo Beschi
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
- [@ccutrer](https://github.com/ccutrer?ref=rubycentral.org) Cody Cutrer
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@kstevens715](https://github.com/kstevens715?ref=rubycentral.org) Kyle Stevens
- [@mercedesb](https://github.com/mercedesb?ref=rubycentral.org) Mercedes
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@dearblue](https://github.com/dearblue?ref=rubycentral.org) dearblue
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@voxik](https://github.com/voxik?ref=rubycentral.org) Vít Ondruch
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@eregon](https://github.com/eregon?ref=rubycentral.org) Benoit Daloze
- [@ekohl](https://github.com/ekohl?ref=rubycentral.org) Ewoud Kohl van Wijngaarden
- [@rye-stripe](https://github.com/rye-stripe?ref=rubycentral.org) Peteris Rudzusiks
- [@kenyon](https://github.com/kenyon?ref=rubycentral.org) Kenyon Ralph
- [@jeremy](https://github.com/jeremy?ref=rubycentral.org) Jeremy Daer
### **Contributors to RubyGems.org:**
- [@arunagw](https://github.com/arunagw?ref=rubycentral.org) Arun Agrawal
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@javier-menendez](https://github.com/javier-menendez?ref=rubycentral.org) Javier Menéndez Rizo
- [@jjb](https://github.com/jjb?ref=rubycentral.org) John Bachir
- [@Uda-Titor](https://github.com/Uda-Titor?ref=rubycentral.org) ryohei udagawa
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@arletterocks](https://github.com/arletterocks?ref=rubycentral.org) Arlette Thibodeau
- [@xuanxu](https://github.com/xuanxu?ref=rubycentral.org) Juanjo Bazán
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
### September 2023 Monthly Update
URL: https://rubycentral.org/news/september-2023-monthly-update/
Last updated: 2023-10-19T01:06:28.000Z
Hello! Welcome to the monthly update. During September, Ruby Central's open source work was supported by 35 different companies, including [Fastly](https://www.fastly.com/?ref=rubycentral.org), Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org) and Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org).
In total, we were supported by 182 members. Thanks to all of our members for making everything that we do possible. <3
## **Ruby Central News**
**RubyConf San Diego (Nov 13-15, 2023)**
[RubyConf](http://rubyconf.org/?ref=rubycentral.org) is the annual fall conference for Ruby enthusiasts to gather and enjoy talks about new projects, meet other Ruby developers, and hear from the community's leading minds. Here are a few things you should know:
About the event
- RubyConf 2023 tickets are [on sale now!](https://rubyconf.org/register?ref=rubycentral.org)
- We've got an entire DAY lined up for workshops, community driven projects, & collaboration with Ruby organizations and members! Choose the [Community Day](https://rubycentral.org/news/community-day-at-rubyconf-2023-highlights-connection-collaboration-mentorship/) Pass on the [registration page](https://rubyconf.org/register?ref=rubycentral.org) to attend just that day (or the 3-day pass which includes Community Day).
- ICYMI our Head of Open Source, André Arko, [was featured on the Friendly Show](https://friendly.show/episodes/andre-arko-and-how-we-got-rubygems-and-bundler?ref=rubycentral.org) podcast last month!
Get involved
- Want to share your brand at RubyConf 2023? Secure your sponsorship now to reach over 500 attendees, showcase your thought leadership, and cultivate invaluable industry relationships by our [sponsorships manager, Tom](mailto:sponsors@rubycentral.org).
- Reminder: you can receive exclusive benefits like conference discounts and more by signing up for a Ruby Central [membership](https://rubycentral.org/#/portal/signup).
## **RubyGems News**
This month in RubyGems, we released RubyGems [3.4.20](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3420--2023-09-27) and Bundler [2.4.20](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2420-september-27-2023).
One of the goals of this RubyGems release was to work on allowing RubyGems to gracefully fall back to a user install if the default gem home isn't writable. This will resolve a request some users of RubyGems have been wanting for eight years ([#5327](https://github.com/rubygems/rubygems/pull/5327?ref=rubycentral.org)). Additionally, we updated the SPDX license list as of 2023-10-03 and raised Gem::Package::FormatError when gem encounters corrupt EOF ([#6882](https://github.com/rubygems/rubygems/pull/6882?ref=rubycentral.org)), and ensured that loading multiple gemspecs with legacy YAML class references does not print a warning ([#6889](https://github.com/rubygems/rubygems/pull/6889?ref=rubycentral.org)).
This month the Bundler team worked on Bundler’s performance and memory efficiency, reducing memory usage both during \`bundle install\` and when any command is run with Bundler. Some commands now use up to 25% less memory, saving as much as 10MB or more depending on bundle size, as well as speeding up boot time for Rails apps. ([#6884](https://github.com/rubygems/rubygems/pull/6884?ref=rubycentral.org), [#6923](https://github.com/rubygems/rubygems/pull/6923?ref=rubycentral.org), [#6963](https://github.com/rubygems/rubygems/pull/6963?ref=rubycentral.org), [#6976](https://github.com/rubygems/rubygems/pull/6976?ref=rubycentral.org), and others)
In preparation for the future release of Bundler 2.5.0, and building on the work of [@segiddins](https://github.com/segiddins?ref=rubycentral.org) and[ @mercedesb](https://github.com/mercedesb?ref=rubycentral.org), we are improving the security of Bundler by adding SHA256 checksum verification of .gem files during installation, as described in this[ RFC](https://github.com/rubygems/rfcs/pull/50?ref=rubycentral.org).
Some other improvements that landed in our repo this month but may not yet be released:
- fixed a false positive SymlinkError in the symbolic link directory ([#6947](https://github.com/rubygems/rubygems/pull/6947?ref=rubycentral.org))
- stop Bundler eagerly loading all specs with extensions ([#6945](https://github.com/rubygems/rubygems/pull/6945?ref=rubycentral.org))
- added support for the version format ruby-3.2.2 in the ruby file: Gemfile directive, support ruby prerelease version formats 3.3.0-preview1, and explicitly reject 3.2.2@gemset because an separate .ruby-gemset file is preferred ([#6954](https://github.com/rubygems/rubygems/pull/6954?ref=rubycentral.org))
- reduced memory allocations for stub specifications ([#6972](https://github.com/rubygems/rubygems/pull/6972?ref=rubycentral.org))
- allowed standalone mode to work on a Windows edge case ([#6989](https://github.com/rubygems/rubygems/pull/6989?ref=rubycentral.org))
- improved release scripts ([#6999](https://github.com/rubygems/rubygems/pull/6999?ref=rubycentral.org))
- fixed the SafeMarshal test on jruby ([#6984](https://github.com/rubygems/rubygems/pull/6984?ref=rubycentral.org))
In September, RubyGems gained [116 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2023-09-01%7D...master@%7B2023-09-30%7D?ref=rubycentral.org) contributed by 14 authors. There were 2,455 additions and 571 deletions across 105 files.
## **RubyGems.org News**
This month in RubyGems.org, we fixed [potentially exposed user emails](https://github.com/rubygems/rubygems.org/issues/3278?ref=rubycentral.org) by hiding gravatars for accounts with private emails ([#3731](https://github.com/rubygems/rubygems.org/pull/3731?ref=rubycentral.org),[ #4104](https://github.com/rubygems/rubygems.org/pull/4104?ref=rubycentral.org)). This ensures user email addresses stay private when users have requested that. We also opened an [RFC](https://github.com/rubygems/rfcs/pull/51?ref=rubycentral.org) to enhance user profile in general.
Support for PostgreSQL 11 version will end next February, so we created a plan, wrote reference scripts and started documenting the upgrade. Check out the Postgres upgrade RFCs to hear the plan and offer feedback! ([#52](https://github.com/rubygems/rfcs/pull/52?ref=rubycentral.org),[ #53](https://github.com/rubygems/rfcs/pull/53?ref=rubycentral.org))
Some other improvements that landed into our repo this month are:
- added a log in Pusher when notify is called ([#4072](https://github.com/rubygems/rubygems.org/pull/4072?ref=rubycentral.org))
- added a versions index on lower(gem\_full\_name) ([#4095](https://github.com/rubygems/rubygems.org/pull/4095?ref=rubycentral.org))
- added backfill for spec\_sha256 on versions ([#4083](https://github.com/rubygems/rubygems.org/pull/4083?ref=rubycentral.org))
- handled nil api\_key in the dashboards controller ([#4081](https://github.com/rubygems/rubygems.org/pull/4081?ref=rubycentral.org))
- added a fix to precompile assets on CI before running tests ([#4059](https://github.com/rubygems/rubygems.org/pull/4059?ref=rubycentral.org))
- made all texts in the about page translatable. ([#4063](https://github.com/rubygems/rubygems.org/pull/4063?ref=rubycentral.org))
- made an update to only validate version metadata on create/change ([#4100](https://github.com/rubygems/rubygems.org/pull/4100?ref=rubycentral.org))
- updated RubyGems & Bundler ([#4103](https://github.com/rubygems/rubygems.org/pull/4103?ref=rubycentral.org))
In September, RubyGems.org gained [64 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2023-09-01%7D...master@%7B2023-09-30%7D?ref=rubycentral.org) contributed by 5 authors. There were 1,855 additions and 1,070 deletions across 90 files.
## **Total spent**
In September, we completed 359hours of development work and spent $53,848.62.
## **Thank you**
Thank you to all the contributors of RubyGems and RubyGems.org for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### **Contributors to RubyGems:**
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@negi0109](https://github.com/negi0109?ref=rubycentral.org) negi
- [@pboling](https://github.com/pboling?ref=rubycentral.org) Peter Boling
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@ytkg](https://github.com/ytkg?ref=rubycentral.org) YOSHIKI
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@krororo](https://github.com/krororo?ref=rubycentral.org) kitazawa
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@yaauie](https://github.com/yaauie?ref=rubycentral.org) Ry Biesemeyer
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@byroot](https://github.com/byroot?ref=rubycentral.org) Jean Boussier
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
### **Contributors to RubyGems.org:**
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
### Listen to Ruby Central's André Arko on the Friendly Show!
URL: https://rubycentral.org/news/andreonthefriendlyshow/
Last updated: 2023-10-18T15:32:46.000Z
ICYMI André Arko, our head of open source, was a guest on the Friendly Show last month! He shared about the history of RubyGems and Bundler, what it takes to maintain these huge open source projects, the future of RubyGems, how Ruby Central is supporting all of this, and more. [Take a listen](https://friendly.show/episodes/andre-arko-and-how-we-got-rubygems-and-bundler?ref=rubycentral.org) and let us know your thoughts!
### RubyConf 2023 Flash Sale!
URL: https://rubycentral.org/news/rubyconf-2023-flash-sale/
Last updated: 2023-10-16T17:00:38.000Z
RubyConf 2023 is FOUR WEEKS AWAY on November 13th! Join us in San Diego at a DISCOUNTED price before we sell out! Grab your tickets now: [https://rubyconf.org/register](https://www.eventbrite.com/e/rubyconf-2023-san-diego-registration-622718807717?discount=flash23&ref=rubycentral.org)
### Get your question answered by Matz at RubyConf 2023!
URL: https://rubycentral.org/news/get-your-question-answered-by-matz-at-rubyconf-2023/
Last updated: 2023-12-04T21:53:59.000Z
Want a chance to be a part of Matz's keynote talk at [RubyConf 2023](https://rubyconf.org/?ref=rubycentral.org)? Submit your questions about Ruby for a chance to have them answered by the Ruby creator himself, and shared with our live audience in San Diego! Join the conversation here: [https://buff.ly/3ZWZqXB](https://t.co/nrzCTRJlXi?ref=rubycentral.org)
### See the Full Line-Up: RubyConf 2023 Announces 2023 Speakers
URL: https://rubycentral.org/news/see-the-full-line-up-rubyconf-2023-announces-2023-speakers/
Last updated: 2023-10-06T17:34:08.000Z
***AI, ethics, and programming skills to be discussed this year***
PASADENA, C.A. (Sept. 28, 2023) – RubyConf is the world's largest and longest-running annual gathering of Ruby enthusiasts, practitioners, and companies. Long-time conference organizers, Ruby Central, Inc., have just announced the speakers for the 23rd annual RubyConf. More than 20 speakers have been chosen to present on technical skills, career growth, and community at the conference, which takes place from Monday, November 13 to Wednesday, November 15 in San Diego, CA.
“We’re really excited about this year's speakers because they tackle topics and propose solutions which are new to this community," said **Chelsea Kaufman, Co-chair, RubyConf 2023.** “We’re seeing the momentum and excitement really rebound since the in-person challenges of COVID began. Our community is as enthusiastic as ever!”
Of the 21 total talks, there are three keynote speakers:
- **Sharon Steed:** author and founder of [Communilogue](https://www.communilogue.co/?ref=rubycentral.org), an empathy consultancy. Steed teaches teams and organizations the key empathy behaviors necessary to retain top talent and improve performance.
- **Saron Yitbarek:** developer, entrepreneur, and founder of [CodeNewbie](https://community.codenewbie.org/?ref=rubycentral.org), now owned by DEV. In her talks she shares stories and lessons from years of building developer communities.
- **Yukihiro “Matz” Matsumoto:** Japanese computer scientist and software programmer best known as the creator of the [Ruby programming language](https://www.ruby-lang.org/en/?ref=rubycentral.org).
“This year’s keynote speakers represent some of the values we strive to promote in the Ruby community; like continuous learning, inclusion, collaboration and empathy” said **Adarsh Pandit, Executive Director, Ruby Central. “**They are experts at building welcoming communities and we’re proud to give them a platform to share their work.”
To learn more about RubyConf 2023, including pricing and registration, visit[ ](https://rubyconf.org/?ref=rubycentral.org)[https://rubyconf.org/register](https://rubyconf.org/register?ref=rubycentral.org). The full conference schedule is also available [here](https://rubyconf.org/program?ref=rubycentral.org).
###
**About Ruby Central**
Ruby Central is a non-profit organization dedicated to supporting and advancing the Ruby programming language and a welcoming and diverse worldwide Ruby community. To learn more, visit .
### August 2023 Monthly Update
URL: https://rubycentral.org/news/august-2023-monthly-update/
Last updated: 2023-10-16T21:30:00.000Z
Hello! Welcome to the monthly update. During August, Ruby Central's open source work was supported by 35 different companies, including[ Fastly](https://www.fastly.com/?ref=rubycentral.org), Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org) and Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org).
In total, we were supported by 189 developer members. Thanks to all of our members for making everything that we do possible. <3
## **Ruby Central News**
**RubyConf San Diego (Nov 13-15, 2023)**
[RubyConf](http://rubyconf.org/?ref=rubycentral.org) is the annual fall conference for Ruby enthusiasts to gather and enjoy talks about new projects, meet and network with other Ruby developers, and hear from the community's leading minds. Here are a few things you should know:
*About the event*
- RubyConf 2023 tickets are[ on sale now!](https://rubyconf.org/register?ref=rubycentral.org) Register by Oct. 14 for standard ticket pricing.
- Have you heard what makes RubyConf 2023 stand out from any other RubyConf in the past? We've got an entire DAY lined up for workshops, community driven projects, & collaboration with Ruby organizations and members! Choose the[ Community Day](https://rubycentral.org/news/community-day-at-rubyconf-2023-highlights-connection-collaboration-mentorship/) Pass on the[ registration page](https://rubyconf.org/register?ref=rubycentral.org) to attend (or the 3-day pass which includes Community Day).
- Also, you can hear our co-chairs [Chelsea and Allison talk about the new format on the Ruby on Rails Podcast](https://www.therubyonrailspodcast.com/488?ref=rubycentral.org) this week.
*Get involved*
- Have you spoken at a #Ruby or #Rails conference and would like to offer guidance to this year’s speakers? [Apply to be a Speaker Mentor!](https://docs.google.com/forms/d/e/1FAIpQLSc0tbwD-h5Yz%5FYe1dqLKmj9MOYLrx-mYC1D5mLm-8TTe0PXMA/viewform?ref=rubycentral.org) Deadline: **Fri, Sep 29th**.
- Want to share your brand at RubyConf23? Secure your sponsorship now to reach over 500 attendees, showcase your thought leadership, and cultivate invaluable industry relationships by [emailing Tom](mailto:tom@rubycentral.org).
- Reminder: you can receive exclusive benefits like conference discounts and more by signing up for a Ruby Central[ membership](https://rubycentral.org/#/portal/signup).
**New Funding Announcement**
We are excited to announce our new funding partnership with the [Sovereign Tech Fund](https://rubycentral.org/news/stf-announce/).
**Join the Ruby Central Board**
Applications are now open until October 6 to join the board. [Apply here](https://rubycentral.org/news/jointheboard/).
## **RubyGems News**
This month in RubyGems, we released[ 3.4.18](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3418--2023-08-02),[ 3.4.19](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3419--2023-08-17) and Bundler[ 2.4.18](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2418-august-2-2023),[ 2.4.19](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2419-august-17-2023).
In RubyGems, we improved performance when updating RubyGems in[ #6864](https://github.com/rubygems/rubygems/pull/6864?ref=rubycentral.org). We added a poller to fetch WebAuthn OTPs in[ #6774](https://github.com/rubygems/rubygems/pull/6774?ref=rubycentral.org), added a file option to the Ruby method in the Gemfile in[ #6876](https://github.com/rubygems/rubygems/pull/6876?ref=rubycentral.org), and removed some side effects when unmarshalling old Gem::Specifications in[ #6825](https://github.com/rubygems/rubygems/pull/6825?ref=rubycentral.org).
Some other improvements that landed into our repo this month but that are not included in the above releases are:
- optimized memory usage in Bundler::Settings, resulting in a faster boot time -[ #6884](https://github.com/rubygems/rubygems/pull/6884?ref=rubycentral.org).
- raised Gem::Package::FormatError when gem encounters corrupt EOF -[ #6882](https://github.com/rubygems/rubygems/pull/6882?ref=rubycentral.org).
- made an update to resolve Ruby version file relative to bundle root -[ #6892](https://github.com/rubygems/rubygems/pull/6892?ref=rubycentral.org).
- added support for ruby file .tool-versions in Gemfile -[ #6898](https://github.com/rubygems/rubygems/pull/6898?ref=rubycentral.org).
- fixed a regression that could cause some legacy Gemfiles with multiple sources to take much longer to resolve -[ #6916](https://github.com/rubygems/rubygems/pull/6916?ref=rubycentral.org).
- improved warning messages for bundled gems -[ #6921](https://github.com/rubygems/rubygems/pull/6921?ref=rubycentral.org).
In August, RubyGems gained[ 106 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2023-08-01%7D...master@%7B2023-08-31%7D?ref=rubycentral.org) contributed by 17 authors. There were 1,006 additions and 268 deletions across 97 files.
## **RubyGems.org News**
This month, RubyGems.org saw several bug fixes and updates, some of which include:
- fixed the footer sponsor images being cut off at certain screen widths -[ #3996](https://github.com/rubygems/rubygems.org/pull/3996?ref=rubycentral.org).
- updated Japanese translations -[ #3998](https://github.com/rubygems/rubygems.org/pull/3998?ref=rubycentral.org).
- allowed searching for a user in avo api key role resource -[ #4000](https://github.com/rubygems/rubygems.org/pull/4000?ref=rubycentral.org).
- removed WebAuthn banner from homepage -[ #4003](https://github.com/rubygems/rubygems.org/pull/4003?ref=rubycentral.org).
- added Avo to sponsors page -[ #3999](https://github.com/rubygems/rubygems.org/pull/3999?ref=rubycentral.org).
- uploaded capybara test screenshots on failure -[ #3990](https://github.com/rubygems/rubygems.org/pull/3990?ref=rubycentral.org).
- fixed compact index files when gems are yanked -[ #207be52ef6ce4fb9ee5eaed97c09f02277911da2](https://github.com/rubygems/rubygems.org/commit/207be52ef6ce4fb9ee5eaed97c09f02277911da2?ref=rubycentral.org).
- enabled OIDC to fetch API tokens -[ #3716](https://github.com/rubygems/rubygems.org/pull/3716?ref=rubycentral.org).
In August, RubyGems gained[ 83 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2023-08-01%7D...master@%7B2023-08-31%7D?ref=rubycentral.org) contributed by 15 authors. There were 6,625 additions and 1,967 deletions across 224 files.
## **Total spent**
In June we completed 418hours of development work and spent $62,707.40.
## **Thank you**
Thank you to all the contributors of RubyGems and RubyGems.org for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### **Contributors to RubyGems:**
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@technicalpickles](https://github.com/technicalpickles?ref=rubycentral.org) Josh Nichols
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@manuraj17](https://github.com/manuraj17?ref=rubycentral.org) Manu
- [@ngan](https://github.com/ngan?ref=rubycentral.org) Ngan Pham
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@jhong97](https://github.com/jhong97?ref=rubycentral.org) John Hong
- [@amatsuda](https://github.com/amatsuda?ref=rubycentral.org) Akira Matsuda
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@gvkhna](https://github.com/gvkhna?ref=rubycentral.org) Gaurav Khanna
### **Contributors to RubyGems.org:**
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@jenshenny](https://github.com/jenshenny?ref=rubycentral.org) Jenny Shen
- [@ericherscovich](https://github.com/ericherscovich?ref=rubycentral.org) Eric Herscovich
- [@pboling](https://github.com/pboling?ref=rubycentral.org)Peter Boling
- [@bettymakes](https://github.com/bettymakes?ref=rubycentral.org) Betty Li
- [@george-ma](https://github.com/george-ma?ref=rubycentral.org) George Ma
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@Daniel-N-Huss](https://github.com/Daniel-N-Huss?ref=rubycentral.org) Daniel Huss
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@nagachika](https://github.com/nagachika?ref=rubycentral.org) Nagachika
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
- [@gemmaro](https://github.com/gemmaro?ref=rubycentral.org) gemmaro
- [@tnir](https://github.com/tnir?ref=rubycentral.org) Takuya N
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
### Ruby Central's OSS Work Now Supported by Sovereign Tech Fund
URL: https://rubycentral.org/news/stf-announce/
Last updated: 2025-05-27T17:10:44.000Z
We’re excited to announce our second partnership with the[ German Sovereign Tech Fund](https://sovereigntechfund.de/en/?ref=rubycentral.org) (STF) to support Ruby Central’s open source maintenance, development, and security work on[ Bundler](https://bundler.io/?ref=rubycentral.org) and[ RubyGems](https://github.com/rubygems/rubygems?ref=rubycentral.org). These tools are critical infrastructure which hundreds of thousands of Ruby developers rely on to do their work every day, including those at GitHub, Stripe, Airbnb, Mastodon and more. Our development team has a long track record of delivering year-over-year improvements to Ruby's public infrastructure since 2009\.
The STF supports the development, improvement, and maintenance of critical open digital infrastructure. It seeks to strengthen the open source ecosystem, focusing on security, resilience, technological diversity, and the people behind the code. This investment is a continuation of a pilot partnership between the STF and Ruby Central from 2022-2023\. We’re grateful to have our work recognized again as indispensable to the long-term health of the open source ecosystem.
This investment will support our developers as they work on our extensive Bundler and RubyGems roadmap, which includes items like:
**Make life better for all Ruby developers by:**
- Adding new functionality in Bundler to support e.g. editor tooling (aka \`bundle compose\`), resolving longstanding user requests and pain points
- Verifying links from gem metadata, to prevent gems from listing unrelated websites
- Integrating the bundle-stats gem into Bundler
- Integrating the bumbler benchmarking tool into Bundler
- Integrating the bundle-audit security tool into Bundler
- Integrating the extended-bundler-errors plugin into Bundler to improve error messages when gem installations fail
- Creating a content view to show the exact actual contents of gem packages, which may differ from the repository contents
- Adding a diff view, showing changes between gem versions, to make it easy to see exact changes
- Maintaining and expanding the popular[ Ruby Toolbox guide](https://www.ruby-toolbox.com/?ref=rubycentral.org), providing detailed information and suggestions for libraries that can be installed and used via Bundler and RubyGems
- Expanding the[ rubyapi.org](https://rubyapi.org/?ref=rubycentral.org) documentation website to include not just API docs for Ruby itself, but also documentation for gems, replacing previously useful but now deteriorating sites like apidock.com and rdoc.info
**Improve reliability for our global service by**:
- Funding a paid 24/7 on-call rotation of 3-5 people, enabling us to quickly respond to handle emergencies, incidents, or critical security issues.
- Updating and consolidating our Terraform repository
- Making infrastructure upgrades, including k8s, elasticsearch, and postgres
- Deprecating and removing the Legacy Dependency API, the most frequent cause of degraded service
- Developing automated review environments to easily test PRs, speeding up the development process while offering more chances to catch and resolve bugs.
**Increase support for gem publishing organizations by:**
- Adding permissions levels, so users can have permission to push gems without also having admin permissions to add and remove other users.
- Building a Terraform provider to manage gem permissions, so that organizations can manage permissions for gems in the same place as other cloud permissions.
- Adding OIDC integration for RubyGems.org, improving security by avoiding permanent auth tokens.
- Adding SSO integration for organizations to allow easier and more automated account management.
- Developing namespaces for organizations, to eliminate an entire class of name-confusion attacks.
**Make life better for RubyGems maintainers by:**
- Building simpler and more automatic admin tools to help users with problems, resolving problems more quickly and with less burden placed on maintainers: yank version, yank gem by name, disable user account by name or email, yank all gems by user account.
- Deprecating and removing gem commands \`cert\`, \`lock\`, reducing surface area for bugs and eliminating unaudited legacy cryptographic signing scheme.
- Creating a GitHub action to release Bundler and RubyGems from CI
**Make life better for gem creators by:**
- Building and releasing a GitHub action to release gems securely using OIDC and ephemeral access tokens
- Creating per-version daily, weekly, and monthly download graphs to show real world usage changes over time
- Updating[ Gemstash](https://rubygems.org/gems/gemstash/versions/2.0.0?ref=rubycentral.org) to include support for the compact index
- Extracting a reference implementation of the compact index with documentation
- Updating \`gem generate\_index\` to generate compact index files
- Supporting and documenting using a static server (e.g. S3) as a gem source that includes the compact index
- Revising support for gems with extensions written in Rust, improving documentation and user experience
Thank you to the STF for funding our work! We look forward to the ways this investment will help us provide more robust maintenance and free open source tools that ultimately strengthen the Ruby ecosystem and serve the whole Ruby community.
### Listen to our RubyConf 2023 Preview on the Ruby On Rails Podcast
URL: https://rubycentral.org/news/listen-to-our-rubyconf-2023-preview-on-the-ruby-on-rails-podcast/
Last updated: 2023-09-22T20:37:36.000Z
Did you catch RubyConf 2023 co-chairs Allison McMillan and Chelsea Kaufman on [the Ruby on Rails Podcast](https://www.therubyonrailspodcast.com/488?ref=rubycentral.org)? They talked about:
- What to expect at this year's conference
- How RubyConf has evolved over the years (and through the pandemic)
- The ways they have incorporated feedback from the past conferences to add more community building activities to RubyConf 2023 including Community Day and Ruby pods
- What’s special and new about this year’s conference venue
- Their favorite experiences in the Ruby community, personal RubyConf memories and why RubyConf is such a special place for new Rubyists
- And more...
Take a listen and let us know what you think!
### Applications Now Open to Join the Board of Ruby Central!
URL: https://rubycentral.org/news/jointheboard/
Last updated: 2023-10-13T18:32:27.000Z
**Ruby Central is a non-profit organization dedicated to support and advocacy of the worldwide Ruby community.**
We produce the annual RubyConf and RailsConf conferences, support community growth, and provide vital infrastructure for the Ruby programming language by maintaining the bundler and rubygems packaging services in addition to other open source projects.
The board of directors for Ruby Central act as representatives to the community and work to ensure smooth operations today and smart strategy for tomorrow. We meet once a month and all take turns working as co-chairs of the conferences.
To support our conferences and programs, we're looking to fill multiple board seats! We'd love to have you come join our small but dedicated team of volunteers.
**We think about big questions like:**
- Where do we want to see the Ruby community go?
- What do we want our events to look like?
- Who do we want to see represented on the stage and in the audience?
- How do we grow and connect our community?
As a board member you will play a pivotal role in helping build the future of Rubyists everywhere. You’ll have the chance to help shape the experience at the world’s largest Ruby conference, introduce us to the next generation of Ruby/RailsConf speakers, guide our open source infrastructure work, and work on exciting new projects which support the community year-round.
**Responsibilities**
- Ensuring the financial health and stability of Ruby Central, including:
- Reviewing regular reports and financials
- Working with our staff on projects
- Supporting event production
- Guiding our Open Source strategy
- Exploring new revenue streams and engagement opportunities
- Staffing
- Help make ongoing staffing and hiring decisions as needed
- Supporting Ruby programming language and ecosystem, including:
- Serving as a reference/resource
- Helping assess and implement new ideas related to Ruby language support
**Skills/Experience**
- Managing finances for a nonprofit
- Open source maintenance and governance
- Corporate or individual fundraising for nonprofits
- B2B or B2C Sales
**Meetings and time commitment**
- One 1.5 hour long board meeting per month
- Board committee meetings and off-site retreats a few times a year
- Attending both conferences
- 2-10 hours weekly depending on tasks at hand
**Apply before October 6 [here](https://docs.google.com/forms/d/1yJHaM-9C-EAeBeQ2SMfTO6FEDkBwGjn6GTYn-Sz0Ddk/viewform?edit%5Frequested=true&pli=1&ref=rubycentral.org). You can also nominate someone for a board position [here](https://docs.google.com/forms/d/1CGl2b2MY2ZyPEfp8zxaTglLct2U2WEZcVqSCPGaNSa4/viewform?edit%5Frequested=true&pli=1&ref=rubycentral.org).**
**FAQS**
**Q:** How long will applications remain open?
- **A:** Applications will be open for two weeks.
**Q:** What happens if my application is selected?
- **A:** We appreciate your patience as we sort through applications – we're a small (but mighty) group of volunteers! We will reach out to any candidates that are selected for an interview. Then we’ll follow up with next steps.
**Q:** Can I nominate someone for a board position?
- **A:** Yes, you can nominate a candidate[ here](https://docs.google.com/forms/d/1CGl2b2MY2ZyPEfp8zxaTglLct2U2WEZcVqSCPGaNSa4/viewform?edit%5Frequested=true&pli=1&ref=rubycentral.org).
**Q:** When is the start date for this position?
- **A:** We’d love to fill our board seats by the end of the year. But we’re also looking for someone who is a great fit for this role and our team. We may reopen applications after this round if we need to keep looking.
**Q:** What if I have other questions?
- **A:** You can email contact@rubycentral.org
### Listen to Ruby Central's André Arko on The Rooftop Ruby Podcast
URL: https://rubycentral.org/news/listen-ruby-centrals-andre-arko-on-the-rooftop-ruby-podcast/
Last updated: 2023-10-18T15:28:18.000Z

ICYMI our head of open source André Arko [was featured on the Rooftop Ruby Podcast last week!](https://www.rooftopruby.com/2108545/13495314?ref=rubycentral.org) He covered his journey to Bundler, how Ruby Together came to be and how he is continuing this work with Ruby Central. He also shared some developer horror stories – and funny stories too! Enjoy, and please don't hesitate to [reach out](contact@rubycentral.org) and let us know what you think.
### Community Day at RubyConf 2023 Highlights Connection, Collaboration & Mentorship
URL: https://rubycentral.org/news/community-day-at-rubyconf-2023-highlights-connection-collaboration-mentorship/
Last updated: 2023-09-06T14:58:10.000Z
***The New Format Allows for Long-term Partnerships & New #RubyFriends***
[Ruby Central, Inc.](https://rubycentral.org/) announced a completely reimagined format for [RubyConf 2023](https://rubyconf.org/?ref=rubycentral.org). The 23rd annual Ruby Conference, taking place in San Diego, California, will kick off with Community Day, which is replacing one day of talks. Instead, registrants will attend workshops, collaborate with one another and take advantage of opportunities to meet open source maintainers, including the chance to pair with core teams; Ruby, JRuby, Truffle Ruby, Bundler/RubyGems and more.
“Many of us have #RubyFriends from conferences, but in our day-to-day work, we work in silos,” said **Allison McMillan, Co-chair, RubyConf 2023** “This year we wanted to create even more space to build connections that persist beyond these three days. Community Day will provide opportunities to talk about projects you’re working on, plan future collaborations or maybe even get involved in a project you never thought you would.”
“This is a great chance for Ruby developers from all over the world to meet the amazing and hardworking people who make the software which they depend on every day,” said **Adarsh Pandit, Executive Director, Ruby Central**.
RubyConf2023 will be held from Monday, November 13 to Wednesday, November 15 at the Town and Country Resort. In addition to Community Day, the conference will also include talks that focus on building tech and interpersonal skills, and career growth. Other official events include live podcast recordings, a 5k run, bike tours and more.
To learn more about RubyConf 2023, including pricing and registration, visit[ https://rubyconf.org](https://rubyconf.org/?ref=rubycentral.org).
###
**About Ruby Central**
Ruby Central is a non-profit organization dedicated to supporting and advancing the Ruby programming language and a welcoming and diverse worldwide Ruby community. We create spaces and events, online and offline, for the community to come together to connect, engage, and educate each other, including RubyConf, the world's largest and longest-running gathering of Ruby enthusiasts, practitioners, and companies. We also provide a support ecosystem for Ruby development to thrive by operating services and maintaining software for the good of the community. To learn more, visit .
### July 2023 Monthly Update
URL: https://rubycentral.org/news/july-2023-monthly-update/
Last updated: 2023-09-19T17:06:04.000Z
Hello! Welcome to the monthly update. During July, Ruby Central's open source work was supported by 35 different companies, including Ruby member[ Zendesk](https://zendesk.com/?ref=rubycentral.org) and Ruby Shield sponsor[ Shopify](https://www.shopify.com/?ref=rubycentral.org).
In total, we were supported by 193 developer members. Thanks to all of our members for making everything that we do possible. <3
## **Ruby Central News**
**The latest on RubyConf 2023 San Diego:**
RubyConf is the annual fall conference for Ruby enthusiasts to gather and enjoy talks about new projects, meet and network with other Ruby developers, and hear from the community's leading minds. This year's conference will feature a community day, a cohort experience, and more. Here are a few things you should know:
- The CFP for RubyConf 2023 is now open! We are accepting proposals for 30-45 mins Talks or 2-hour Workshops. Take a look at this year's conference tracks and[ submit your proposal](https://sessionize.com/rubyconf-2023/?ref=rubycentral.org) by August 20.
- Need some help with your proposal? Check out this[ old but still relevant post](https://rubycentral.org/news/5-reasons-to-turn-that-idea-into-a-rubyconf-2022-talk-/) for inspiration and some helpful links.
- RubyConf 2023 tickets are[ on sale now!](https://rubyconf.org/register?ref=rubycentral.org) **Early bird rates are available until August 20th.**
- Guess what's going to set RubyConf 2023 apart from the previous years? We've got an entire DAY lined up for workshops, community driven projects, & collaboration with Ruby organizations and members! Choose the Community Day Pass on the [registration page](https://rubyconf.org/register?ref=rubycentral.org) to attend.
- Want to amplify your brand's impact at RubyConf23? [Secure your sponsorship](mailto:sponsors@rubycentral.org) now to reach over 500 attendees, showcase your thought leadership, and cultivate invaluable industry relationships.
- Reminder: you can receive exclusive benefits like conference discounts and more by signing up for a Ruby Central[ membership](https://rubycentral.org/#/portal/signup).
## RubyGems News
This month in RubyGems, we released [3.4.16](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3416--2023-07-10), [3.4.17](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3417--2023-07-14) and Bundler [2.4.16](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2416-july-10-2023), [2.4.17](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2417-july-14-2023).
In RubyGems, we [improved](https://github.com/rubygems/rubygems/pull/6810?ref=rubycentral.org) certain `gem install` invocations that had gotten slower since the dependencies API was phased out. In Bundler, the above releases include several improvements such as [fixes](https://github.com/rubygems/rubygems/pull/6784?ref=rubycentral.org) related to locked platforms, [improvements](https://github.com/rubygems/rubygems/pull/6786?ref=rubycentral.org) to make sections related to Git gems stable, and some other regression fixes.
Some other improvements that landed into our repo this month but that are not included in the above releases are:
- improved RubyGems `require` \- [#6827](https://github.com/rubygems/rubygems/pull/6827?ref=rubycentral.org).
- improvements related to the Security Devices support feature - [#6774](https://github.com/rubygems/rubygems/pull/6774?ref=rubycentral.org).
- updated the Magnus version in the Rust extension gem template - [#6843](https://github.com/rubygems/rubygems/pull/6843?ref=rubycentral.org).
- removed side effects when unmarshaling old `Gem::Specification` files- [#6825](https://github.com/rubygems/rubygems/pull/6825?ref=rubycentral.org).
- made up update to use `File::NULL `instead of hard coded null device names - [#6809](https://github.com/rubygems/rubygems/pull/6809?ref=rubycentral.org).
- added Automatiek improvements - [#6788](https://github.com/rubygems/rubygems/pull/6788?ref=rubycentral.org).
In July, RubyGems gained [96 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2023-07-01%7D...master@%7B2023-07-31%7D?ref=rubycentral.org) contributed by 13 authors. There were 1,559 additions and 695 deletions across 86 files.
## RubyGems.org News
This month, RubyGems.org saw several bug fixes and updates, some of which include:
- reduced the size of the deployed docker image from >350MB to 277MB - [#3894](https://github.com/rubygems/rubygems.org/pull/3894?ref=rubycentral.org).
- redirected MFA Required users to the edit settings page - [#3902](https://github.com/rubygems/rubygems.org/pull/3902?ref=rubycentral.org).
- extracted `GEM_NAME_RESERVED_LIST` into database and included in admin panel.- #[3897](https://github.com/rubygems/rubygems.org/pull/3897?ref=rubycentral.org).
- added user validation on MFA Level - [#3905](https://github.com/rubygems/rubygems.org/pull/3905?ref=rubycentral.org).
- added "enabled/disabled" badge for OTP & Webauthn - [#3936](https://github.com/rubygems/rubygems.org/pull/3936?ref=rubycentral.org).
- fixed issue that led to limiting allowed methods in nginx - [#3941](https://github.com/rubygems/rubygems.org/pull/3941?ref=rubycentral.org).
- implemented the `setup_webauthn_authentication` helper method in updating MFA level - [#3963](https://github.com/rubygems/rubygems.org/pull/3963?ref=rubycentral.org).
- implemented Avo actions to enqueue compact index file upload jobs - [#3970](https://github.com/rubygems/rubygems.org/pull/3970?ref=rubycentral.org).
- redirected users to signin after webauthn error occurrances - [#3962](https://github.com/rubygems/rubygems.org/pull/3962?ref=rubycentral.org).
- added a `maintenance_tasks` engine for running one-off tasks - [#3971](https://github.com/rubygems/rubygems.org/pull/3971?ref=rubycentral.org).
- refactored the mailer content to specify the MFA implementation used (TOTP) - [#3903](https://github.com/rubygems/rubygems.org/pull/3903?ref=rubycentral.org) (shown below).

In July, RubyGems gained [99 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2023-07-01%7D...master@%7B2023-07-31%7D?ref=rubycentral.org) contributed by 18 authors. There were 2,460 additions and 1,566 deletions across 128 files.
## Total spent
In June we completed 210hours of development work @$150/hour, and spent $31,470.50.
## Thank you
Thank you to all the contributors of RubyGems and RubyGems.org for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### Contributors to RubyGems:
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@ParadoxV5](https://github.com/ParadoxV5?ref=rubycentral.org) Jimmy H
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@koic](https://github.com/koic?ref=rubycentral.org) Koichi ITO
- [@jenshenny](https://github.com/jenshenny?ref=rubycentral.org) Jenny Shen
- [@obregonia1](https://github.com/obregonia1?ref=rubycentral.org) Kentaro Takeyama
- [@fxn](https://github.com/fxn?ref=rubycentral.org) Xavier Noria
- [@ko1](https://github.com/ko1?ref=rubycentral.org) Koichi Sasada
- [@matsadler](https://github.com/matsadler?ref=rubycentral.org) Mat Sadler
### Contributors to RubyGems.org:
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@bettymakes](https://github.com/bettymakes?ref=rubycentral.org) Betty Li
- [@jenshenny](https://github.com/jenshenny?ref=rubycentral.org) Jenny Shen
- [@george-ma](https://github.com/george-ma?ref=rubycentral.org) George Ma
- [@Schwad](https://github.com/Schwad?ref=rubycentral.org) Nick Schwaderer
- [@shouichi](https://github.com/shouichi?ref=rubycentral.org) Shouichi Kamiya
- [@ericherscovich](https://github.com/ericherscovich?ref=rubycentral.org) Eric Herscovich
- [@scottzyang](https://github.com/scottzyang?ref=rubycentral.org) Scott Yang
- [@a5-stable](https://github.com/a5-stable?ref=rubycentral.org) a5
- [@etiennebarrie](https://github.com/etiennebarrie?ref=rubycentral.org) Étienne Barrié
- [@ccmywish](https://github.com/ccmywish?ref=rubycentral.org) ccmywish
- [@ParadoxV5](https://github.com/ParadoxV5?ref=rubycentral.org) Jimmy H
### June 2023 Monthly Update
URL: https://rubycentral.org/news/june-2023-monthly-update/
Last updated: 2023-08-16T18:39:44.000Z
Hello! Welcome to the monthly update. During June, our work was supported by [Shopify](https://www.shopify.com/?ref=rubycentral.org), [Zendesk](https://zendesk.com/?ref=rubycentral.org) and many others.
## **Ruby Central News**
**The latest on RubyConf 2023 San Diego:**
RubyConf is the annual fall conference for Ruby enthusiasts to gather and enjoy talks about new projects, meet and network with other Ruby developers, and hear from the community's leading minds. This year's conference will feature a community day, a cohort experience, and more. Here are a few things you should know:
- The CFP for RubyConf 2023 is now open! We are accepting proposals for 30-45 mins Talks or 2-hour Workshops. Take a look at this year's conference tracks and [submit your proposal](https://sessionize.com/rubyconf-2023/?ref=rubycentral.org) by August 20\.
- Need some help with your proposal? Stay tuned for our CFP coaching sessions to be held in the next few weeks — we’ll be announcing the dates soon at [rubyconf.org](https://rubyconf.org/?ref=rubycentral.org)!
- RubyConf 2023 tickets are [on sale now!](https://rubyconf.org/register?ref=rubycentral.org) Early bird rates are available until August 20th. This year's ticket options include a couple of exciting new ways to experience the conference: Community Day and Ruby Squad. Check out the [registration page](https://rubyconf.org/register?ref=rubycentral.org) to learn more.
- Reminder: you can receive exclusive benefits like conference discounts and more by signing up for a Ruby Central [membership](https://rubycentral.org/#/portal/signup).
In June, Ruby Central's open source work was supported by 35 different companies, including Ruby member[ Zendesk](https://zendesk.com/?ref=rubycentral.org) and Ruby Shield sponsor[ Shopify](https://www.shopify.com/?ref=rubycentral.org).
In total, we were supported by 193 developer members. Thanks to all of our members for making everything that we do possible. <3
## RubyGems News
This month in RubyGems, we released RubyGems [3.4.14](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3414--2023-06-12), [3.4.15](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3415--2023-06-29), and Bundler [2.4.14](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2414-june-12-2023), [2.4.15](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2415-june-29-2023).
The following improvements and fixes are included in these releases (see the changelog for more information):
- resolved a problem where using git sources could make the order of lockfiles unstable - [#6786](https://github.com/rubygems/rubygems/pull/6786?ref=rubycentral.org).
- updated the command to test local gem command changes - [#6761](https://github.com/rubygems/rubygems/pull/6761?ref=rubycentral.org).
- enabled `Performance/FlatMap` cop - [#6745](https://github.com/rubygems/rubygems/pull/6745?ref=rubycentral.org).
- improved the edge case error message - [#6733](https://github.com/rubygems/rubygems/pull/6733?ref=rubycentral.org).
- stopped publishing the Gemfile in the default gem template - [#6723](https://github.com/rubygems/rubygems/pull/6723?ref=rubycentral.org).
- added a fix to avoid infinite loops when hitting resolution bugs - [#6722](https://github.com/rubygems/rubygems/pull/6722?ref=rubycentral.org).
- stopped failures from occurring when the build directory name contains `+` symbol - [#6750](https://github.com/rubygems/rubygems/pull/6750?ref=rubycentral.org).
In June, RubyGems gained [109 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2023-06-01%7D...master@%7B2023-06-30%7D?ref=rubycentral.org) contributed by 10 authors. There were 978 additions and 624 deletions across 110 files.
## RubyGems.org News
This month, RubyGems.org saw several bug fixes and updates, some of which include:
- updated `toxiproxy` \- [#3884](https://github.com/rubygems/rubygems.org/pull/3884?ref=rubycentral.org).
- updated `kubeconform` used on CI - [#3886](https://github.com/rubygems/rubygems.org/pull/3886?ref=rubycentral.org).
- switched `webauthn_credentials.any?` and `.present?` to be webauthn\_enabled? - [#3867](https://github.com/rubygems/rubygems.org/pull/3867?ref=rubycentral.org).
- added recovery code support for webauthn - [#3859](https://github.com/rubygems/rubygems.org/pull/3859?ref=rubycentral.org).
- made `create_between` consistent for versions with same`created_at` timeframe - [#3887](https://github.com/rubygems/rubygems.org/pull/3887?ref=rubycentral.org).
- added an admin action to reserve a gem namespace - [#3875](https://github.com/rubygems/rubygems.org/pull/3875?ref=rubycentral.org).

In June, RubyGems gained [113 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2023-06-01%7D...master@%7B2023-06-30%7D?ref=rubycentral.org) contributed by 11 authors. There were 2,262 additions and 463 deletions across 76 files.
## Total spent
In June we completed 188 hours of development work @$150/hour, and spent $28,218.50.
## Thank you
Thank you to all the contributors of RubyGems and RubyGems.org for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### Contributors to RubyGems:
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@davetron5000](https://github.com/davetron5000?ref=rubycentral.org) David Copeland
- [@gareth](https://github.com/gareth?ref=rubycentral.org) Gareth Adams
- [@ioquatix](https://github.com/ioquatix?ref=rubycentral.org) Samuel Williams
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@andrykonchin](https://github.com/andrykonchin?ref=rubycentral.org) Andrii Konchyn
- [@jenshenny](https://github.com/jenshenny?ref=rubycentral.org) Jenny Shen
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@george-ma](https://github.com/george-ma?ref=rubycentral.org) George Ma
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
### Contributors to RubyGems.org:
- [@jenshenny](https://github.com/jenshenny?ref=rubycentral.org) Jenny Shen
- [@ericherscovich](https://github.com/ericherscovich?ref=rubycentral.org) Eric Herscovich
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@juankuquintana](https://github.com/juankuquintana?ref=rubycentral.org) Juan Ku Quintana
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@bettymakes](https://github.com/bettymakes?ref=rubycentral.org) Betty Li
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@bradly](https://github.com/bradly?ref=rubycentral.org) Bradly Feeley
### May 2023 Monthly Update
URL: https://rubycentral.org/news/may-2023-monthly-update/
Last updated: 2023-07-27T15:57:21.000Z
Hello! Welcome to the monthly update. During May, our work was supported by [Shopify](https://www.shopify.com/?ref=rubycentral.org), [Zendesk](https://zendesk.com/?ref=rubycentral.org) and many others.
## **Ruby Central News**
In May, Ruby Central's open source work was supported by 35 different companies, including Ruby member[ Zendesk](https://zendesk.com/?ref=rubycentral.org) and Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org).
In total, we were supported by 196 developer members. Thanks to all of our members for making everything that we do possible. <3
## RubyGems News
This month in RubyGems, we released RubyGems [3.4.13](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3413--2023-05-09) and Bundler [2.4.13](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2413-may-9-2023).
Other changes that landed in our repo during May were:
- ongoing unification of RubyGems and Bundler codebases - [#6691](https://github.com/rubygems/rubygems/pull/6691?ref=rubycentral.org), [#6716](https://github.com/rubygems/rubygems/pull/6716?ref=rubycentral.org).
- a fix for API key loading when RubyGems host is set to development - [#6683](https://github.com/rubygems/rubygems/pull/6683?ref=rubycentral.org).
- a new error message to be shown when trying to update bundler in frozen mode - [#6684](https://github.com/rubygems/rubygems/pull/6684?ref=rubycentral.org).
- an update that makes the frozen setting take precedence over the deployment setting - [#6685](https://github.com/rubygems/rubygems/pull/6685?ref=rubycentral.org).
- a fix to correct deployment vs path precedence - [#6703](https://github.com/rubygems/rubygems/pull/6703?ref=rubycentral.org).
In May, RubyGems gained [91 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2023-05-01%7D...master@%7B2023-05-31%7D?ref=rubycentral.org) contributed by 9 authors. There were 674 additions and 1,001 deletions across 103 files.
## RubyGems.org News
This month, RubyGems.org saw several bug fixes and updates, some of which include:
- improved styling on the reverse dependencies page - [#3760](https://github.com/rubygems/rubygems.org/pull/3760?ref=rubycentral.org).
- an increased the number of puma threads: from 1 to 5 -[#3773](https://github.com/rubygems/rubygems.org/pull/3773?ref=rubycentral.org).
- setting up `kubeconform` to lint rendered k8s yaml - [#3774](https://github.com/rubygems/rubygems.org/pull/3774?ref=rubycentral.org).
- an added job to upload pre-rendered versions files to S3 -[#3775](https://github.com/rubygems/rubygems.org/pull/3775?ref=rubycentral.org).
- an added email notification when MFA is enabled - [#3779](https://github.com/rubygems/rubygems.org/pull/3779?ref=rubycentral.org).
- a fix to ensure `x-amz-meta-Surrogate-Control` is set for `/versions` from S3 - [#3787](https://github.com/rubygems/rubygems.org/pull/3787?ref=rubycentral.org).
- an added development environment a default mailer port configuration - [#3792](https://github.com/rubygems/rubygems.org/pull/3792?ref=rubycentral.org).
- renaming user OTP methods to reference OTP instead of MFA - [#3807](https://github.com/rubygems/rubygems.org/pull/3807?ref=rubycentral.org).
- referencing `UserWebauthnMethods` in `UserMultifactorMethods` \- [#3808](https://github.com/rubygems/rubygems.org/pull/3808?ref=rubycentral.org).
In May, RubyGems.org gained [105 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2023-05-01%7D...master@%7B2023-05-31%7D?ref=rubycentral.org), contributed by 12 authors. There were 1,515 additions and 1,223 deletions across 103 files.
## **Total Spent**
In May we completed 188 hours of development work @$150/hour, and spent $28,193.00.
## Thank you
Thank you to all the contributors of RubyGems and RubyGems.org for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### Contributors to RubyGems:
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@aeroastro](https://github.com/aeroastro?ref=rubycentral.org) Takumasa Ochi
- [@kou](https://github.com/Kou?ref=rubycentral.org) Sutou Kouhei
- [@jenshenny](https://github.com/jenshenny?ref=rubycentral.org) Jenny Shen
- [@ericherscovich](https://github.com/ericherscovich?ref=rubycentral.org) Eric Herscovich
### Contributors to RubyGems.org:
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@javier-menendez](https://github.com/javier-menendez?ref=rubycentral.org) Javier Menéndez Rizo
- [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org) Colby Swandale
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@garyhtou](https://github.com/garyhtou?ref=rubycentral.org) Gary Tou
- [@jenshenny](https://github.com/jenshenny?ref=rubycentral.org) Jenny Shen
- [@ericherscovich](https://github.com/ericherscovich?ref=rubycentral.org) Eric Herscovich
- [@dancristianb](https://github.com/dancristianb?ref=rubycentral.org) Dan Cristian
- [@juankuquintana](https://github.com/juankuquintana?ref=rubycentral.org) Juan Ku Quintana
### RubyConf 2023 in San Diego on November 13-15
URL: https://rubycentral.org/news/rubyconf-2023-san-diego/
Last updated: 2023-12-04T21:54:15.000Z
Ruby Central, Inc. is proud to host its 23rd annual RubyConf conference in beautiful San Diego, California! RubyConf will span 3 days, with the first day dedicated to workshops and a hack day, followed by two days of talks, networking, and more.
Early Bird tickets are now available on [RubyConf.org](https://rubyconf.org/?ref=rubycentral.org) to purchase. These tickets are **limited**, so get your tickets today!
The conference is hosted by Town and Country Resort. Hotel rate is $189 per night - more can be found on our location page [www.rubyconf.org/location](http://www.rubyconf.org/location?ref=rubycentral.org)
Updates can be found on Twitter ([https://twitter.com/rubyconf](https://twitter.com/rubyconf?ref=rubycentral.org)) or sign up for our mailing list ([link](https://rubycentral.us13.list-manage.com/subscribe?u=e7e9b891a6914ff2f5acdfd15&id=0a4c3c473c&ref=rubycentral.org))
[Get Your Ticket ->](https://rubyconf2023.eventbrite.com/?aff=webruby23&ref=rubycentral.org)
### April 2023 Monthly Update
URL: https://rubycentral.org/news/april-2023-monthly-update/
Last updated: 2023-06-23T16:13:20.000Z
Hello! Welcome to the monthly update. During April, our work was supported by [Shopify](https://www.shopify.com/?ref=rubycentral.org), [Zendesk](https://zendesk.com/?ref=rubycentral.org) and many others.
## Ruby Central News
In April, Ruby Central's open source work was supported by 35 different companies, including Ruby member[ Zendesk](https://zendesk.com/?ref=rubycentral.org) and Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org).
In total, we were supported by 162 developer members. Thanks to all of our members for making everything that we do possible. <3
## RubyGems News
This month in RubyGems, we released RubyGems [3.4.11](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3411--2023-04-10), [3.4.12](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3412--2023-04-11) and Bundler [2.4.11](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2411-april-10-2023), [2.4.12](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2412-april-11-2023).
The following improvements and fixes are included in these releases (see the changelog for more information):
- reduced chances of Bundler reverting to old APIs by removing a fallback to full indexes on big gemfiles in RubyGems - [#6578](https://github.com/rubygems/rubygems/pull/6578?ref=rubycentral.org).
- made RubyGems less dependent on default gems by using a vendored `pure-ruby` YAML parser to load its own configuration - [#6615](https://github.com/rubygems/rubygems/pull/6615?ref=rubycentral.org).
- added some development improvements like RuboCop enhancements - [#6599](https://github.com/rubygems/rubygems/pull/6599?ref=rubycentral.org), [#6608](https://github.com/rubygems/rubygems/pull/6608?ref=rubycentral.org), [#6586](https://github.com/rubygems/rubygems/pull/6586?ref=rubycentral.org), [#6590](https://github.com/rubygems/rubygems/pull/6590?ref=rubycentral.org), [#6582](https://github.com/rubygems/rubygems/pull/6582?ref=rubycentral.org), and unified our tasks to vendor gems - [#6628](https://github.com/rubygems/rubygems/pull/6628?ref=rubycentral.org).
In April, RubyGems gained [128 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2023-04-01%7D...master@%7B2023-04-30%7D?ref=rubycentral.org) contributed by 12 authors. There were 2,125 additions and 1,244 deletions across 175 files.
## RubyGems.org News
**Dependency API Updates:**
Based on additional feedback from community members, we have pushed back the removal by two weeks and added an exception until August 8 for Java users. New brownout dates are May 12, 15, 17, 19, 22, and the removal date is moved from May 10 to May 24.
This month, RubyGems.org saw several bug fixes and updates, some of which include:
- refactored WebAuthn Verification logic - [#3720](https://github.com/rubygems/rubygems.org/pull/3720?ref=rubycentral.org).
- added logging around pushing gems - [#3745](https://github.com/rubygems/rubygems.org/pull/3745?ref=rubycentral.org).
- added an admin Tool: Yank user - [#3684](https://github.com/rubygems/rubygems.org/pull/3684?ref=rubycentral.org).
- fixed password hint text - [#3730](https://github.com/rubygems/rubygems.org/pull/3730?ref=rubycentral.org).
- added a mailer for WebAuthn credential updates - [#3695](https://github.com/rubygems/rubygems.org/pull/3695?ref=rubycentral.org).
- added a pop-up when a WebAuthn credential is deleted -[#3708](https://github.com/rubygems/rubygems.org/pull/3708?ref=rubycentral.org).
- added an admin Tool: Change User Email - [#3709](https://github.com/rubygems/rubygems.org/pull/3709?ref=rubycentral.org).
- allowed `avo` to search when index is allowed - [#3725](https://github.com/rubygems/rubygems.org/pull/3725?ref=rubycentral.org).
- enabled Datadog HTTP request queuing - [#3754](https://github.com/rubygems/rubygems.org/pull/3754?ref=rubycentral.org).
- removed outdated `bin/update_vendor_cache` \- [#3752](https://github.com/rubygems/rubygems.org/pull/3752?ref=rubycentral.org).
- fixed lifecycle location in k8s yaml config - [#3747](https://github.com/rubygems/rubygems.org/pull/3747?ref=rubycentral.org).
- added the `preStop` lifecycle hook to Nginx - [#3746](https://github.com/rubygems/rubygems.org/pull/3746?ref=rubycentral.org).
- removed nginx version caching - [#3714](https://github.com/rubygems/rubygems.org/pull/3714?ref=rubycentral.org).
- advertised that compact index actions accept range requests - [#3713](https://github.com/rubygems/rubygems.org/pull/3713?ref=rubycentral.org).
- updated the default response to render plain text in `WebauthnVerification#authenticate` \- [#3712](https://github.com/rubygems/rubygems.org/pull/3712?ref=rubycentral.org).
- added caching to dependency API - [#3703](https://github.com/rubygems/rubygems.org/pull/3703?ref=rubycentral.org).
- updated Ingress apiVersion to `networking.k8s.io/v1` \- [#3687](https://github.com/rubygems/rubygems.org/pull/3687?ref=rubycentral.org).
- replaced the dependency API route with search in encoding test - [#3682](https://github.com/rubygems/rubygems.org/pull/3682?ref=rubycentral.org).
- added a displayed message to user when safari is detected - [#3674](https://github.com/rubygems/rubygems.org/pull/3674?ref=rubycentral.org).

In addition to features and bugfixes, the entire RubyGems.org team was hard at work behind the scenes, maintaining and improving the infrastructure that the Rails app runs within:
- Upgrades for EKS, ALB, APIService, and metrics server
- Migrate remaining hand-created infrastructure into terraform
- Set up a dedicated review environment for webauthn testing
- Add logging of headers and trace IDs to DataDog and Honeycomb
Finally, on top of all of that work, the on-call team also handled several incidents of elevated error rates and instability during and after the Dependency API brownout dates. While some users saw transient or occasional errors at various times, we were able to successfully resolve the issues each time without any outages.
In April, RubyGems.org gained [162 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2023-04-01%7D...master@%7B2023-04-31%7D?ref=rubycentral.org), contributed by 15 authors. There were 4,754 additions and 1,317 deletions across 164 files.
## Total Spent
In April we completed 323 hours of development work @$150/hour, and spent $48,404.
## Thank you
Thank you to all the contributors of RubyGems and RubyGems.org for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### Contributors to RubyGems:
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@luke-gru](https://github.com/luke-gru?ref=rubycentral.org) Luke Gruber
- [@aellispierce](https://github.com/aellispierce?ref=rubycentral.org) Ashley Ellis Pierce
- [@jenshenny](https://github.com/jenshenny?ref=rubycentral.org) Jenny Shen
- [@jchestershopify](https://github.com/jchestershopify?ref=rubycentral.org) Jacques Chester
- [@bettymakes](https://github.com/bettymakes?ref=rubycentral.org) Betty Li
- [@ericherscovich](https://github.com/ericherscovich?ref=rubycentral.org) Eric Herscovich
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@MRozmus](https://github.com/MRozmus?ref=rubycentral.org) Marcin Rozmus
### Contributors to RubyGems.org:
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@jenshenny](https://github.com/jenshenny?ref=rubycentral.org) Jenny Shen
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@jchestershopify](https://github.com/jchestershopify?ref=rubycentral.org) Jacques Chester
- [@aellispierce](https://github.com/aellispierce?ref=rubycentral.org) Ashley Ellis Pierce
- [@bettymakes](https://github.com/bettymakes?ref=rubycentral.org) Betty Li
- [@ericherscovich](https://github.com/ericherscovich?ref=rubycentral.org) Eric Herscovich
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@adrianthedev](https://github.com/adrianthedev?ref=rubycentral.org) Adrian Marin
- [@arunagw](https://github.com/arunagw?ref=rubycentral.org) Arun Agrawal
- [@javier-menendez](https://github.com/javier-menendez?ref=rubycentral.org) Javier Menéndez Rizo
### March 2023 Monthly Update
URL: https://rubycentral.org/news/march-2023-monthly-update/
Last updated: 2023-06-16T20:28:18.000Z
Hello! Welcome to the monthly update. During March, our work was supported by [Shopify](https://www.shopify.com/?ref=rubycentral.org), [Zendesk](https://zendesk.com/?ref=rubycentral.org) and many others.
## Ruby Central News
In March, Ruby Central's open source work was supported by 35 different companies, including Ruby member[ Zendesk](https://zendesk.com/?ref=rubycentral.org) and Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org).
In total, we were supported by 124 developer members. Thanks to all of our members for making everything that we do possible. <3
## RubyGems News
This month in RubyGems, we released RubyGems [3.4.8](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#348--2023-03-08), [3.4.9](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#349--2023-03-20), [3.4.10](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3410--2023-03-27) and Bundler [2.4.8](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#248-march-8-2023), [2.4.9](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#249-march-20-2023), and [2.4.10](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2410-march-27-2023).
The following improvements and fixes are included in these releases (see the changelog for more information):
- enhanced `tar` file functionality to support future server-side gem content navigation features - [#6494](https://github.com/rubygems/rubygems/pull/6494?ref=rubycentral.org), [#6476](https://github.com/rubygems/rubygems/pull/6476?ref=rubycentral.org), [#6390](https://github.com/rubygems/rubygems/pull/6390?ref=rubycentral.org).
- improved auto-healing of corrupted lockfiles and fixed some related regressions - [#6400](https://github.com/rubygems/rubygems/pull/6400?ref=rubycentral.org), [#6423](https://github.com/rubygems/rubygems/pull/6423?ref=rubycentral.org), [#6552](https://github.com/rubygems/rubygems/pull/6552?ref=rubycentral.org), [#6540](https://github.com/rubygems/rubygems/pull/6540?ref=rubycentral.org), [#6532](https://github.com/rubygems/rubygems/pull/6532?ref=rubycentral.org), [#6495](https://github.com/rubygems/rubygems/pull/6495?ref=rubycentral.org).
- fixed resolution edge cases - [#6330](https://github.com/rubygems/rubygems/pull/6330?ref=rubycentral.org), [#6442](https://github.com/rubygems/rubygems/pull/6442?ref=rubycentral.org), [#6441](https://github.com/rubygems/rubygems/pull/6441?ref=rubycentral.org), [#6535](https://github.com/rubygems/rubygems/pull/6535?ref=rubycentral.org).
- added support of OTP fallback when OTP and WebAuthn are enabled from the CLI - [#6523](https://github.com/rubygems/rubygems/pull/6523?ref=rubycentral.org).
- unified RubyGems and Bundler Rubocop rules - [#6487](https://github.com/rubygems/rubygems/pull/6487?ref=rubycentral.org).
Other improvements we worked on during this month that weren’t included in the March release are:
- fixed the `gems.rb` lockfile for Bundler version lookup in the template file - [#6413](https://github.com/rubygems/rubygems/pull/6413?ref=rubycentral.org).
- added gem version promoter specs - [#6537](https://github.com/rubygems/rubygems/pull/6537?ref=rubycentral.org).
- added a better suggestion when `bundler/setup` fails due to missing gems and Gemfile is not the default - [#6428](https://github.com/rubygems/rubygems/pull/6428?ref=rubycentral.org).
- removed an unhelpful side-effect of `GEM_HOME` configuration in some tests - [#6461](https://github.com/rubygems/rubygems/pull/6461?ref=rubycentral.org).
In March, RubyGems gained [332 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2023-03-01%7D...master@%7B2023-03-31%7D?ref=rubycentral.org), contributed by 14 authors. There were 4,504 additions and 3,236 deletions across 432 files.
## RubyGems.org News
Based on feedback from impacted users, we [pushed back deprecating the dependency API by one month](https://blog.rubygems.org/2023/04/07/dependency-api-deprecation-delayed.html?ref=rubycentral.org).
This month, RubyGems.org saw several bug fixes and updates, some of which include:
- added a default retry for application job - [#3539](https://github.com/rubygems/rubygems.org/pull/3539?ref=rubycentral.org).
- added a log tickets page to the admin dashboard - [#3586](https://github.com/rubygems/rubygems.org/pull/3586?ref=rubycentral.org).
- fixed Fastly soft purging - [#3619](https://github.com/rubygems/rubygems.org/pull/3619?ref=rubycentral.org).
- added a feature to allow an admin to reset the user API key from Admin Tools - [#3622](https://github.com/rubygems/rubygems.org/pull/3622?ref=rubycentral.org).
- fixed a flaky test by making `Rubygem#protected_days` stop at zero - [#3655](https://github.com/rubygems/rubygems.org/pull/3655?ref=rubycentral.org).
- disabled LaunchDarkly in local environments - [#3647](https://github.com/rubygems/rubygems.org/pull/3647?ref=rubycentral.org).
- renamed `GemContentEntry` to `RubygemContents::Entry` \- [#3669](https://github.com/rubygems/rubygems.org/pull/3669?ref=rubycentral.org).
- removed delayed job `statsd` deployment since it's no longer in use - [#3642](https://github.com/rubygems/rubygems.org/pull/3642?ref=rubycentral.org).
- stored and yanked gem contents in background jobs - [#3454](https://github.com/rubygems/rubygems.org/pull/3454?ref=rubycentral.org).
- added a response to the CLI on webauthn verification - [#3535](https://github.com/rubygems/rubygems.org/pull/3535?ref=rubycentral.org).
In March, RubyGems.org gained [190 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2023-03-01%7D...master@%7B2023-03-31%7D?ref=rubycentral.org), contributed by 15 authors. There were 7,437 additions and 2,105 deletions across 337 files.
## Total Spent
In March we completed 589 hours of development work @$150/hour, and spent $88,352.11.
## Thank you
Thank you to all the contributors of RubyGems and RubyGems.org for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### Contributors to RubyGems:
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@TonyCTHsu](https://github.com/TonyCTHsu?ref=rubycentral.org) TonyCTHsu
- [@orien](https://github.com/orien?ref=rubycentral.org) Orien Madgwick
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@johnnyshields](https://github.com/johnnyshields?ref=rubycentral.org) Johnny Shields
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@Julzerator](https://github.com/Julzerator?ref=rubycentral.org) Julie Haehn
- [@KJTsanaktsidis](https://github.com/KJTsanaktsidis?ref=rubycentral.org) KJ Tsanaktsidis
- [@MSP-Greg](https://github.com/MSP-Greg?ref=rubycentral.org) MSP-Greg
- [@voxik](https://github.com/voxik?ref=rubycentral.org) Vít Ondruch
### Contributors to RubyGems.org:
- [@stirlhoss](https://github.com/stirlhoss?ref=rubycentral.org) Stirling Hostetter
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@y-yagi](https://github.com/y-yagi?ref=rubycentral.org) y-yagi
- [@ericherscovich](https://github.com/ericherscovich?ref=rubycentral.org) Eric Herscovich
- [@jchestershopify](https://github.com/jchestershopify?ref=rubycentral.org) Jacques Chester
- [@jenshenny](https://github.com/jenshenny?ref=rubycentral.org) Jenny Shen
- [@cprodhomme](https://github.com/cprodhomme?ref=rubycentral.org) Clément Prod'homme
- [@arunagw](https://github.com/arunagw?ref=rubycentral.org) Arun Agrawal
- [@aellispierce](https://github.com/aellispierce?ref=rubycentral.org) Ashley Ellis Pierce
### RailsConf 2023 Speaker Spotlight: Hilary Stohs-Krause
URL: https://rubycentral.org/news/railsconf-2023-speaker-spotlight-hilary-stohs-krause/
Last updated: 2023-04-20T17:07:59.000Z
RailsConf always boasts an exciting variety of talks that highlight the creativity and interdisciplinary nature of the Ruby community. As a tech sector newcomer, I thought it would be fun to curate a series highlighting speakers whose stories about their experiences in tech captured my curiosity. Read on for today’s speaker spotlight…
### Title of Talk:
How We Implemented Internal Salary Transparency (And Why It Matters)
### Speaker:
Hilary Stohs-Krause

### How Did you get into Ruby?
I attended a programming bootcamp about 8 years ago and have never looked back!
### What’s your favorite part about working on Open Source Software?
My favorite part of open source is the opportunity to give back to projects that help solve my problems, and also the ability to contribute my own solutions for other people's problems.
### What’s your least favorite part about working on OSS?
My least favorite part of working on open source is trying to prioritize maintaining gems I created but no longer use 🫣
### What inspired you to give this talk?
There's been a surge of interest in salary transparency as a tool for equity over the last few years, and having been through various iterations of implementing transparency at our company, I thought it could be helpful for folks to hear a first-person perspective.
### What do you want people to take away from it?
There are so many different ways to implement wage transparency, and getting started can be easier than people might think. It doesn't have to be some grand overhaul of company policy - you can start small, and work your way up.
### What are you most looking forward to at this conference?
Seeing all my #RubyFriends!
### Do you have any other fun plans in Atlanta during the in-person conference week?
I'm hoping to check out the botanical gardens.
### Thank you, Hilary, for sharing a bit of your story. See you at RailsConf 2023!
### RailsConf 2023 Speaker Spotlight: Crux Conception, M. Psych
URL: https://rubycentral.org/news/railsconf-2023-speaker-spotlight-crux-conception/
Last updated: 2024-03-28T19:56:46.000Z
RailsConf always boasts an exciting variety of talks that highlight the creativity and interdisciplinary nature of the Ruby community. As a tech sector newcomer, I thought it would be fun to curate a series highlighting speakers whose stories about their experiences in tech captured my curiosity. Read on for today’s speaker spotlight…
### Title of Talk:
Artificial Intelligence & Race: Does AI have issues with racial bias?
### Speaker:
Crux Conception, M. Psych

### How Did you get into Ruby?
Although I may not be a Ruby expert myself, my experience in developing teams and facilitating communication has given me insight into the value of the Ruby programming language. As someone specializing in soft skills, I understand how important it is for a team to communicate effectively. Ruby's syntax has proven to be more easily readable and understood than other languages. Furthermore, my background in psychology has taught me the importance of team building and cohesiveness in any project. The Ruby users and developers community is often praised for its friendly and inclusive culture, which can significantly benefit the success of collaborative projects. Using Ruby in web development has numerous advantages even outside the programming community. Its simplicity and flexibility allow for quicker development and updates, and it has been widely adopted for its scalability and efficiency. So while I may not be a technical expert in Ruby, my soft skills expertise has given me an understanding and appreciation for its value in building successful teams and projects.
### What’s your favorite part about working on Open Source Software?
One of the significant advantages of working on open-source software is the ability to learn from experienced developers and contribute to projects that benefit the software ecosystem. Open-source software projects offer great opportunities for developers to improve their coding skills, build their resumes, and gain recognition for their work. Contributing to open-source software demonstrates experience collaborating with other developers to solve problems and deliver quality software. Contributing to open-source software is an excellent way for developers to learn, grow, and positively impact society while showcasing their coding expertise and building a robust portfolio.
### What’s your least favorite part about working on OSS?
This is from a beginner's perspective; therefore, I only have a few favorite parts about working on OSS because I'm new to the game and still trying to figure everything out. It's all exciting and new to me. As I gain more experience with OSS, it can sometimes be frustrating. One of the biggest challenges is dealing with issues and bugs reported on the project. Trying to sort through all the feedback and prioritize what needs to be fixed first can be overwhelming. Additionally, working on OSS is often a volunteer activity, so balancing OSS contributions with other commitments can be a struggle. It requires a lot of dedication and time management skills to make meaningful contributions to a project while juggling other responsibilities.
### What inspired you to give this talk?
As a now-retired Homicide Detective, I arrested the wrong individual based on Artificial Intelligence (Facial Recognition). The individual spent four years in prison, and later, his conviction was overturned. I began to conduct research and submitted questionnaires and interviews throughout the technology community. My findings lead me to this presentation. The presence of AI is permeating our daily lives at an unprecedented rate. From having our speed and traffic violations recorded at every stoplight via a computer-generated AI with facial recognition software to systems that immediately analyze a criminal’s fingerprints, it impacts us in many ways we do not even notice. Artificial Intelligence is on our streets, in our grocery stores, and even in our homes. As a person of color, the inspiration for giving a talk on Artificial Intelligence and Racial Bias in law enforcement comes from personal experiences and the collective experiences of many others like me. We've witnessed an alarming trend of racial profiling and discrimination in law enforcement, which is even more problematic with the increasing use of Artificial Intelligence technologies. AI algorithms used in law enforcement have demonstrated significant racial biases. Facial recognition software, notably, is less accurate when identifying people of color, leading to wrongful arrests and accusations. Given the sheer scale of these issues, it is not surprising that people of color are deeply concerned about the potential for AI to exacerbate racial discrimination in law enforcement. As AI continues to be integrated into criminal justice systems, there is a significant risk that existing biases and stereotypes will be further entrenched in policy and practice. By bringing attention to the problem of AI and racial bias, it is hoped that informed policy and robust ethical standards can be developed to ensure that technology works to eliminate racial disparity rather than perpetuate them.
### What do you want people to take away from it?
Facial recognition technology, while offering benefits like fast identification and improved security, is prone to biases, particularly ethnic partiality, due to inaccurate data and preconceptions. To address this, more developer training is needed to reduce biases in algorithms. Future development should emphasize inclusivity, ensuring fairness for all individuals. Developers must also understand the differences between public and real-life data, adapt their models to eliminate preconceptions, and utilize distinctive intelligence to improve the technology's accuracy, fairness, and inclusivity.
### What are you most looking forward to at this conference?
I am most looking forward to the diverse range of topics and levels of expertise that the speakers and attendees will cover. There will be opportunities to learn from experts in the field and gain a deeper understanding of building and managing Rails applications. In addition to the educational opportunities, I am also excited to network with developers and discover new tools, resources, and partnerships in the industry. Overall, I believe that RailsConf offers an incredible opportunity to enhance my understanding and proficiency in Rails development and connect with a passionate and knowledgeable community of developers from around the world.
### Do you have any other fun plans in Atlanta during the in-person conference week?
I am excited about the upcoming in-person conference in "A". One of the things that I am looking forward to is flying my drone and capturing the views of Georgia's breathtaking scenery. In addition to this, I am an avid poet and make it my point to attend local poetry slams wherever I travel. The open-mic format is an excellent way to showcase one's creative talents and share unique perspectives on life. I will check in to see if any poetry slams are during the week and plan on attending at least one. And if there is time, I have a raincheck to swim with the whale sharks at the Georgia Aquarium. During my last trip to Atlanta, I had made plans to give my keynote speech underwater. However, my scuba diver certificate expired.
### Thank you, Crux, for sharing a bit of your story. See you at RailsConf 2023!
### RailsConf 2023 Speaker Spotlight: Alicia Rojas
URL: https://rubycentral.org/news/railsconf-2023-speaker-spotlight-title-of-talk-speaker-how-did-you-get-into-ruby-whats-your-favorite-part-about-working-on-open-source-software-whats-your-least-favorite-part-about-work/
Last updated: 2023-04-06T20:00:09.000Z
RailsConf always boasts an exciting variety of talks that highlight the creativity and interdisciplinary nature of the Ruby community. As a tech sector newcomer, I thought it would be fun to curate a series highlighting speakers whose stories about their experiences in tech captured my curiosity. Read on for today’s speaker spotlight…
### Title of Talk:
Building an offline experience with a Rails-powered PWA
### Speaker:
Alicia Rojas

### How did you get into Ruby?
I started coding at a remote school during the 2020 lockdown. Ruby on Rails was in the study program so I did it :)
### What’s your favorite part about working on Open Source Software?
The spirit of collaboration and collective learning that characterizes communities of users and contributors. In OSS communities you often find people willing to help who ask for nothing in return.
### What’s your least favorite part about working on OSS?
The fact that some good projects cease to be sustainable because they lack a strong community to sustain them. Most companies do not consider contributing to OSS as part of their responsibilities even though they profit from it. Many great and useful projects die because maintainers can no longer work on them due to their paid jobs.
### What inspired you to give this talk?
I am motivated to share what I have learned and encourage more developers to use technology to create products that improve the lives of people who are not normally considered by the industry, such as rural people, and also to use our tools to address the climate crisis. Additionally, attending RailsConf last year made me realize that my level of knowledge was not as basic as I thought, and also that the representation of Latin American women giving talks was very low.
### What do you want people to take away from it?
\- Basic and practical knowledge about how to turn a rails app into a PWA using the MVC pattern and Hotwire.
\- To become more aware of potencial non-conventional audiences for our apps and their challenges.
### What are you most looking forward to at this conference?
Sharing with the Rails community again :)
### Do you have any other fun plans in Atlanta during the in-person conference week?
Nothing as of yet
### Thank you, Alicia, for sharing a bit of your story. See you at RailsConf 2023!
### What We Do at Ruby Central
URL: https://rubycentral.org/news/what-we-do-at-ruby-central/
Last updated: 2024-01-24T18:24:11.000Z
You may know Ruby Central as the host of RubyConf and RailsConf over the past two decades, but in reality, we do [so much more](https://rubycentral.org/history/). At a panel discussion during RubyConf 2022, the Ruby Central board laid out the organization's growing role in the Ruby community over time – from the creation of RubyGems to its efforts to improve diversity and inclusion, as well as its growing role in supporting the open source work Rubyists rely on to maintain core infrastructure like Bundler.

In 2023, as we emerge from the initial shock of the COVID pandemic, we have a new team, an updated conference structure, and even more ambitious goals. Ruby Central is excited to be in a position to expand its support of Rubyists even further and “help the community thrive both technically and non-technically,” as board member Allison McMillan put it. For example, on the infrastructure side, the team is excited to have identified [new sources of funding](https://rubycentral.org/news/ruby-shield/) to support Ruby maintainers in providing more robust and sustainable maintenance of RubyGems and Bundler. When it comes to supporting new Ruby community members, we have been enhancing our [Scholars and Guides program](https://railsconf.org/blog/scholars-and-guides?ref=rubycentral.org) to provide more ongoing support for underrepresented community members interested in learning the Ruby programming language.
"And this is only the first step,” says McMillan. “Ideally, in years to come, we'll be expanding additional educational offerings and support, more globally-inclusive events and activities, and connecting more folks in the community with one another to maintain the close-knit feeling that the ruby community has historically had."
Here are a few of the ideas we’re excited about as we look to the future:
- Even more sources of funding
- Community building and continuity between conferences, including:
- expanding the Scholar and Guides program to potentially be year round
- regional conferences
- grant programs
- Continuing education - finding ways to help new members join the community outside of the conferences
- Connecting to local Ruby communities
- Creating a more robust CFP pipeline: coaching, mentorship, speaker training
- We also look forward to collaborating with you and the community on what you want to see from Ruby Central!
### Help shape Ruby Central’s role in the community
As always, we want to hear from you! If you’re interested in making your voice heard as Ruby Central grows, here are a few ways to connect with us:
- [Reach out directly to our leadership team](mailto:hello@rubycentral.org).
- Come talk to the board at conferences. We’d love to say hi and hear what you want us to keep doing and what you didn’t like. At RailsConf 2023 we’ll be carving out space specifically for you to get some face time with us at the RailsConf check-in booth and during the Ruby Central town hall on Tuesday April 25th at 1:30 pm.
- Fill out the conference surveys you receive and give us your honest feedback.
Also, stay tuned for opportunities to get involved behind the scenes at Ruby Central.
We look forward to collaborating with you to build the future for the Ruby community that we all want to see.
### RailsConf 2023 Speaker Spotlight: Selena Small
URL: https://rubycentral.org/news/railsconf-2023-speaker-spotlight/
Last updated: 2023-03-30T15:21:52.000Z
RailsConf always boasts an exciting variety of talks that highlight the creativity and interdisciplinary nature of the Ruby community. As a tech sector newcomer, I thought it would be fun to curate a series highlighting speakers whose stories about their experiences in tech captured my curiosity. Read on for today’s speaker spotlight…
## Title of Talk:
10x your teamwork through pair programming
## Speaker:
Selena Small

## How Did you get into Ruby?
I was working as a bar tender in a night club and Tom the regular would come in, he started teaching to me to code - first Assembly 68k, then C, then Ruby and I never looked back!
## What’s your favorite part about working on Open Source Software?
While I don't actively contribute, but developing the open means ideas can be easily shared and I rely on that.
## What’s your least favorite part about working on OSS?
OSS doesn't promote pair-programming and doesn't always promote good TDD practices.
## What inspired you to give this talk?
I've been working in a heavy pairing environment for the last 6 years and have learned the benefits - I want to share those with the world because there are a lot of misconceptions about what it is and what's involved. What makes a great pairing environment is what organisations often strive to be able to claim - a strong sense of psychological safety and collaboration to deliver better outcomes than what an individual can do alone.
## What do you want people to take away from it?
Software is about people. Two heads are better than one. Be vulnerable and give it a try.
## What are you most looking forward to at this conference?
Meeting some really cool people and enjoying some great social events.
## Do you have any other fun plans in Atlanta during the in-person conference week?
[What is there to do in Atlanta?](https://railsconf.org/location?ref=rubycentral.org)
## Thanks, Selena, for sharing a bit of your story. See you at RailsConf 2023!
### The Ruby Central board: where we’ve been and where we’re headed
URL: https://rubycentral.org/news/ruby-central-board/
Last updated: 2023-12-04T21:55:03.000Z
When Ruby Central was founded in 2001 it was a small operation focused solely on organizing RubyConf, now the world's largest and longest-running gathering of Rubyists, which launched the same year. Twenty-two years later, Ruby Central is in an era of expansion! New board member roles were recently announced and as we move toward some exciting new goals and plans this year, we thought it would be a good time to share a look at the role of the Ruby Central board, how it’s changed and where we’re headed.

**A look back**
The growth of Ruby Central has been steady and intentional. The board is made up entirely of volunteers, who are passionate Ruby community members. Over the last two decades team members have stepped in and out to support Ruby Central’s mission, and support one another (and prevent burnout!). As Ruby Central grows and changes its mission has been able to grow and change with it.
**2001 - 2011:** Founders David Alan Black and Chad Fowler, both organizers of the inaugural RubyConf in 2001 in Tampa, and Rich Kilmer, make the decision to establish Ruby Central as a nonprofit organization. They serve as its only board members until 2011\.
**2012:** Ruby Central takes over show running of RailsConf. Previous to this, the conference was co-produced with O’Reilly Media.
Ruby Central brings on first staff member, Abby Phoenix who joins as its sole employee, to run both RubyConf and RailsConf. Prior to this, the board members ran all aspects of the conferences.
Ben Scofield who had been helping organize RailsConf, joins as a board member along with Evan Phoenix, who had been helping run [rubygems.org](http://rubygems.org/?ref=rubycentral.org), as Chad Fowler and Rich Kilmer step down from their board roles, and David Black steps back into an advisory role.
Ruby Central board grows to three members: Ben and Evan realize they need a third active board member and reach out to Marty Haught, who had been hosting a Rocky Mountain RubyConf event, and he agrees to join.
**2014**: Ben steps down from board and Sarah Mei joins to replace him.
**2019:** The Board decides to expand to six members, with an eye toward a more sustainable team and a greater capacity and potential for growth for Ruby Central as the organization seeks to do more for the Ruby community.
Barrett Clark, Allison McMillan, Fable Tales, and Max Tiu join Marty and Evan to round out the board. Sarah steps down.
**2020:** Ruby Central merges with Ruby Together, bringing support of the vital Ruby infrastructure development under its umbrella.
Former Ruby Together board members Adarsh Pandit, Valerie Woolard and Jonan Scheffler, join. Barrett steps down.
**2020 - 2022:**
Max steps down. Chelsea Kaufman joins in October of 2022.
Ruby Central reimagines its role in the community. The pandemic makes it clear that conferences aren’t the only way to serve the Ruby community. The board sets new goals: On top of the conferences, what more can we do to support the growth of the community — not just in the US but all over the world — and the programming language?
**How the current board runs**
Here’s what your [2023 Ruby Central board](https://rubycentral.org/#directors) have to say about how they run things:
> The board of directors for Ruby Central are representatives from the community and are here to help make sure everything runs smoothly. We meet once a month and we all take turns working as co-chairs of the conferences.

> Here are some of the other key things we do:
> **We decide what the organization is all about:** We set the mission and goals, and make sure everything the organization does lines up with those. We make sure the mission aligns with what the community needs.
> **We hire and keep an eye on the boss:** We hire and evaluate the executive director, who runs things day-to-day.
> **We keep the organization's finances in good shape:** We make sure there's enough money, set the budget, and make sure everyone is following the rules.
> **We follow the law and do what's right:** we make sure the organization is doing things legally and ethically.
> **We bring in the cash:** We find ways to raise money, like getting donations, applying for grants, and partnering with other groups.
> **We keep the board strong:** We make sure it's made up of the right people, train them, and set rules for how it should run.
> Basically, we are a group of people who make sure Ruby Central is doing what it's supposed to do, and doing it in a responsible way.
“The organization is here for the community,” said board president Chelsea Kaufman on a panel at RubyConf 2022\. The board emphasized how important it is to them to receive feedback and collaborate with Rubyists as Ruby Central grows. “Tell us your thoughts. Your voices really matter to us,” she added.
This is a very exciting time for us at Ruby Central. If you have questions or ideas for the Ruby Central board as we expand in new directions, please don’t hesitate to reach out to us at .
### Countdown to RailsConf 2023!
URL: https://rubycentral.org/news/countdown-to-railsconf-2023/
Last updated: 2023-05-05T16:27:44.000Z
We’re just about a month away from [RailsConf ](https://railsconf.org/?ref=rubycentral.org)in Atlanta! We can’t wait to gather with you for this year’s exciting lineup of talks, workshops, and keynote speakers. [You can still get a ticket here](https://www.eventbrite.com/e/railsconf-2023-atlanta-tickets-514117357857?ref=rubycentral.org), although they are going very fast!

In the meantime, [watch this space](http://railsconf2023.sessionize.com/?ref=rubycentral.org) for the program schedule, and keep in mind these important dates and details to help you plan for your best conference experience:
**Room reservation cut-off date**
The last day to [book a room](https://railsconf.org/location?ref=rubycentral.org) at The Westin Peachtree Plaza, Atlanta, where RailsConf will take place, is Thursday, March 30 (5:00 PM ET).
**Ticket sales and registration cancellation cut-off date**
The last day to buy a conference ticket is Saturday, April 22 (11:59PM ET). The last day to receive a refund for a ticket you’ve already purchased is Friday, April 21 (11:59PM ET). You can learn more about our refund policy at the bottom of the page [here](https://railsconf.org/register?ref=rubycentral.org).
**Lactation room deadline**
The last day to request a time in the private lactation room at the conference is Friday, March 31 (5:00 PM ET).
**COVID guidelines**
Please make sure to read our COVID guidelines ahead of attending this year’s conference. They can be found at the bottom of the page [here](https://railsconf.org/register?ref=rubycentral.org).
**Workshop and social events sign-ups**
Coming soon! Watch this space and stay tuned to our social media channels as we update with information on how to RSVP for conference workshops and our official social events.
As always, if you still have RailsConf2023 questions, please don’t hesitate to reach out to us at [railsconf@rubycentral.org](mailto:railsconf@rubycentral.org). We can’t wait to see you in Atlanta!
### February 2023 Monthly Update
URL: https://rubycentral.org/news/february-2023-monthly-update/
Last updated: 2023-06-16T20:27:07.000Z
Hello! Welcome to the monthly update. During February, our work was supported by [Shopify](https://www.shopify.com/?ref=rubycentral.org), [Zendesk](https://zendesk.com/?ref=rubycentral.org) and many others.
## Ruby Central News
In February, Ruby Central's open source work was supported by 35 different companies, including Ruby member[ Zendesk](https://zendesk.com/?ref=rubycentral.org) and Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org).
In total, we were supported by 124 developer members. Thanks to all of our members for making everything that we do possible. <3
## RubyGems News
This month in [RubyGems](https://github.com/rubygems/rubygems?ref=rubycentral.org), we released RubyGems [3.4.7](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#347--2023-02-15) and Bundler [2.4.7](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#247-february-15-2023).
The following improvements and fixes are included in these releases (see the changelog for more information):
- added a `--gemfile` flag to the `bundle init` command to configure the gemfile name to be able to generate a custom name - [#6046](https://github.com/rubygems/rubygems/pull/6046?ref=rubycentral.org).
- added a warning on self-referencing gemspec dependencies - [#6335](https://github.com/rubygems/rubygems/pull/6335?ref=rubycentral.org).
- fixed inconsistent behavior of zero-byte files in one of the archives - [#6329](https://github.com/rubygems/rubygems/pull/6329?ref=rubycentral.org).
- restored older (better) version of error message when locked ref does not exist, to improve clarity - [#6356](https://github.com/rubygems/rubygems/pull/6356?ref=rubycentral.org).
- fixed gem crashing when installing from a corrupted lockfile - [#6355](https://github.com/rubygems/rubygems/pull/6355?ref=rubycentral.org).
- fixed crash in PubGrub involving empty ranges - [#6365](https://github.com/rubygems/rubygems/pull/6365?ref=rubycentral.org).
Other improvements we worked on this month that weren't included in the February release are:
- adding an experimental feature for the `gem exec` command to run executables from gems that may or may not be installed - [#6309](https://github.com/rubygems/rubygems/pull/6309?ref=rubycentral.org).
- implementing safe load for all marshaled data - [#6384](https://github.com/rubygems/rubygems/pull/6384?ref=rubycentral.org).
- making the gemspec file generated by bundle gem properly exclude itself from packaged gem - [#6339](https://github.com/rubygems/rubygems/pull/6339?ref=rubycentral.org).
- preserving `bundler-setup-relative` paths if the `:path` option is set to relative in standalone setup - [#6327](https://github.com/rubygems/rubygems/pull/6327?ref=rubycentral.org).
In February, RubyGems gained [108 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2023-02-01%7D...master@%7B2023-02-28%7D?ref=rubycentral.org), contributed by 16 authors. There were 1,744 additions and 217 deletions across 100 files.
## RubyGems.org News
This month, we made significant progress on the backend admin dashboard. We implemented robust auditing of all changes and added support for resetting users' MFA, blocking a user, and deleting webhooks.

We [announced](https://blog.rubygems.org/2023/02/22/dependency-api-deprecation.html?ref=rubycentral.org) the deprecation of the dependency API, and we plan to implement brownouts and remove the endpoint entirely. We also migrated all RDS instances to be managed by Terraform and tested the migration of managed node groups on the rubygems.org EKS cluster.
In addition to these updates, RubyGems.org saw several bug fixes and updates, some of which include:
- the addition of telemetry to capture MFA login durations - [#3376](https://github.com/rubygems/rubygems.org/pull/3376?ref=rubycentral.org).
- the integration of DataDog for application performance monitoring - [#3461](https://github.com/rubygems/rubygems.org/pull/3461?ref=rubycentral.org).
- the set up of GitHub OAuth to protect the new /admin namespace - [#3388](https://github.com/rubygems/rubygems.org/pull/3388?ref=rubycentral.org).
- an updated Rails test job name for stability across version updates - [#3420](https://github.com/rubygems/rubygems.org/pull/3420?ref=rubycentral.org).
- fixed test avo warnings (via removal of redundant rake tasks loading) - [#3422](https://github.com/rubygems/rubygems.org/pull/3422?ref=rubycentral.org).
- an added avo MFA reset admin action & view of audit entries - [#3426](https://github.com/rubygems/rubygems.org/pull/3426?ref=rubycentral.org).
- a fixed ERD CI (via an updated `erd.dot`) - [#3490](https://github.com/rubygems/rubygems.org/pull/3490?ref=rubycentral.org).
- an updated Terraform package: `0.13.7 -> 1.3.9`.
- updated Terraform providers packages: AWS `2.51 -> 4.54`, external `1.2 -> 2.2`, Kubernetes `1.8 -> 2.18`,template `2.1 -> 2.3`.
In February, RubyGems.org gained [209 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2023-02-01%7D...master@%7B2023-02-28%7D?ref=rubycentral.org), contributed by 17 authors. There were 7,602 additions and 1,071 deletions across 273 files.
## Ruby Ecosystem News
Here we outline additional exciting updates made to other projects in the Ruby Ecosystem.
**New: Ruby SSL Check**
- we updated `ruby-ssl-check` to print a warning if you're using an unmaintained version of Ruby - [#14](https://github.com/rubygems/ruby-ssl-check/pull/14?ref=rubycentral.org).
As always, we continue to fix bugs, review and merge PRs and reply to support tickets.
## Total Spent
In February we completed 978 hours of development work @$150/hour, and spent $146,653.05.
## Thank you
Thank you to all the contributors of RubyGems and RubyGems.org for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### Contributors to RubyGems:
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@amatsuda](https://github.com/amatsuda?ref=rubycentral.org) Akira Matsuda
- [@sambostock](https://github.com/sambostock?ref=rubycentral.org) Sam Bostock
- [@composerinteralia](https://github.com/composerinteralia?ref=rubycentral.org) Daniel Colson
- [@koic](https://github.com/koic?ref=rubycentral.org) Koichi ITO
- [@jhawthorn](https://github.com/jhawthorn?ref=rubycentral.org) John Hawthorn
- [@gustavothecoder](https://github.com/gustavothecoder?ref=rubycentral.org) Gustavo Ribeiro
- [@mercedesb](https://github.com/mercedesb?ref=rubycentral.org) Mercedes
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@luke-gru](https://github.com/luke-gru?ref=rubycentral.org) Luke Gruber
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
### Contributors to RubyGems.org:
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@jenshenny](https://github.com/jenshenny?ref=rubycentral.org) Jenny Shen
- [@bettymakes](https://github.com/bettymakes?ref=rubycentral.org) Betty Li
- [@ericherscovich](https://github.com/ericherscovich?ref=rubycentral.org) Eric Herscovich
- [@arunagw](https://github.com/arunagw?ref=rubycentral.org) Arun Agrawal
- [@sambostock](https://github.com/sambostock?ref=rubycentral.org) Sam Bostock
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@indirect](https://github.com/indirect?ref=rubycentral.org) André Arko
- [@jchestershopify](https://github.com/jchestershopify?ref=rubycentral.org) Jacques Chester
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@javier-menendez](https://github.com/javier-menendez?ref=rubycentral.org) Javier Menéndez Rizo
### Mastodon Development Now Supported by Ruby Central
URL: https://rubycentral.org/news/mastodon-development-now-supported-by-ruby-central/
Last updated: 2023-03-21T18:30:04.000Z

We’re proud to announce that Ruby Central is now a platinum sponsor of Mastodon! We’re also a now top tier Patreon of ruby.social, the official Ruby Central instance. You can follow us at[ @rubycentral@ruby.social](https://ruby.social/@rubycentral?ref=rubycentral.org) for the latest news on upcoming conferences, projects and other exciting updates.
### January 2023 Monthly Update
URL: https://rubycentral.org/news/january-2023-monthly-update/
Last updated: 2023-06-16T20:26:03.000Z
Hello! Welcome to the monthly update. During January, our work was supported by [Shopify](https://www.shopify.com/?ref=rubycentral.org), [Zendesk](https://zendesk.com/?ref=rubycentral.org) and many others.
## Ruby Central News
In January, Ruby Central's open source work was supported by 35 different companies, including Ruby member[ Zendesk](https://zendesk.com/?ref=rubycentral.org) and Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org).
On top of those companies, 1 developer, Abdullah Esmail, joined as a new member. In total, we were supported by 124 developer members. Thanks to all of our members for making everything that we do possible. <3
## RubyGems News
This month in[ RubyGems](https://github.com/rubygems/rubygems?ref=rubycentral.org), we released RubyGems[ 3.4.2](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#342--2023-01-01),[ 3.4.3](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#343--2023-01-06),[ 3.4.4](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#344--2023-01-16),[ 3.4.5](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#345--2023-01-21),[ 3.4.6](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#346--2023-01-31) and Bundler[ 2.4.2](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#242-january-1-2023),[ 2.4.3](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#243-january-6-2023),[ 2.4.4](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#244-january-16-2023),[ 2.4.5](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#245-january-21-2023),[ 2.4.6](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#246-january-31-2023); here’s what shipped with these releases:
- allowing require decorations be disabled -[ #6319](https://github.com/rubygems/rubygems/pull/6319?ref=rubycentral.org).
- properly merging incompatibility ranges to speed up resolution -[ #6215](https://github.com/rubygems/rubygems/pull/6215?ref=rubycentral.org).
- turning the --ext option of bundle gem into a string and deprecating usage without explicit value -[ #6144](https://github.com/rubygems/rubygems/pull/6144?ref=rubycentral.org).
- Enhancing the bundle open command to allow opening a directory or file for a gem -[ #6146](https://github.com/rubygems/rubygems/pull/6146?ref=rubycentral.org).
Additional improvements and fixes we made this month include the following (see the changelog for more information):
- fixed flakiness on Ruby 3.2 and Windows and sped up some specs -[ #6321](https://github.com/rubygems/rubygems/pull/6321?ref=rubycentral.org).
- updated the list of SPDX license identifiers -[ #6310](https://github.com/rubygems/rubygems/pull/6310?ref=rubycentral.org).
- added tests for old lockfiles with new ruby versions -[ #6317](https://github.com/rubygems/rubygems/pull/6317?ref=rubycentral.org).
- stopped packages for external platforms from being introduced in the lockfile in instances when Bundler retries resolution -[ #6285](https://github.com/rubygems/rubygems/pull/6285?ref=rubycentral.org).
In January, RubyGems gained[ 158 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2023-01-01%7D...master@%7B2023-01-31%7D?ref=rubycentral.org), contributed by 14 authors. There were 3,450 additions and 2,535 deletions across 112 files.
## RubyGems.org News
In January, RubyGems.org saw several bug fixes and updates, some of which include:
- an added Webauthn Verification authenticate endpoint -[ #3331](https://github.com/rubygems/rubygems.org/pull/3331?ref=rubycentral.org).
- moving browser tests to standard Rails system tests-[ #3374](https://github.com/rubygems/rubygems.org/pull/3374?ref=rubycentral.org).
- an added patch for the mfa\_expires\_at edge condition -[ #3357](https://github.com/rubygems/rubygems.org/pull/3357?ref=rubycentral.org).
- a simplified version of GitHub button JS. -[ #3348](https://github.com/rubygems/rubygems.org/pull/3348?ref=rubycentral.org).
- the addition of telemetry to capture MFA login durations -[ #3376](https://github.com/rubygems/rubygems.org/pull/3376?ref=rubycentral.org).
- introducing a timeout after inactivity on the OTP page -[ #3325](https://github.com/rubygems/rubygems.org/pull/3325?ref=rubycentral.org).
This month, RubyGems.org gained[ 86 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2023-01-01%7D...master@%7B2023-01-31%7D?ref=rubycentral.org), contributed by 12 authors. There were 584 additions and 395 deletions across 46 files.
As always, we continue to fix bugs, review and merge PRs and reply to support tickets.
## Total Spent
In January we completed 458 hours of development work @$150/hour, and spent $68,749.50.
## Thank you
Thank you to all the contributors of RubyGems and RubyGems.org for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### Contributors to RubyGems:
- [@composerinteralia](https://github.com/composerinteralia?ref=rubycentral.org) Daniel Colson
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@yoka](https://github.com/yoka?ref=rubycentral.org) Jesse Ikonen
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@technicalpickles](https://github.com/technicalpickles?ref=rubycentral.org) Josh Nichols
- [@jdufresne](https://github.com/jdufresne?ref=rubycentral.org) Jon Dufresne
- [@markdoliner](https://github.com/markdoliner?ref=rubycentral.org) Mark Doliner
- [@matsadler](https://github.com/matsadler?ref=rubycentral.org) Mat Sadler
- [@flavorjones](https://github.com/flavorjones?ref=rubycentral.org) Mike Dalessio
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
- [@tbates-redarc](https://github.com/tbates-redarc?ref=rubycentral.org) Tim Bates
- [@fxn](https://github.com/fxn?ref=rubycentral.org) Xavier Noria
### Contributors to RubyGems.org:
- [@sonalkr132](https://github.com/sonalkr132?ref=rubycentral.org) Aditya Prakash
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
- [@ericherscovich](https://github.com/ericherscovich?ref=rubycentral.org) Eric Herscovich
- [@jenshenny](https://github.com/jenshenny?ref=rubycentral.org) Jenny Shen
- [@jchestershopify](https://github.com/jchestershopify?ref=rubycentral.org) Jacques Chester
- [@mercedesb](https://github.com/mercedesb?ref=rubycentral.org) Mercedes
- [@arunagw](https://github.com/arunagw?ref=rubycentral.org) Arun Agrawal
- [@segiddins](https://github.com/segiddins?ref=rubycentral.org) Samuel Giddins
### How this year's RailsConf 2023 tracks will help you become a more well rounded developer
URL: https://rubycentral.org/news/railsconf-2023-has-a-new-feature-community-curated-tracks/
Last updated: 2023-02-22T18:56:20.000Z
Last year in a preview for RailsConf we highlighted the conference tracks (organized lineups of talks and workshops that focus on a particular themed category) and featured program committee members who shared why they were excited about the tracks they submitted, who they recommended each one for, and what it might be like to try following a track throughout the conference. As [RailsConf 2023](https://railsconf.org/?ref=rubycentral.org) approaches, this year’s program committee is doing things differently, setting a new paradigm for not only RailsConf but possibly future Ruby Central conferences to come.
I caught up with the program committee chairs to hear more about their approach to creating this year’s RailsConf tracks, what they’re excited about when it comes to CFP submissions this year, and how you can help shape this year’s conference whether you’re applying to give a talk or simply registering to attend.

### A collaborative CFP process
With all of the exciting changes and conversations happening in the Ruby world — like the influx of social media users to Mastodon (a Rails platform) and the corresponding increase in interest in Activitypub and use of the Fediverse — this year’s RailsConf promises to spark some lively discussions. The conference tracks are being designed with an element of collaboration in mind. The program committee’s goal is to tune in to the conversations that are most important to the Ruby community at this moment and build the program from there. By offering broader track categories rather than selecting specific discussion prompts to guide submissions, the committee hopes to welcome a wider pool of potential participants to create a space for themselves in the program. This, in short, means almost all talk ideas are welcome!
“I was really interested in creating a voice for the community through the tracks,” says RailsConf 2023 program committee co-chair Chelsea Kaufman. “I think it’s really important…to make sure that we have talks coming to RailsConf that represent what the community wants to hear. We’re excited on our end that we’re going to shape the tracks and talks once we have all the CFPs,” she says.
Although there’s seemingly much more leeway for conference talk topics, the program committee decided to do away with the general track in favor of track themes.
“These tracks are not meant to tell them what we want to hear about. These tracks are designed to give them ideas,” says Jonan Scheffler, RailsConf 2023 program committee co-chair, to those considering submitting a talk proposal. “If their ideas do not conform to these tracks…we especially want to hear about it!” He encourages.
The program committee encourages potential speakers to help create a conference from the perspective of the whole developer. “We wanted to provide content that would help people generally…in their careers,” explains Scheffler.
### A closer look at the RailsConf 2023 tracks
The track categories listed on the RailsConf 2023 CFP offer some topic suggestions, but they each also explicitly invite the community to submit their own alternative ideas. The program committee will help guide selected talks into the track that is the best fit, allowing for an exciting potential variety of talks in each area. As you’re preparing your CFP submission or (if you’re not presenting) simply doing some early planning, it might help to hear more about the program committee’s goals in creating each track.
*Tech Skills*
The Tech Skills track is perfect for Rubyists who are “excited to share technology that they have been playing with, or a new gem that they’ve written, or something they’re interested in learning more about or sharing with their community,” says Scheffler.
For those attending or keeping their audience in mind, talks in this track will be ideal for those “looking to keep up with what’s coming out, or if you’re looking to improve or expand the scope of your technical ability,” he adds.
*People skills:*
“To me, the People \[Skills\] track is about the individual person, but also what does it mean to work with lots of different types of people,” says Kaufman.This track encourages conversations on management and leadership… diversity, inclusion, mentorship — “not just about how to find a mentor, but how to be a good mentor,” adds Kaufman.
For those submitting to the CFP, she hints at a topic she’s excited about: how to be a compassionate engineer.
*Community:*
Perhaps the most straightforward category, the Community track is about “how we nurture and grow the Rails community,” says Scheffler.
“For community organizers much of what it takes to keep a community engaged and thriving comes naturally, but remember that many of your peers find this topic particularly challenging," he adds. "If you're having a hard time coming up with an idea consider speaking about your own experience as a developer. What works, what doesn't, and which pieces of your strategy you personally found surprising.”
*Career:*
“Oh, man...this is my favorite track!” shares Kaufman of the Career track. “Especially in this climate with all the layoffs happening, there’s a lot of folks looking for the next thing; we have a lot of amazing people coming into the industry.”
She hopes to see a wide range of talks come into the CFP, including topics like finding the networks that help you continue to grow; and navigating the job search at any stage in your career — even as senior management.
In a time where there is an influx of tech workers looking for jobs, Kaufman and the RailsConf 2023 program committee encourage speakers in this track to contribute to “finding ways to support them and rally around them.”
### The best approach to RailsConf 2023
The potential breadth of topics is also something to be excited about for those attending the conference as non-presenters. Unlike other similar conferences focusing mainly on technical content, “RailsConf is special in that we like to talk about the whole person,” says Scheffler.
“I think that the way that we are shaping the conference, you have an opportunity to learn a little bit in a lot of different areas,” Kaufman adds.
Both program committee chairs agree that you’ll get the most out of this year’s RailsConf by attending talks in several different tracks. Attendees can take advantage of the wide variety of skills and advice available to round out their professional toolkits, both within and outside their niche.
“I recommend that people find talks that are interesting to them and mix and match according to their own interests,” says Scheffler. He also encourages folks to attend talks in tracks they may not have normally considered. “If you’re a tech person, stretch yourself and go to the community track. We want you to explore, don’t let the topics restrict your enjoyment,” he adds.
Don’t be afraid to choose a talk or two that feel unexpected or that don’t seem like the most popular in their track “You never know what you’re going to learn.. and you get an opportunity to really make some good connections with people, even in smaller settings,” Kaufman points out.
### How to make the most of the hallway track
Of course, if you’re not attending a talk, workshop, or any of the other official activities during a session but still want to participate in the conference, the hallway track is here for you. It can be a great way to take a break — which is an important part of a successful conference experience, Scheffler notes — while staying engaged. “Hallways are for making friends; talks are for having something to talk to your new friend about,” he says.
The possibility of making new connections in the hallway can be exciting, “but it can also be very intimidating,” acknowledges Kaufman. “For new folks that this is maybe their first conference, or they’re earlier in their career; for all of our introverts out there, me included, the hallway track can be scary to, like, walk up to somebody.”
Kaufman says it’s up to experienced Ruby community members to contribute to making a hallway track that is rewarding and worthwhile. Including people in conversations and talking to that attendee who is“maybe looking a little lost, or doesn’t know where they need to go next” all help create the welcoming environment that holds potential for the best conference connections/hallway experiences.
“We as a community get to shape the hallway track,” she says.
### Final thoughts
Whether you’re looking to submit a talk or just signing up to attend and participate in all the other aspects of the conference, this year’s RailsConf 2023 will be shaped by what you contribute. You can make the most of your experience by intentionally exploring the topics all the tracks have to offer and creating an enriching and kind environment in the hallways and conference third spaces.
And if you’re submitting a talk, don’t hesitate to bring out your most unique, unexpected, and unconventional ideas. Those are the ones that will make the tracks even more exciting and create a conference that allows us all to learn a holistic view of success in the Ruby community.
If you want personalized advice on your talk and you’re reading this when it’s published, there is one final coaching session[ happening today](https://www.eventbrite.com/e/call-for-proposal-cfp-coaching-session-tickets-536361430477?ref=rubycentral.org)! If you’ve missed the coaching session, check out[ these](https://rubycentral.org/news/5-reasons-to-turn-that-idea-into-a-rubyconf-2022-talk-/)[ blog](https://noelrappin.com/blog/2014/01/conference-prompts-or-how-to-submit-proposals-and-influence-people/?ref=rubycentral.org)[ posts](http://www.sarahmei.com/blog/2014/04/07/what-your-conference-proposal-is-missing/?ref=rubycentral.org), which offer encouragement, and a wealth of valuable wisdom on creating a powerful conference talk. You can think of them as a coaching session in blog form.
Bottom line, if you’re considering submitting to the CFP, the support is all there. So we hope you follow that impulse.
“There’s a lot of imposter syndrome around submitting talks. No one has ever seen the world in the way that you have, and everybody brings a different perspective,” Kaufman affirms. **“**That’s what’s going to make the conference a success.”
### Ruby Central Guide Spotlight
URL: https://rubycentral.org/news/rubyconf2022-guide-highlight/
Last updated: 2023-08-02T17:30:20.000Z
This week we’re highlighting members of our Scholars and Guides community, Ruby Central’s conference mentorship program which provides new and aspiring Rubyists with a supportive social and, if needed, a financial pathway to entering the tech community.
Today’s spotlight is a RubyConf2022 Guide. If you are thinking of attending the upcoming conference, becoming a Guide is a wonderful way to give back to the Ruby community and help continue to create the welcoming spirit that makes it so special. We hope this spotlight gives you a little insight into the experience and an extra nudge to “just do it!”
**Guide:**
Kyle Keesling
**Title:**
CTO

**What’s your favorite part about working on Open Source Software?**
I love the collaborative and altruistic nature of it. The fact that we are a group of folks with an expressed interest in helping others – often strangers that we'll never meet – build cool, interesting, and useful things is a unique thing that warrants celebrating.
**What’s your least favorite part about working on OSS?**
Occasionally you will see some people that mistake the generosity of others’ time and efforts as something they are entitled to. We should never take folks' work for granted.
**How did you get into Ruby?**
I taught myself Ruby when my partners and I came up with the idea for our SaaS business. I was relatively new to OOP but had been making static HTML websites for years. The quality of life features and tools that Ruby and Rails provided made me an instant convert, and I haven't looked back since.
**Why did you become a part of the Scholars/Guides program?**
As someone who's been a part of the community for over 10 years, I'm also a team of one, with nearly all of my development work being done solo. I've appreciated the efficiencies and power that Ruby and its community have afforded me, and want to make sure that others continue learning and benefit from it. I also think it's important for folks to see that there are many different paths to happiness in our community, whether it's working for a large company, or for yourself.
**What did it take for you to go from feeling like you had to work completely solo to engaging in the community through conferences?**
As I wanted to grow more and learn more, I started using google search and finding resources. I found a lot of free resources. It seemed very unique that the Rails/Ruby community had many people willing to write about \[their projects\] because they wanted to share how cool they thought \[their projects\] were.
Being by yourself, you don’t really know how well you’re doing or if you’re doing things right. Engaging with others — you find people you can have these discussions with, and get feedback. Build friendships. Beat imposter syndrome — and realize everyone feels the same way.
**Can you speak to the level of awareness about different career paths for people new to Ruby or the industry in general?**
Traditionally people think it’s coder to manager. But…a lot of companies (especially with Ruby jobs) offer roles where you can continue to be an IC and still progress. You don’t have to necessarily choose.
Especially for someone like me who has never worked in a traditional programming role, I don’t know the structures and procedures that other companies use, but meeting people who have worked in those roles is interesting. People from all over the world come \[to the conference\], so it’s really surprising and inspiring to see all the ways and places Ruby is being used.
**What’s something that surprised you at the conferences you’ve attended?**
At RubyConf, there was a guy that made a game engine and was deploying games to the App Store. That blew my mind! In Japan, some of the government systems use Ruby. A lot of these times, we think we’re just making a website. There’s all kinds of applications that can be really inspiring. It’s cool that we are using the same tools.
**What do you think is the block people face that stops them from engaging deeply in the community via conferences?**
Being a team of one, it was intimidating to think about going to this by myself. A lot of times programmers and technical people tend to be more introverted, so I think there are hurdles there. Then you go to these events, and you find a lot of commonalities with people – you also see there’s a whole, wide, diverse group of people. It’s not just guys; it’s women, people from all walks of life and from all over the world. It’s really cool to have some kind of commonality and also have that diversity. I think it’s something kind of special. It’s something that our community puts a lot of emphasis on, which I think is really important. If you have to come alone, knowing that it’s a community of very welcoming and open-minded people is a good thing.
**What would you say to anyone considering the Scholars and Guide program who is on the fence?**
If you’re on the fence, do it. I can’t really see a downside. You’re already going to an event where you know that you have a lot of commonality with a lot of the folks that are there. And this kind of gives you another avenue to meet new people, make new connections, and be helpful to other people.
It was \[also\] nice on the other side because it’s a two way street. I’m a friendly face to people, but they’re a friendly face to me. So that was kind of nice, too…it was kind of a built in way to break the ice.
***If you are considering in becoming a Guide, please [follow this link](https://rubycentral.org/scholars%5Fguides%5Fprogram/) to the applications.***
### Ruby Central Scholar Spotlight
URL: https://rubycentral.org/news/rubyconf2022-scholar-highlight/
Last updated: 2026-02-18T20:58:13.000Z
This week we’re highlighting members of our Scholars and Guides community, Ruby Central’s conference mentorship program which provides new and aspiring Rubyists with a supportive social and, if needed, a financial pathway to entering the tech community.
Today’s spotlight is a RubyConf 2022 Scholar. If you are thinking of attending the upcoming conference, joining the program as a Scholar can help you feel grounded as you[ navigate a conference for the first time](https://rubycentral.org/news/navigating-rubyconf2022-as-a-newcomer/) and find your way as a new Ruby developer.
If you’re still on the fence about applying, we hope this spotlight helps give you the extra boost to go for it!
**Name**
Bryce Simonds
**Title**
Software Engineer

**How did you get into Ruby?**
Bootcamp - Turing School of Software and Design
**Are there Ruby projects you're working on, that you're excited about?**
At RubyConf 2022 I was exposed to [DragonRuby](https://dragonruby.org/?ref=rubycentral.org) and I am SO excited to get started playing around and creating projects with it. Beyond DragonRuby I am currently on a team working to create a web application using a Ruby backend to connect Dungeons and Dragons (D&D) Dungeon Masters to D&D Players using a variety of consent questions. After that project my plan is to start contributing to open source projects in a bit of my free time. I love giving back and am excited to do so!
**How did you feel going into RubyConf 2022?**
EXCITED! I LOVE meeting new people and developing new genuine relationships. I also knew beforehand there would be many talks where I would have an opportunity to learn brand new topics and expand upon topics I am already confident in. So that contributed to the excitement as well!
I was \[also\] a little nervous that people would discredit my knowledge and credentials since I attended a bootcamp instead of having a 4 year CS degree.
**What were you expecting to come out of it?**
I was expecting to learn, grow, meet new people and have an amazing week
**What surprised you, if anything about your RubyConf 2022 experience?**
How SUPER kind, welcoming, and supportive the RubyConf community is. Never once was I looked down upon for not knowing as much as someone else.
**What was the highlight of the conference for you?**
It is between having the opportunity to talk on stage during the lightning talks and receiving such positive feedback, and the other highlight which was just getting out and having fun with others whether it was dinner plans, coffee, or my personal favorite: karaoke night!
**Any advice for other first time conference attendees?**
It is so true what I heard from day 1 of the conference: it is 100% okay (and encouraged!) to spend time getting to know others and chat in the hallway (known as the 'hallway track') instead of attending every single talk each day. Try to find a balance and rest easy knowing talks are recorded so you can go back and watch them later.
**Any advice for other first time guides/first time scholars?**
Take care of yourself when you need to so that you can have the energy to engage with others, be present for the talks, and have a truly awesome time. Some examples: Find out what meals are provided at the conference and make sure you have a plan for having food for each meal. For example you could have groceries delivered to your hotel for breakfast since lunch is provided and you love going out to dinner. Get enough sleep and fight the FOMO when your group wants to stay up until 2am in the hotel lobby. You will see them tomorrow and probably feel more awake and ready for the day. Go up to your hotel room for a break if you're feeling exhausted from talking to others, or sitting all day, or whatever it is. These are just a few examples but overall again: take care of yourself.
**Any other final thoughts?**
I want to thank everyone at Ruby Central. For putting this event together, for having me as a scholar, for encouraging me to get up on stage, and for keeping an eye on all of us scholars throughout \[the\] conference to ensure we were having a good time. And for those debating whether or not to attend RubyConf for any reason I want to emphasize if my blog post has not already emphasized this exact point => literally every single person I interacted with whether it be for one second or one hour, was warm and welcoming, kind and caring, and a blast to talk to. Matz is nice, so we are nice.
### RailsConf 2023 in Atlanta
URL: https://rubycentral.org/news/railsconf-2023-in-atlanta-2/
Last updated: 2023-03-23T17:00:43.000Z

This year [RailsConf](http://railsconf.org/?ref=rubycentral.org) will be April 24-26th in beautiful Atlanta, Georgia!
# Tickets
[Tickets are now on sale here](https://railsconf.org/register?ref=rubycentral.org). We offer discounts for students, groups of 5+, and more.
# CFP
Also, the [Call for Proposals (CFP) is now open here](https://sessionize.com/railsconf2023/?ref=rubycentral.org)! We are accepting proposals for talks (30-45 mins) or Workshops (2 hours).
We warmly welcome both new and experienced speakers, technical and non-technical talks, and beginner, intermediate, or advanced-level topics.
We love first time speakers! If you are thinking about submitting a talk but need some feedback, coaching, or just a cheerleader to tell you “you can do it!”, we have scheduled some coaching sessions for you:
- [Feb 14 9am PST / 12 EST](https://www.eventbrite.com/e/call-for-proposal-cfp-coaching-session-tickets-536361430477?ref=rubycentral.org)
- [Feb 16 12 PST / 3pm EST](https://www.eventbrite.com/e/call-for-proposal-cfp-coaching-session-tickets-536361430477?ref=rubycentral.org)
- [Feb 21 4 PST / 7pm EST](https://www.eventbrite.com/e/call-for-proposal-cfp-coaching-session-tickets-536361430477?ref=rubycentral.org)
Take a look at this year's[ conference tracks](https://sessionize.com/railsconf2023?ref=rubycentral.org) and submit your proposal today!
# Scholars and Guides
The Scholars and Guides Program is a mentorship program for conference attendees interested in having someone experienced show them around and someone less-experienced have a helpful person around to navigatep a new situation. [You can read more and apply here on railsconf.org](https://railsconf.org/get-involved?ref=rubycentral.org).
## What is a Scholar?
Scholars, or mentees, are people new to the Ruby and Rails communities and looking to make professional connections. Scholars are paired with a Guide, or mentor, who will be available throughout the event to offer insight and advice on programming, working as a developer, and helping you build long-lasting connections with influential community members.
## What is a Guide?
Guides are volunteer mentors and will support the Scholars through mentorship, guidance, and professional networking leading up to and during a Ruby or Rails conference. Guides are familiar with the Ruby and/or Rails community, help create networking opportunities, and help the Scholar navigate a professional conference.
[Apply to be a scholar or guide here](https://railsconf.org/get-involved?ref=rubycentral.org#scholars-guides)!
# Sponsors
Interested in becoming a RailsConf Sponsor? Review this year's conference [Prospectus](https://framerusercontent.com/modules/assets/vlmjEAwebSclz3StaKoHvpXyLk~50nNsSrn1lf3FMahDzGH1BRikNzCWmzmmqgqUp%5FLm5k.pdf?ref=rubycentral.org) and email us at [sponsors@railsconf.org](sponsors@rubycentral.org). We would love to partner with you!
# Questions?
Still have RailsConf2023 questions? Please don’t hesitate to reach out to us at [contact@rubycentral.org](mailto:contact@rubycentral.org).
No matter how you choose to participate, we hope to see you there!
### Ruby Shield Update - Winter 2023
URL: https://rubycentral.org/news/ruby-shield-update-winter-2023/
Last updated: 2023-05-05T16:29:40.000Z
In case you missed it, in 2022, [ we launched Ruby Shield](https://rubycentral.org/news/ruby-shield/), our open source funding partnership with Shopify.
The mission of Ruby Shield is to increase work on Ruby security, strengthen our current infrastructure, and make Ruby development safer and more stable for the community. We are excited to bring on security-focused developers, provide more robust maintenance for rubygems.org, and implement new community-priority feature proposals.
Importantly, we’d like to reiterate that Shopify will not have any additional influence over Ruby Central’s decisions, processes or events. No individual or company can dictate our priorities, and our work will (as always) aim to benefit the Ruby community as a whole. As promised in the Ruby Shield announcement, we are sharing program updates with the community so you can see how our work moves forward — transparency is an important value for everyone at Ruby Central. We hope to share updates like this a few times a year.
Read on for our first update!
## New Projects
Since we launched Ruby Shield last year we’ve started several projects:
### Global On-Call Rotation
For the past two years, RubyGems.org maintenance has been a mainly US-based volunteer effort with some paid help when we could get it. This setup stretched our small team thin and often left them with little room for breaks.
We’ve now hired paid infrastructure engineers and implemented a “follow the sun” on-call rotation, meaning we have someone awake and on-call during their own daytime, around the world, every day. This allows us to provide consistent coverage for potential issues 24 hours per day. It even includes enough slack to allow individuals to take time off without forcing anyone to take overnight shifts, hopefully making the work more sustainable in the long run.
### RubyGems.org Scaling and Maintenance
We also have been able to invest in the long-term stability of RubyGems.org. Some progress we’ve made on this since the Ruby Shield launch include:
- Resolving AWS deprecations
- Postgres version upgrade
- Kubernetes version upgrade
- Upgraded search servers from ElasticSearch 7.10 to OpenSearch 1.3.
- Released RubyGems 3.4 and Bundler 2.4.
You can take a closer look at the development work we’ve done in our[ monthly updates](https://rubycentral.org/news/).
### Securing RubyGems
Ruby Shield funding has also allowed us to focus on securing the trustworthiness of gems. We’ve added an OpenSSF scorecard to GitHub and GitHub Actions, migrated the git protocol from http:// to the more secure https:// and added support for Hardware Security Tokens & Passkeys (aka WebAuthN).
### Support Tools
Finally, we are adding more tools for the maintainers who support developers using RubyGems.org. Specifically, we are setting up admin tools to reduce time spent on routine support requests like 2FA resets, spam, abuse, etc. This will reduce the burden on maintainers and also allow non-maintainers to assist.
## What’s Up Next?
### Long-deferred projects
As we’ve mentioned, Ruby Shield allows us to plan security and stability initiatives on a timescale of years instead of days.
- Continue upgrading our infrastructure to keep everything running smoothly
- Improve the user experience for RubyGems and Bundler, with built-in checksum verification for gems, faster performance, easier to understand error messages, and shortcuts for common tasks
- Increase information available about each gem, including better download counts, easier access to gem contents, and eventually version diffs and code search
- Investigate ecosystem security opportunities like The Update Framework and Sigstore
### Expanding even further
We plan to continue expanding and building on the work we’ve started with Ruby Shield. We’ve identified more financial support options for this work, including The German Sovereign Tech Fund, the Plaintext Group OSS Virtual Incubator, the NLnet Foundation, and the Comcast Innovation Fund. We’re also hoping to collaborate with other language distributors like Python, Perl, and Rust to share best practices and learn from each other’s mistakes.
## Your Name Here
We are grateful to the team at Shopify for working with us to financially support this project. This work wouldn’t be possible without it.
But why let them have all the fun? If your company is interested in supporting this work (or something else), [get in touch with us](mailto:hello@rubycentral.org) \- we’d love to talk more about how you can support the Ruby developers on your team as well as the rest of the world.
And if you’re an individual developer who wants to support Ruby infrastructure and community work, [consider joining us as a supporting member](https://rubycentral.org/#/portal/signup). Individual members subscribe at a sliding scale amount, which supports Ruby Central and our work. Membership benefits are a work in progress, but more fun perks are on the way.
You can also attend [RailsConf](http://railsconf.org/?ref=rubycentral.org) or [RubyConf](http://rubyconf.org/?ref=rubycentral.org) to support our work or join the conferences as a [sponsorship partner](mailto:sponsors@rubycentral.org). All of this helps us support the Ruby community.
## Ruby Community Input
As a community organization, our goal is to support and grow the Ruby community around the world, but we can’t do it as well without you.
- Would you like to contribute to any of these projects?
- Are there any programs or projects you think we should be prioritizing which would benefit the Ruby community?
- Do you have a new project, or feature idea?
We want to hear from you! Send your feedback or suggestions to our team at [contact@rubycentral.org](mailto:contact@rubycentral.org).
Thanks for reading!
### December 2022 Monthly Update
URL: https://rubycentral.org/news/december-2022-monthly-update/
Last updated: 2023-06-16T20:24:55.000Z
Hello! Welcome to the monthly update. During December, our work was supported by [Shopify](https://www.shopify.com/?ref=rubycentral.org), [Zendesk](https://zendesk.com/?ref=rubycentral.org) and many others.
## **Ruby Central News**
In December, Ruby Central's open source work was supported by 35 different companies, including Ruby member[ Zendesk](https://zendesk.com/?ref=rubycentral.org) and Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org).
On top of those companies, 1 new developer, Christopher Bloom, signed up as a member. In total, we were supported by 123 developer members. Thanks to all of our members for making everything that we do possible. <3
## **RubyGems News**
This month in RubyGems, we released final versions of RubyGems[ 3.4.0](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#340--2022-12-24) and[ 3.4.1](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#341--2022-12-24) and Bundler[ 2.4.0](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#240-december-24-2022) and[ 2.4.1](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#241-december-24-2022) featuring:
- a new "call to update" message when RubyGems is outdated -[ #5922](https://github.com/rubygems/rubygems/pull/5922?ref=rubycentral.org).
- an enhanced Bundler resolver based on [PubGrub](https://nex3.medium.com/pubgrub-2fb6470504f?ref=rubycentral.org), with clearer error messages when gem requirements conflict -[ #6146](https://github.com/rubygems/rubygems/pull/6146?ref=rubycentral.org).
- the \`bundle gem\` command can now generate a gem template with extensions written in Rust -[ #6149](https://github.com/rubygems/rubygems/pull/6149?ref=rubycentral.org).
- gems from git sources are now faster and smaller by using shallow clones under the hood -[ #6241](https://github.com/rubygems/rubygems/pull/6241?ref=rubycentral.org).
In addition to that, we made the following improvements and fixes (as always, see the changelog for the full list and all the details):
- added support for --pre flag in bundle update and bundle lock -[ #5258](https://github.com/rubygems/rubygems/pull/5258?ref=rubycentral.org).
- fixed bundle outdated with both --groups and --parseable flags -[ #6148](https://github.com/rubygems/rubygems/pull/6148?ref=rubycentral.org).
- fixed crash due to BundlerVersionFinder not being defined -[ #6152](https://github.com/rubygems/rubygems/pull/6152?ref=rubycentral.org).
- created a fallback to selecting installable candidates if possible when materializing specs -[ #6225](https://github.com/rubygems/rubygems/pull/6225?ref=rubycentral.org).
- updated generated CI scripts to be able to compile Rust extensions -[ #6168](https://github.com/rubygems/rubygems/pull/6168?ref=rubycentral.org).
- added a spec to make sure global gemspecs can't confuse Bundler -[ #6086](https://github.com/rubygems/rubygems/pull/6086?ref=rubycentral.org).
We also dropped support for old Rubies (2.3, 2.4, and 2.5) and finally removed the auto-sudo feature in Bundler 2.4,[ a longstanding request of our users](https://blog.rubygems.org/2022/10/18/septemeber-rubygems-updates.html/?ref=rubycentral.org#rubygems-news) because it is surprising and potentially a security issue for a tool to silently try to run itself as root.
In December, RubyGems gained[ 242 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2022-12-01%7D...master@%7B2022-12-31%7D?ref=rubycentral.org), contributed by 20 authors. There were 77,119 additions and 3,466 deletions across 2,051 files.
## **RubyGems.org News**
In December, RubyGems.org saw several bug fixes and updates, some of which include the following:
- fixed mocha deprecation warnings in tests -[ #3295](https://github.com/rubygems/rubygems.org/pull/3295?ref=rubycentral.org).
- as part of ongoing work involved in creating WebAuthn CLI, we setup a verification page -[ #3310](https://github.com/rubygems/rubygems.org/pull/3310?ref=rubycentral.org), added a Webauthn verification authenticate endpoint[ #3305](https://github.com/rubygems/rubygems.org/pull/3305?ref=rubycentral.org), and set the Webauthn authentication challenge on the prompt page -[ #3324](https://github.com/rubygems/rubygems.org/pull/3324?ref=rubycentral.org).
- fixed dependency links pointing to their dependents -[ #3312](https://github.com/rubygems/rubygems.org/pull/3312?ref=rubycentral.org).
- created an ES index in search\_test before relying on it -[ #3303](https://github.com/rubygems/rubygems.org/pull/3303?ref=rubycentral.org).
- updated the docs and scripts for contributing and setup -[ #3300](https://github.com/rubygems/rubygems.org/pull/3300?ref=rubycentral.org).
- migrated from Elasticsearch to the opensearch-ruby gem -[ #3036](https://github.com/rubygems/rubygems.org/pull/3036?ref=rubycentral.org).
The infrastructure team handled several alerts, all of which we resolved before they escalated to a full outage. In addition to handling emergency pages, the infrastructure team also made progress on upgrades for postgres, ElasticSearch, and other server software that RubyGems.org depends on.
This month, RubyGems.org gained[ 59 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2022-12-01%7D...master@%7B2022-12-31%7D?ref=rubycentral.org), contributed by 12 authors. There were 2,133 additions and 632 deletions across 77 files.
As always, we continue to fix bugs, review and merge PRs and reply to support tickets.
## **Total spent**
In December we completed 243.7 hours of development work @$150/hour, and spent $36,554.77.
## **Thank you**
Thank you to all the contributors of RubyGems and RubyGems.org for this month! Your contributions are greatly appreciated, and we are grateful for your support.
### **Contributors to RubyGems:**
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@peterzhu2118](https://github.com/peterzhu2118?ref=rubycentral.org) Peter Zhu
- [@duckinator](https://github.com/duckinator?ref=rubycentral.org) Ellen Marie Dash
- [@ianks](https://github.com/ianks?ref=rubycentral.org) Ian Ker-Seymer
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@eregon](https://github.com/eregon?ref=rubycentral.org) Benoit Daloze
- [@zarqman](https://github.com/zarqman?ref=rubycentral.org) Zarqman
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
- [@alyssais](https://github.com/alyssais?ref=rubycentral.org) Alyssa Ross
- [@eloyesp](https://github.com/eloyesp?ref=rubycentral.org) Eloy Espinaco
- [@siegfault](https://github.com/siegfault?ref=rubycentral.org) Michael Siegfried
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@joshuaswett](https://github.com/joshuaswett?ref=rubycentral.org) Joshua Swett
- [@markburns](https://github.com/markburns?ref=rubycentral.org) Mark Burns
- [@mensfeld](https://github.com/mensfeld?ref=rubycentral.org) Maciej Mensfeld
- [@gustavothecoder](https://github.com/gustavothecoder?ref=rubycentral.org) Gustavo Ribeiro
### **Contributors to RubyGems.org:**
- [@sonalkr132](https://github.com/sonalkr132?ref=rubycentral.org) Aditya Prakash
- [@jenshenny](https://github.com/jenshenny?ref=rubycentral.org) Jenny Shen
- [@kevinlinxc](https://github.com/kevinlinxc?ref=rubycentral.org) Kevin Lin
- [@mensfeld](https://github.com/mensfeld?ref=rubycentral.org) Maciej Mensfeld
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@aellispierce](https://github.com/aellispierce?ref=rubycentral.org) Ashley Ellis Pierce
- [@dorianmariefr](https://github.com/dorianmariefr?ref=rubycentral.org) Dorian Marié
- [@bettymakes](https://github.com/bettymakes?ref=rubycentral.org) Betty
- [@jchestershopify](https://github.com/jchestershopify?ref=rubycentral.org) Jacques Chester
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@martinemde](https://github.com/martinemde?ref=rubycentral.org) Martin Emde
### November 2022 Monthly Update
URL: https://rubycentral.org/news/november-2022-monthly-update/
Last updated: 2023-06-16T20:24:02.000Z
Hello! Welcome to the monthly update. During November, our work was supported by [Shopify](https://www.shopify.com/?ref=rubycentral.org), [Zendesk](https://zendesk.com/?ref=rubycentral.org) and many others.
## ruby central news
In November, we released a new version of [the Ruby Central website](https://rubycentral.org/)! This new site replaces the previous rubytogether.org and rubycentral.org sites, providing a single place to [read monthly updates and blog posts](https://rubycentral.org/news/), [manage your newsletter subscription](https://rubycentral.org/#/portal/signin), and [sign up as a supporting member](https://rubycentral.org/#/portal/signup).
The previous Ruby Together monthly updates have been brought over, as well as our previous posts about conferences, speakers, and Ruby developers. If you signed up for the newsletter or as a member in the past, the new site will allow you to manage your existing subscription.
This month, Ruby Central's open source work was supported by 32 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org) and Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org). 1 company joined as a new member.
On top of those companies, 1 new developer -- Emanuel H. Farias -- signed up as a member. In total, we were supported by 122 developer members. Thanks to all of our members for making everything that we do possible. <3
## RubyGems and Bundler news
This month in RubyGems, we released new versions of RubyGems [3.3.25](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3325--2022-11-02), [3.3.26](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3326--2022-11-16) and Bundler [2.3.25](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2325-november-2-2022), [2.3.26](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2326-november-16-2022).
The following improvements and fixes are included in these releases (see the changelog for more information:
- improved some test times and fixed warning by not installing documentation. - [#6074](https://github.com/rubygems/rubygems/pull/6074?ref=rubycentral.org).
- fixed a broken link in `bundle-platform` man page - [#6071](https://github.com/rubygems/rubygems/pull/6071?ref=rubycentral.org).
- added permission restrictions to GitHub actions - [#6081](https://github.com/rubygems/rubygems/pull/6081?ref=rubycentral.org).
- removed reference to RVM documentation in the message returned when you run `bundler outdated` \- [#6083](https://github.com/rubygems/rubygems/pull/6083?ref=rubycentral.org).
- added a test to ensure that global gemspecs do not confuse Bundler - [#6086](https://github.com/rubygems/rubygems/pull/6086?ref=rubycentral.org).
- fixed an issue that occurs when a lockfile gem does not resolve on the current platform - [#6070](https://github.com/rubygems/rubygems/pull/6070?ref=rubycentral.org).
- updated the docs for `gemfile` man page - [#6007](https://github.com/rubygems/rubygems/pull/6007?ref=rubycentral.org).
- improved resolution messages when some platform gems are missing - [#6068](https://github.com/rubygems/rubygems/pull/6068?ref=rubycentral.org).
- added `asdf`, a ruby version manager option that contributors can utilize - [#6066](https://github.com/rubygems/rubygems/pull/6066?ref=rubycentral.org).
- upgraded `rb-sys` to version 0.9.37 - [#6047](https://github.com/rubygems/rubygems/pull/6047?ref=rubycentral.org).
In November, RubyGems and Bundler gained [116 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2022-11-01%7D...master@%7B2022-11-31%7D?ref=rubycentral.org), contributed by 15 authors. There were 3,719 additions and 3,370 deletions across 141 files.
## RubyGems.org news
In November, RubyGems.org saw several bug fixes and updates, some of which include the following:
- added tests to cover scenarios where an API key is not saved after being created or updated - [#3280](https://github.com/rubygems/rubygems.org/pull/3280?ref=rubycentral.org).
- merged a PR to avoid filling the template with the gem name automatically - [#6093](https://github.com/rubygems/rubygems/pull/6093?ref=rubycentral.org).
- merged a PR to protect the gem placeholder name to prevent misuse of the package name.- [#3275](https://github.com/rubygems/rubygems.org/pull/3275?ref=rubycentral.org).
- used `DelayedJob` as an active job adapter - [#3266](https://github.com/rubygems/rubygems.org/pull/3266?ref=rubycentral.org).
- increased the maximum size of the memcached entry to 2MB - [#3260](https://github.com/rubygems/rubygems.org/pull/3260?ref=rubycentral.org).
- added `ossf/scorecards` to assist in detecting non-secure configurations related to GitHub and GitHub Actions - [#3258](https://github.com/rubygems/rubygems.org/pull/3258?ref=rubycentral.org).
- updated to the latest versions of RubyGems (3.3.25) and Bundler (2.3.25) - [#3250](https://github.com/rubygems/rubygems.org/pull/3250?ref=rubycentral.org).
In November, RubyGems.org gained [46 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2022-11-01%7D...master@%7B2022-11-31%7D?ref=rubycentral.org), contributed by 6 authors. There were 108 additions and 36 deletions across 10 files.
As always, we continue to fix bugs, review and merge PRs and reply to support tickets.
## total spent
In November we completed 124.5 hours of development work @$150/hour, and spent $18,683.00.
## thank you
Thank you to all the contributors of RubyGems and RubyGems.org for this month! Your contributions are greatly appreciated, and we are grateful for your support.
Contributors to RubyGems:
- [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) David Rodríguez
- [@peterzhu2118](https://github.com/peterzhu2118?ref=rubycentral.org) Peter Zhu
- [@ianks](https://github.com/ianks?ref=rubycentral.org) Ian Ker-Seymer
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@syohex](https://github.com/syohex?ref=rubycentral.org) Shohei YOSHIDA
- [@Bo98](https://github.com/Bo98?ref=rubycentral.org) Bo Anderson
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@gustavothecoder](https://github.com/gustavothecoder?ref=rubycentral.org) Gustavo Ribeiro
- [@JuanVqz](https://github.com/JuanVqz?ref=rubycentral.org) Juan Vásquez
- [@nobu](https://github.com/nobu?ref=rubycentral.org) Nobuyoshi Nakada
Contributors to RubyGems.org:
- [@hsbt](https://github.com/hsbt?ref=rubycentral.org) Hiroshi SHIBATA
- [@simi](https://github.com/simi?ref=rubycentral.org) Josef Šimánek
- [@tnir](https://github.com/tnir?ref=rubycentral.org) Takuya N
- [@sonalkr132](https://github.com/sonalkr132?ref=rubycentral.org) Aditya Prakash
Until next time,
Irene, André and the Ruby Central team
### October 2022 Monthly Update
URL: https://rubycentral.org/news/october-2022-monthly-update/
Last updated: 2023-06-16T20:23:25.000Z
Hello! Welcome to the monthly update. During October, our work was supported by [Shopify](https://www.shopify.com/?ref=rubycentral.org), [Zendesk](https://zendesk.com/?ref=rubycentral.org) and many others.
### ruby central news
In October, Ruby Central's open source work was supported by 33 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org) and Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org). 3 companies joined as new members.
On top of those companies, 3 new developers signed up as members, including Chris Roos and Chris Lowis. In total, we were supported by 123 developer members. Thanks to all of our members for making everything that we do possible. <3
### RubyGems news
This month in RubyGems, we released new versions of RubyGems [3.3.23](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3323--2022-10-05), [3.3.24](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3324--2022-10-17) and Bundler [2.3.23](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2323-october-5-2022), [2.3.24](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2324-october-17-2022).
The following improvements and fixes are also included in these releases (see the changelog for more information):
- added a small development environment that was contributed to make a `rubocop` script for use while developing Bundler - [#5979](https://github.com/rubygems/rubygems/pull/5979?ref=rubycentral.org).
- improved resolution performance and correctness by adding resolver spec groups for Ruby platform only when necessary. This is in preparation for the upcoming migration to Pub Grub - [#5698](https://github.com/rubygems/rubygems/pull/5698?ref=rubycentral.org).
- added `SHA256` in test certificates - [#5982](https://github.com/rubygems/rubygems/pull/5982?ref=rubycentral.org).
- made an update to allow JRuby to pass keywords to `Kernel#warn` \- [#6002](https://github.com/rubygems/rubygems/pull/6002?ref=rubycentral.org).
- unified source code and documentation to always use HTTPS under the hood with dealing with GitHub sources. - [#5993](https://github.com/rubygems/rubygems/pull/5993?ref=rubycentral.org) and [#6026](https://github.com/rubygems/rubygems/pull/6026?ref=rubycentral.org).
- fixed several issues with `Gem::Platform` handling in musl platforms ([#5915](https://github.com/rubygems/rubygems/pull/5915?ref=rubycentral.org)), in arm platforms with eabi modifiers ([#5957](https://github.com/rubygems/rubygems/pull/5957?ref=rubycentral.org)), and to properly deal with string parameters when comparing ([#5939](https://github.com/rubygems/rubygems/pull/5939?ref=rubycentral.org)).
- improved handling of permanent redirect responses when pushing gems - [#5931](https://github.com/rubygems/rubygems/pull/5931?ref=rubycentral.org).
- fixed an obscure issue affecting file extraction of some specific `.gem` packages - [#5906](https://github.com/rubygems/rubygems/pull/5906?ref=rubycentral.org).
- migrated the GitLab CI template generated by `bundle gem` to be the one now recommended by GitLab.
In October, RubyGems gained [74 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2022-10-01%7D...master@%7B2022-10-31%7D?ref=rubycentral.org), contributed by 11 authors. There were 1,594 additions and 833 deletions across 125 files.
### RubyGems.org news
There was minor maintenance work on RubyGems.org this month which included triaging issues, reviewing pull requests, and updating dependencies. We also began a deferred upgrade to the latest version of Terraform, and getting onto the latest versions for all the services managed by Terraform.
In October, RubyGems gained [30 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2022-10-01%7D...master@%7B2022-10-31%7D?ref=rubycentral.org), contributed by 3 authors. There were 22 additions and 22 deletions across 1 file.
As always, we continue to fix bugs, review and merge PRs and reply to support tickets.
### total spent
In October we completed 71 hours of development work @$150/hour, and spent $10,636.50.
Until next time,
Irene, André and the Ruby Together team
### Navigating RubyConf2022 As A Newcomer
URL: https://rubycentral.org/news/navigating-rubyconf2022-as-a-newcomer/
Last updated: 2023-08-21T18:54:38.000Z
[RubyConf2022](https://rubyconf.org/?ref=rubycentral.org) is three weeks away, and for some of you planning to attend, this may be your first RubyConf, tech conference or conference in general! If you’re in this boat, you may be feeling a range of emotions. Events like these are often big (we have 400+ people signed up for RubyConf2022 so far!), full of official and unofficial events, and offer an abundance of subjects to learn, and people to learn from — especially if you’re new to the field. They can also be overwhelming and go by quickly!
So, how do you take it all in and make the most of your RubyConf2022 experience?
Luckily, the Ruby community places a high value on including, welcoming and mentoring new members; and this is no more evident than in Ruby Central’s [Scholars and Guides Program](https://rubycentral.org/scholars%5Fguides%5Fprogram/). Established to invite new people into the tech industry that would normally face barriers trying to enter; the program offers grants, mentors, events, and more to its scholar participants. Scholars receive complimentary access to a Ruby Central sponsored conference, a mentor (Guide), group events, and a built-in community of other Scholars and Guides to attend the conference and events with.
We caught up with a few of the Scholars and Guides from recent RailsConf and RubyConf events, to get their advice on what to expect and what to prepare for as you navigate RubyConf2022 as a newcomer. Read on for their expert wisdom!
### Oh You’re a Fan of Ruby? Name Every Gem! (Or, Imaginary Conference Conversations)
In the days and hours leading up to RubyConf you may be feeling excitement or nervousness — or anything in between. These feelings can be intensified by preconceived notions about what a tech conferences is like. It’s easy to build up a picture of worst case scenarios when you don’t know exactly what you’ll be walking into. The Scholars and Guides we interviewed shared their biggest worries going into their first Ruby Central and tech conferences, and we have a feeling you’ll be able to relate.
“As a junior new to the entire industry I suspected that I would be quizzed with leetcode questions or would otherwise find myself in conversations that would require perfect knowledge of sorting algorithms or some new, yet obscure, technology,” shared Dana Weiss, a Software Engineer and former Scholar. “I’m a bit of an introvert so I was just hoping to make it through unscathed.”
Ella Xu, a Software Engineer at Hack Club; and Caitlin Henry, Ruby on Rails Software Engineer, both wondered if the professional connections they were seeking would be easy to make.
“I thought there would be existing social circles, or cliques, of people that knew each other before the conference,” Xu shared. “I was most nervous about how overwhelming navigating the conference would be, and about how easy it would be to connect with and meet others,” said Henry.
For one Guide, a version of these fears played out. John Sawers, a speaker, entrepreneur and engineering manager who currently helps coordinate Ruby Central’s Opportunity Scholars and Guides Program, recalled the overwhelming experience of his first tech conference.
“It was easy enough to go to sessions, but actually talking to the other attendees was very hard,” he said. “I think I only talked to one person, and he was hyping his JS library.”
Sawers said he left the conference feeling like he didn’t get the full experience, saying he “felt pretty isolated.”
So, how can you shift your focus from your fears to experiencing RubyConf2022 to the fullest?
### Hacking Pre-conference Jitters: Get By With A Little Help From Your Conference Friends
Well first, it might help to know that there will be no coding pop quizzes (as Weiss was happy to find out) – and if anyone tries to give you one, you’re free to walk away!
Next, you can start by slowing tapping into the energy of the conference. Being around a few fellow conference goers before fully immersing yourself in the day’s activities might help you ease into the event.
Henry’s nerves began to transform, “once I checked into the hotel the day before the conference started,” they said. “I was more excited than nervous as I felt the pre-conference buzz of the hotel lobby and bar.”
Sawers intentionally changed his approach to navigating conferences after his first go-around. “My experience didn’t change until my social context changed,” he said. He attended his first RailsConf with his team and found that “it was so much easier to manage, more fun, and I could rely on more outgoing members of the team to start conversations or find fun things to do.”
Kinsey Durham Grace, another Scholars and Guides coordinator, and Infrastructure Engineer at GitHub, similarly reflected that having a group to navigate the conference with made all the difference. In her case, it was the Scholars and Guides program. As a speaker, she joined her first conference as a Guide.
After that, “it became an essential part of my conference experience,” she said. “It is where I can feel comfortable in a smaller group and where I have met my best friends in the community.”
Sawers, too, says he now has “conference friends” he looks forward to connecting with after having attended several Ruby- and Rails- Confs. “I collected more every year,” he added.
In fact, all of the Scholars and Guides agreed that the best way to navigate the conference and reduce your fears was to focus on making connections.
### The Social Butterfly Effect: Making Meaningful Connections
You never know the ripple effect one friendly RubyConf conversation could have on your life – or at the very least, your day. So what’s the best way to get started? The Scholars and Guides we interviewed suggested a few different approaches.
“One of the greatest things was the Slack channel,” shared Henry. “This was a great place to connect, stay in touch with, and meet other attendees. From threads about making lunch/dinner plans in Portland, to discussing our favorite talks, to threads for the LGBTQ Rails community to connect, the Slack channel had something for everyone!”
As an attendee you’ll receive access the RubyConf2022 conference channel a week before the event. The Scholars and Guides program also has its own Slack channels, to support members and connect them throughout the conference.
Xu shared her strategy for meeting conference goers on site: “Don’t try to go to every talk/workshop/event; spend time meeting other conference attendees in the hallways and exhibition hall,” she advised.
Another good place to start is approaching a speaker after a session you enjoy — they are very likely to be open to a conversation. “They love it (I’m a speaker, so I know),” assured Sawers. “They’ll always be down at the front after their talk, so go say hi.”
On the other hand, conference goers may strike up a conversation with you – in that case, you get to skip the hard part. As long as you’re safe and feeling up for it, take a chance to get to know them. “Say yes to all the opportunities presented!” prompted Weiss. It could be the beginning of a beautiful conference friendship!
When it comes to working up the courage to start a conversation, putting yourself in the right mindset can start with acknowledging that it’s normal to feel a little uncomfortable. “Likely you’re out of your comfort zone just being there,” said Sawers. “Embrace that and make your self even less comfortable by talking to as many people as you can.”
All of the Scholars and Guides agreed that overcoming this will be well worth it. As Henry shared, “the biggest thing you’ll take away, other than the exposure and knowledge gained, are those new relationships!”
### More Words of Wisdom
Aside from making connections, the Scholars and Guides interviewed offered a few more pieces of guidance to help first time conference goers make the most of RubyConf2022.
“Be sure to set goals before the conference,” Durham Grace suggested. For example going into her first conference Xu intended “to learn about Rails features I didn’t know about before and be able to use that knowledge to make a meaningful contribution to an open source Rails app” and “to meet other developers and learn about their work.”
It can also be as simple as looking at the conference schedule ahead of time, as Henry did “in great detail. I knew that there were going to be some amazing talks to attend,” they shared.
Additionally, as a conference newcomer, whether or not you are in the Scholars and Guides program, you are welcome to request a conference Guide. “If we have bandwidth, we will pair first time conference attendees with a Guide,” shared Durham Grace.
Finally, mentally prepare yourself to be present and have a great time! “It’s going to be intense and very tiring,” said Henry. “Have fun and get as much out of the conference as you can!” encouraged Durham Grace. “Soak it all up!” Added Henry.
### Final Dispatches From The Scholars and Guides Program
If any of this is making you consider signing up for the Scholars and Guides program in the future (applications are closed for RubyConf2022 and the Scholar/Guide pairings have been [announced](https://rubyconf.org/scholarships?ref=rubycentral.org#SG22)!), here are some encouraging words from the past participants, that may help push you past your comfort zone to sign up!
“There was so much great information that the guides shared with us Scholars, and it was a great way to connect with others pre-conference. This helped to ease my nerves as I could ask as many questions as I wanted leading up to the conference,” said Henry.
“It was helpful to talk to and walk around with other Scholars and Guides,” said Xu. She said this is what helped her the most with her pre-conference nerves.
“She was able to introduce me to her friends and point me to good speakers so I didn’t miss any good talks,” said Weiss of her guide. I immediately had folks to eat lunch with and make dinner plans with, so I already felt like a part of the community.”
“I can think of a lot of Scholars who got their first jobs at RailsConf and these are exactly the people we want to see getting a solid foothold in tech,” said Sawers.
“It’s amazing how many Guides that have been Scholars before come back each year,” said Durham Grace. Hearing the stories of how the program helped them change their lives is so incredible to hear. I have met so many incredible people through the program!”
We hope this advice was helpful and has helped set the tone for RubyConf2022\. No matter how you’re feeling, know that you’re welcome and we’re excited to have you join us! If you haven’t already, you can check out all of the conference event info – including all the talks, the exciting lineup of keynote speakers, logistics and more – on the [RubyConf website](https://rubyconf.org/home?ref=rubycentral.org).
We look forward to seeing you in person soon!
### RubyConf2022 Speaker Spotlight: Lori Olson
URL: https://rubycentral.org/news/rubyconf2022-speaker-spotlight--lori-olson/
Last updated: 2022-11-28T23:39:45.000Z
RubyConf boasts an exciting variety of tracks and talks that highlight the creativity and interdisciplinary nature of the Ruby community. As a tech sector newcomer, I thought it would be fun to curate a series highlighting talks that immediately captured my curiosity, and get to know their respective speakers a little better. Read on for today’s speaker spotlight…
### Title of Talk:
This Old App
### Speaker: Lori Olson

### How Did you get into Ruby?
Was a Java developer, going to a Java conference (No Fluff, Just Stuff) where Dave Thomas was speaking. All anyone could talk about in the hallway track was this cool new framework called Rails (version 0.13). Tried it out on my upcoming project at work. Never looked back.
### What’s your favorite part about working on Open Source Software?
The community. So many people working together, to make programmers happy.
### What’s your least favorite part about working on OSS?
Also the community. Those parts of it that feel entitled to complain, demand, and belittle project maintainers while never contributing so much as a typo fix.
### What inspired you to give this talk?
Sweta of WNB.rb posted a “talk prompts” list, and one of which was “do you have a hobby or interest that informs your work”. I’ve been embroiled in a major house renovation for a while now, and what immediately sprang to mind was “What renovating an old house teaches you about upgrading an old app”.
### What do you want people to take away from it?
Whether you are talking about an old house, or an old app, those old things require maintenance, and eventually a coat of paint (or UI refresh) isn’t going to be enough and you’ll have to rip it apart to rebuild. Just be aware there are many years of other people’s hidden mistakes… waiting for you.
### What are you most looking forward to at this conference?
Seeing lots of old friends and making new ones.
### Do you have any other plans in Portland during conference week that you’re excited about?
Definitely plan to hit up NASA Space Center.
### Thank you, Lori, for sharing a bit of your story. See you at RubyConf2022!
### Sept. 2022 Monthly Update
URL: https://rubycentral.org/news/sept--2022-monthly-update/
Last updated: 2023-06-16T20:22:27.000Z
Hello! Welcome to the monthly update. During September, our work was supported by[Shopify](https://www.shopify.com/?ref=rubycentral.org), [Zendesk](https://zendesk.com/?ref=rubycentral.org) and many others.
## Ruby Central News
We are excited to announce that the German government’s [Sovereign Tech Fund](https://sovereigntechfund.de/en.html?ref=rubycentral.org) has chosen RubyGems and Bundler to participate in their pilot round of funding for open source infrastructure maintenance and development. We’re excited to invest further in the RubyGems open source ecosystem with help from the STF.
In September, Ruby Central’s open source work was supported by 33 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org) and Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org). 1 company joined as a new member.
On top of those companies, 1 new developer, Kuba =)K, signed up as a member! In total, we were supported by 122 developer members. Thanks to all of our members for making everything that we do possible. <3
## RubyGems News
This month in RubyGems, we released RubyGems [v3.3.22](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3322--2022-09-07) and Bundler [v2.3.22](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2322-september-7-2022).
The following improvements and fixes are also included in these releases (see the changelog for more information):
- added `bundle-console` command in Bundler’s documentation - [#5901](https://github.com/rubygems/rubygems/pull/5901?ref=rubycentral.org).
- updated the Bundler metadata source code URI for accuracy in gemspec - [#5896](https://github.com/rubygems/rubygems/pull/5896?ref=rubycentral.org).
- removed warning for old TLS version connections - [#5928](https://github.com/rubygems/rubygems/pull/5928?ref=rubycentral.org).
- removed no longer needed `fiddle` hacks since RubyInstaller released patch versions to not load `fiddle` on boot - [#5902](https://github.com/rubygems/rubygems/pull/5902?ref=rubycentral.org).
In addition, this month we’ve been working on migrating Bundler’s internal resolver engine to use [PubGrub](https://nex3.medium.com/pubgrub-2fb6470504f?ref=rubycentral.org), the cutting edge dependency resolution algorithm developed by Sass and Dart maintainer @nex3, and [ported to Ruby](https://github.com/jhawthorn/pub%5Fgrub?ref=rubycentral.org) by [@jhawthorn](https://github.com/jhawthorn?ref=rubycentral.org). Our progress so far includes better error messages and several cases of dramatically faster resolutions. We hope to release this work soon.
We have also removed the feature of auto-sudo’ing when there are not enough permissions to perform certain operations, because it could potentially run commands as root without prompting the user. The feature existed exclusively for the Ruby built in to macOS, but caused problems elsewhere. Since Apple has announced they plan to stop shipping Ruby with macOS in the future, it seemed like a good time to remove the feature. This removal will be released with Bundler 2.4.0
In September, RubyGems and Bundler gained [94 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2022-09-01%7D...master@%7B2022-09-31%7D?ref=rubycentral.org), contributed by 19 authors. There were 1,678 additions and 1,869 deletions across 161 files.
## RubyGems.org News
In September, RubyGems.org saw several bug fixes and updates, some of which include the following:
- added `rake task` to migrate MFA `ui_only` users to `ui_and_gem_signin` \- [#3217](https://github.com/rubygems/rubygems.org/pull/3217?ref=rubycentral.org).
- fixed MFA status label on owners index page - [#3206](https://github.com/rubygems/rubygems.org/pull/3206?ref=rubycentral.org).
- added a fix to include missing i18n API Keys - [#3208](https://github.com/rubygems/rubygems.org/pull/3208?ref=rubycentral.org).
- implemented a fix to allow users to delete all scoped `API keys` on password reset - [#3202](https://github.com/rubygems/rubygems.org/pull/3202?ref=rubycentral.org).
- added recommended `to_utf8` method when comparing certificates subject - [#3197](https://github.com/rubygems/rubygems.org/pull/3197?ref=rubycentral.org).
This month, RubyGems gained [45 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2022-09-01%7D...master@%7B2022-09-31%7D?ref=rubycentral.org), contributed by 11 authors. There were 621 additions and 212 deletions across 65 files.
As always, we continue to fix bugs, review and merge PRs and reply to support tickets.
## total spent
In September we completed 70.9 hours of development work @$150/hour, and spent $10,636.50.
Until next time,
Irene, André and the Ruby Together team
### Ruby Central Welcomes New Executive Director, Neil MacGovern
URL: https://rubycentral.org/news/2022-news/
Last updated: 2023-12-01T16:57:21.000Z
Ruby Central, the non-profit organization dedicated to supporting and advancing the Ruby programming language and worldwide Ruby community, welcomes Neil McGovern as its new Executive Director. Neil officially starts work for Ruby Central on November 1st, and will operate from the United Kingdom. With over 20 years of open source experience, Neil is joining us just in time to attend RubyConf 2022\. Community members will have a chance to meet him at this year’s conference from November 29th to December 1st in Houston, Texas.
Allison McMillan, Ruby Central President comments, “We’re thrilled to kickoff the next chapter of Ruby Central, and discover new and exciting ways to support the Ruby language and diverse, worldwide community in the future.. Neil brings a wealth of experience and we have high hopes for what he will enable the community and Ruby Central to achieve together!”
Neil most recently served as Executive Director of the GNOME Foundation, and has been a Debian Developer and Debian Project Leader. He’s looking forward to combining his experience in nonprofit management and open source communities in service of the Ruby Community.
Please join us in welcoming Neil to Ruby Central! If you have any questions, please email contact@rubycentral.org
### August 2022 Monthly Update
URL: https://rubycentral.org/news/august-2022-monthly-update/
Last updated: 2023-06-16T20:20:31.000Z
Hello! Welcome to the monthly update. During August, our work was supported by [Shopify](https://www.shopify.com/?ref=rubycentral.org), [Zendesk](https://zendesk.com/?ref=rubycentral.org) and many others.
## ruby together news
In August, Ruby Together was supported by 33 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org) and Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org). In total, we were supported by 123 developer members. Thanks to all of our members for making everything that we do possible. <3
## RubyGems news
This month in RubyGems, we released new versions of RubyGems ([3.3.20](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3320--2022-08-10), [3.3.21](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3321--2022-08-24)) and Bundler ([2.3.20](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2320-august-10-2022), [2.3.21](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2321-august-24-2022)).
The following are the main improvements shipped during this month (see the changelog for more improvements and fixes):
- added full support for `musl` variants for gems, both in RubyGems and Bundler - [#4488](https://github.com/rubygems/rubygems/pull/4488?ref=rubycentral.org), [#5852](https://github.com/rubygems/rubygems/pull/5852?ref=rubycentral.org).
- implemented `Bundler.settings[:only]` to install gems of the only specified groups (a longstanding feature request we finally decided to add) - [#5759](https://github.com/rubygems/rubygems/pull/5759?ref=rubycentral.org).
- restored previous performance of private RubyGems servers; it had gotten very slow after some correctness fixes - [#5826](https://github.com/rubygems/rubygems/pull/5826?ref=rubycentral.org).
In August, RubyGems gained [142 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2022-08-01%7D...master@%7B2022-08-31%7D?ref=rubycentral.org), contributed by 10 authors. There were 2,296 additions and 866 deletions across 214 files.
## RubyGems.org news
In August, RubyGems.org saw several bug fixes and updates, some of which include the following:
- set up email to announce MFA is required for maintainers of gems with 180M+ downloads - [#3171](https://github.com/rubygems/rubygems.org/pull/3171?ref=rubycentral.org).
- removed MFA required (Phase 3) feature flag cookie - [#3170](https://github.com/rubygems/rubygems.org/pull/3170?ref=rubycentral.org).
- simplified the API v1 GH scanning endpoint tests - [#3196](https://github.com/rubygems/rubygems.org/pull/3196?ref=rubycentral.org).
- added superscript star for a RubyGem version date with a tooltip - [#3193](https://github.com/rubygems/rubygems.org/pull/3193?ref=rubycentral.org).
- set up autocomplete value for OTP text field - [#3187](https://github.com/rubygems/rubygems.org/pull/3187?ref=rubycentral.org).
- added a redirect uri to MFA setup and upgrade page that lets the user return to the settings page - [#3185](https://github.com/rubygems/rubygems.org/pull/3185?ref=rubycentral.org).
- blocked CLI commands `push`, `yank`, `add/remove owners`, and `signin` if the user requires MFA and has it disabled or at a weak level - [#3155](https://github.com/rubygems/rubygems.org/pull/3155?ref=rubycentral.org).
This month, RubyGems gained [88 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2022-08-01%7D...master@%7B2022-08-31%7D?ref=rubycentral.org), contributed by 14 authors. There were 2,684 additions and 510 deletions across 68 files.
As always, we continue to fix bugs, review and merge PRs and reply to support tickets.
## total spent
In August we completed 94.3 hours of development work @$150/hour, and spent $14,149.50.
Until next time,
Irene, André and the Ruby Together team
### 5 Reasons To Turn That Idea Into A RailsConf or RubyConf Talk
URL: https://rubycentral.org/news/5-reasons-to-turn-that-idea-into-a-rubyconf-2022-talk-/
Last updated: 2024-06-06T20:55:47.000Z
## ***Check out this evergreen article if you're considering submitting to*** [***the current CFP***](https://sessionize.com/rubyconf-2024?ref=rubycentral.org)***! All of the reasons below still apply. Good luck!* 😄**
In case you missed it, the Call For Proposals for RubyConf 2022 — and RubyConf Mini — is live, and in case you needed a calendar check, there’s just under a week left to submit! Whether you’ve been preparing for this moment all year, or last month’s CFP announcement illuminated a gem ;-D of inspiration in you, now’s the time to crack your knuckles, take to the keyboard, put your best ideas forward in the CFP app and ship it.
If you’re on the fence about submitting a proposal, you’ve come to the right place. We’re here to demystify the process, alleviate your concerns and share some words of wisdom from a few recent RubyConf speakers who are glad they went for it! Without further ado, here are your 5 reasons to turn that idea into RubyConf 2022 talk:
## 1\. You’ll be supported the whole way through
Turning your ideas into a conference talk proposal that is clear, fits this year’s conference themes and impresses the program committee can feel like a daunting task. Luckily, you don’t have to start from a blank slate. In fact, former program committee member Noel Rappin and veteran speaker Sarah Mei have created some of our favorite guides to help you [develop your ideas into a proposal](https://noelrappin.com/blog/2014/01/conference-prompts-or-how-to-submit-proposals-and-influence-people/?ref=rubycentral.org), and [elevate that proposal](http://www.sarahmei.com/blog/2014/04/07/what-your-conference-proposal-is-missing/?ref=rubycentral.org) to make it engaging and polished.
If you’re still feeling lost or would like some feedback on your work so far, another Ruby veteran Kevin Murphy has kindly offered his [support](https://twitter.com/kevin%5Fj%5Fm/status/1552744656307458048?ref=rubycentral.org) and has even shared examples of his [successful proposals](https://kevinjmurphy.com/posts/sharing-past-conference-proposals/?ref=rubycentral.org) to spark your imagination.
Maybe you have everything you need for a RubyConf talk proposal, but you’re nervous about what happens if your talk gets selected and you have to actually, you know, talk!
We have your back. Whether you’ve never given a conference talk, never presented at RubyConf specifically or simply are not sure how to best explain your particular topic, once you are selected you have the option to be paired with a speaker mentor who can help you prepare your talk.
If you want to get a jump start on the process, many former speakers have shared their experiences getting to the RubyConf stage too, including RubyConf 2021 speaker Stefanni Brasil who created a fun and helpful [step-by-step guide](https://www.hexdevs.com/posts/public-speaking-tips-for-software-developers/?ref=rubycentral.org) to creating and delivering a technical talk.
## 2\. No, really — we got you! Here’s some more topic inspiration
Choosing to submit a talk to be included in a [conference track](https://cfp.rubycentral.org/events/rubyconf-2022?ref=rubycentral.org) is a great way to narrow down your choices if you’re feeling overwhelmed by this step in the submission process. Some of our most inclusive tracks are “Bringing Your Backgrounds With You” and “Hidden Gems.” Casey Watts and Elayne Juten, the program committee members who created these tracks, respectively, shared their personal reasons to submit a talk to these tracks.
“Teams are stronger when you can bring your full self to work, and our conference is stronger when our speakers can bring their full selves. This theme is close to the heart of the Ruby community,” said Watts. “What unique perspectives do you bring to the community and the workplace? We’d love to hear about them!”
Juten invites potential speakers to share about a particular gem (or gems) from new angles: “What gems do you love to use? Have you explored the internals of a gem? We would love to hear from you!”
## 3\. You may help invite new faces to the table
It’s no secret that tech conferences, like the field itself, can be very homogenous…i.e. white and men dominated, with not much variety in class representation. We fully recognize this and it’s why we created the [Opportunity Scholarship program](https://rubycentral.org/scholarships) and why we are happy to partner with [WNB.rb](https://www.wnb-rb.dev/?ref=rubycentral.org) to support RubyConf Mini. It’s also why if you feel like representation has been an important part of your tech career, you can consider applying to speak a chance to welcome and build community with other Rubyists looking for someone like you.
That’s what inspired Stefanni Brasil, co-founder and educator at hexdevs, to submit her talk [“Perceptual Learning == More Ruby Experts?”](https://www.youtube.com/watch?v=3sfyVxjvew0&ref=rubycentral.org) at RubyConf 2021\. “I wanted to see more people like me speaking at technical conferences. I’m a second-language English speaker and immigrant,” she said. Brasil also tapped into the Ruby community for support. “I collaborated with other developers from WNB.rb and we supported each other during this process. It made a total difference in feeling more confident with submitting a proposal.”
## 4\. You’ll have a chance for your skills to shine
One of the common themes former speakers shared about speaking at their first RubyConf is that it was a validating highlight in their professional careers. From joining a roster of Rubyists who have made great contributions to the community, to connecting with potential employers who are actively hiring, “putting yourself out there” as a speaker is a wonderful way to confirm your Ruby expertise.
“It was a shift to feeling like I have something to contribute, and that I’m able to be part of this community beyond just observing it,” said Scott Moore, Senior Software Engineer at Doximity. After he presented his workshop [“All comments must be haiku! Custom linting with RuboCop”](https://www.youtube.com/watch?v=wC0fO7Ggzyg&ref=rubycentral.org) at RubyConf 2021, “One of the attendees told me they implemented the concept from the workshop at their day job,” he said. “Being able to help someone like that in such an immediate way was hugely rewarding.”
## 5\. You’ll experience RubyConf magic in a new way
If you’ve ever attended a RubyConf you’re likely familiar with the special environment created when the all of the ideas, innovation, and problem solving are focused on Ruby. “Often the technologies around web development are all mixed together with Ruby,” said Principal Software Engineer, Kyle d’Oliveira who gave a talk at RubyConf 2021 titled [“The mindset of debugging.”](https://www.youtube.com/watch?v=LitTV2k%5FX34&ref=rubycentral.org)
“It is really inspiring to see what can be done with Ruby on its own. You can learn neat things about the language itself, or new ways to apply it that you may not have thought about before.”
As a speaker, you have the opportunity be a part of shaping this experience for fellow Rubyists by adding your unique perspective to the conversations, and possibly changing the way they look at the language forever.
### 5a. Bonus
For those of you who can and do sign up to speak in Houston or Providence, this will be doubly felt. “I find being present in-person is the difference between listening to a conference vs participating in a conference,” shared d’Oliveira. “It’s easier to connect with people, randomly meeting someone, join hallway conversations, etc.” added Brasil.
## A few final thoughts
The bottom line is, you don’t need to feel completely ready to create a wonderful conference proposal and deliver a great talk. All you need is the seed of an idea and the Ruby community will support you the rest of the way. We’ll leave you with a final word of encouragement from one of our featured former speakers:
> “Earlier in my career, I didn’t think it was useful to speak at a conference because I didn’t think I had anything novel, interesting, or even useful to say. I look back and I realize just how wrong I was. Everyone has something valuable to talk about that could be beneficial to others and the more we push to share as part of the Ruby community, the better we can all become.”
–Kyle d’Oliveira
We hope this post has helped all of you CFP fence-sitters to take the leap! If you still have questions about the [application](https://cfp.rubycentral.org/events/rubyconf-2022?ref=rubycentral.org), please don’t hesitate contact us at [rubyconf@rubycentral.org](mailto:rubyconf@rubycentral.org).
Happy proposal writing!
### July 2022 Monthly Update
URL: https://rubycentral.org/news/july-2022-monthly-update/
Last updated: 2023-06-16T20:20:53.000Z
Hello! Welcome to the monthly update. During July, our work was supported by [Shopify](https://www.shopify.com/?ref=rubycentral.org), [Zendesk](https://zendesk.com/?ref=rubycentral.org) and many others.
## ruby together news
In July, Ruby Together was supported by 32 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org) and Ruby Shield sponsor [Shopify](https://www.shopify.com/?ref=rubycentral.org). 2 companies joined as new members.
On top of those companies, 2 new developers signed up as members. In total, we were supported by 126 developer members. Thanks to all of our members for making everything that we do possible. <3
## RubyGems News
This month in RubyGems, we released new versions of RubyGems [3.3.18](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3318--2022-07-14), [3.3.19](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3319--2022-07-27) and Bundler [2.3.18](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2318-july-14-2022), [2.3.19](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2319-july-27-2022).
The following is a non-exhaustive list of other improvements included in the above releases (see the changelog for further information):
- updated the CLI to display MFA warnings on `gem signin`, to support work done on the RubyGems.org side - [#5590](https://github.com/rubygems/rubygems/pull/5590?ref=rubycentral.org).
- added the long-requested feature of allowing to gem install from specific groups only - [#5579](https://github.com/rubygems/rubygems/pull/5759?ref=rubycentral.org).
- extended the `gem` DSL with a `force_ruby_platform` option - [#4049](https://github.com/rubygems/rubygems/pull/4049?ref=rubycentral.org).
- fixed an issue with Bundler on Windows that allows the new `x64-mingw-ucrt`, the default on **Ruby 3.1**, to work seamlessly with the existing `platforms DSL` \- [#5655](https://github.com/rubygems/rubygems/pull/5655?ref=rubycentral.org).
- improved performance of `bundler/setup` \- [#5546](https://github.com/rubygems/rubygems/pull/5546?ref=rubycentral.org), [#5695](https://github.com/rubygems/rubygems/pull/5695?ref=rubycentral.org).
- fixed several TruffleRuby issues - [#5711](https://github.com/rubygems/rubygems/pull/5711?ref=rubycentral.org), [#5694](https://github.com/rubygems/rubygems/pull/5694?ref=rubycentral.org), [#5746](https://github.com/rubygems/rubygems/pull/5746?ref=rubycentral.org).
- fixed a confusing permission error when copying compact index cache - [#5709](https://github.com/rubygems/rubygems/pull/5709?ref=rubycentral.org).
- fixed an issue with Bundler printing the bug report template so that it gives a better error rather than suggesting a bug - [#5726](https://github.com/rubygems/rubygems/pull/5726?ref=rubycentral.org).
- improved `gem not found` error messages to include the expected source - [#5729](https://github.com/rubygems/rubygems/pull/5729?ref=rubycentral.org).
- merged a PR to fix `gem update --system` errors in some edge cases - [#5728](https://github.com/rubygems/rubygems/pull/5728?ref=rubycentral.org), [#5737](https://github.com/rubygems/rubygems/pull/5737?ref=rubycentral.org).
In July, RubyGems gained [150 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2022-07-01%7D...master@%7B2022-07-31%7D?ref=rubycentral.org), contributed by 15 authors. There were 8,654 additions and 7,904 deletions across 410 files.
## RubyGems.org News
Our big news this month is our plan to [enforce multi-factor authentication for gems with more than 180 million downloads](https://blog.rubygems.org/2022/08/15/requiring-mfa-on-popular-gems.html?ref=rubycentral.org). We’ll continue to monitor as enforcement is rolled out, and make adjustments as needed.
In July, RubyGems.org saw several bug fixes and updates, some of which include the following:
- added an `mfa_required` function to check when a user needs to enable MFA due to one of the packages they own passing the MFA-required downloads threshold - [#3135](https://github.com/rubygems/rubygems.org/pull/3135?ref=rubycentral.org).
- merged a PR to reorganize locales by running `bill/fill-locales` \- [#3134](https://github.com/rubygems/rubygems.org/pull/3134?ref=rubycentral.org).
- updated the `TargetRubyVersion` for Rubocop - [#3139](https://github.com/rubygems/rubygems.org/pull/3139?ref=rubycentral.org).
- added an update to skip sending email when a user has no email address present - [#3150](https://github.com/rubygems/rubygems.org/pull/3150?ref=rubycentral.org).
- fixed webhooks for users with multiple API keys - [#3151](https://github.com/rubygems/rubygems.org/pull/3151?ref=rubycentral.org).
This month, RubyGems.org gained [74 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2022-06-01%7D...master@%7B2022-06-31%7D?ref=rubycentral.org), contributed by 13 authors. There were 1,015 additions and 263 deletions across 63 files.
As always, we continue to fix bugs, review and merge PRs and reply to support tickets.
## total spent
In June we completed 39 hours of development work @$150/hour, and spent $5,860.50.
Until next time,
Irene, André, and the Ruby Together team
### Ruby Central announces Ruby Shield, a partnership between Ruby Central and Shopify
URL: https://rubycentral.org/news/ruby-shield/
Last updated: 2023-06-16T15:41:32.000Z
We’re thrilled to announce **Ruby Shield**, a partnership between Ruby Central and Shopify that underscores our shared commitment to security work. This partnership will allow Ruby Central to focus more on security and general Ruby and Rails infrastructure development and maintenance. Ruby Central operates rubygems.org, the primary Ruby software registry, and supports development of tools such as Rubygems and Bundler.
As many in our community know, Shopify has long had a team dedicated to supporting Rails. Their team has recently started dedicating more effort towards contributing and maintaining rubygems.org for the betterment of the entire Ruby ecosystem. Shopify will also support Ruby Central with a donation to the organization made over the next four years, which we plan to use to hire security-focused developers. While Shopify’s financial support will not result in any additional privileges, preferences, or access to Ruby Central decision-making, Ruby Central is excited to see new feature proposals like enhanced software signing projects, widely desired by a large portion of the community.
The Ruby community is important to us at Ruby Central and our mission is to support the community in its entirety. Shopify understands the critical role which Ruby Central plays in the Ruby community and is committed to supporting Ruby Central's empowerment of all Ruby developers. We look forward to potentially working with more companies on similar opportunities in the future as the Ruby community and ecosystem continues to grow and thrive.
## FAQ
### Why is this good news for the Ruby community?
Many of the tools Ruby developers use every day to manage their open-source dependencies are supported almost entirely by volunteers or Ruby Central funding. With Shopify’s support, Ruby Central will now be able to confidently plan security and stability initiatives on a timescale of years. This work will improve the tools used by upstream open-source contributors, the many libraries that the entire community uses in production, as well as tools directly used by Shopify.
### Why is Shopify investing in supply chain security?
Open-source supply chains are increasingly under attack. [Sonatype reports](https://www.sonatype.com/resources/state-of-the-software-supply-chain-2021?ref=rubycentral.org) that supply chain attacks increased 650% YoY in 2021\. At the same time, open-source demand (73% YoY increase in downloads) and supply (20% YoY growth of new component versions) are exploding.
Shopify is already [working with the OpenSSF](https://openssf.org/blog/2022/04/19/your-favorite-software-repositories-now-working-together?ref=rubycentral.org) and the supply-chain maintainers in other ecosystems – Python, Node.js, Rust, PHP, and Java – to find solutions to shared problems and collaborating with Ruby Central is the next step.
Shopify is committed to building high-trust, open-source communities and Ruby Shield will help maintain this sense of security and trust under the stewardship of Ruby Central.
### What is Ruby Central's role in the Ruby open-source ecosystem?
Ruby Central has been funding work on the critical infrastructure used by the Ruby Community since 2003, and hires engineers who are working on [rubygems.org](http://rubygems.org/?ref=rubycentral.org) and the Ruby developer toolchain. Ruby Central also operates the primary repository of Ruby open-source software (rubygems.org) which adds a lot of direct value to the community. Shopify’s commitment will help Ruby Central confidently plan their engineering budget, take on new security-related projects, improve the cycle time for contributors, and make Ruby open-source more secure.
### How else have Shopify and Ruby Central worked together?
Shopify is a long-time sponsor of RubyConf and RailsConf, which go directly to helping fund Ruby Central activities and initiatives. This new partnership helps Ruby Central provide more to the Ruby Community than we could funding the activities solely via the conferences.
Additionally, Ruby Central announced the addition of Shopify developers, [Ashley Ellis Pierce](https://github.com/aellispierce?ref=rubycentral.org) and [Jenny Shen](https://github.com/jenshenny?ref=rubycentral.org), to the Maintainers team of rubygems.org.
### What influence does this partnership give Shopify over Ruby Central?
This was an important consideration in Ruby Central moving forward the partnership. After discussion with Shopify and amongst the Ruby Central directors, the agreement was formulated as a donation without strings. Both parties have made it clear that usage of the donation is at the discretion of Ruby Central. As a good steward of the Ruby community, Ruby Central plans to disclose how the funds were used both for full transparency on the partnership as well as to highlight the work that was done.
### What is Shopify's role in the Ruby open-source ecosystem?
Shopify engineers proudly use Ruby and Rails as their primary tech stack, handling business for millions of merchants and entrepreneurs worldwide. Shopify also employs many Ruby Core and Rails Core team members who frequently contribute to open-source projects and are excited to work with Ruby Central so that Ruby and Rails can continue to thrive and be tools which easily scale for every company who uses them.
[Click here to learn more about Shopify’s open-source philosophy](https://shopify.engineering/shopify-open-source-philosophy?ref=rubycentral.org).
### How much is Shopify contributing to Ruby Shield?
Shopify is committing $1 million USD to Ruby Central over four years, in addition to committing dedicated Engineering effort from Shopify’s Ruby and Rails Infrastructure team.
### How will Ruby Central spend these funds?
Ruby Central will use this money primarily to invest in improving Ruby’s supply chain, including operations and security engineering work. Some ideas include rubygems.org scaling and stability; better package signing; increasing support for multi-factor authentication; maintaining commonly-used libraries; and generally improving common tools like Bundler.
But these are just suggestions! The Ruby Central team will continue to steward programming, projects, and initiatives in the most impactful direction for the community.
Shopify and Ruby Central will work together to periodically publish a report about the work being done to make Ruby better and more secure.
To send feedback to Ruby Central, email [contact@rubycentral.org](mailto:contact@rubycentral.org).
### June 2022 Monthly Update
URL: https://rubycentral.org/news/june-2022-monthly-update/
Last updated: 2022-11-28T23:39:45.000Z
Hello! Welcome to the monthly update. During June, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), and many others.
## ruby together news
In June, Ruby Together was supported by 32 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org). 1 company joined as a new member.
On top of that, 1 new developer signed up as a member. In total, we were supported by 127 developer members. Thanks to all of our members for making everything that we do possible. <3
## RubyGems news
This month in RubyGems, we released new versions of RubyGems [3.3.16](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3316--2022-06-15), [3.3.17](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3317--2022-06-29) and Bundler [2.3.16](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2316-june-15-2022), [2.3.17](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2317-june-29-2022).
The following is a non-exhaustive list of other improvements included in the above releases (see the changelog for further information):
- fixed a regression when loading old marshaled specs - [#5610](https://github.com/rubygems/rubygems/pull/5610?ref=rubycentral.org).
- improved performance of installing gems from gem server sources - [#5614](https://github.com/rubygems/rubygems/pull/5614?ref=rubycentral.org).
- fixed incorrect password redaction when there’s an error in `gem source -a` \- [#5623](https://github.com/rubygems/rubygems/pull/5623?ref=rubycentral.org).
- fixed some errors being printed twice in `--verbose` mode - [#5654](https://github.com/rubygems/rubygems/pull/5654?ref=rubycentral.org).
- created documentation on how to run `rake setup` as a regular user - [#5662](https://github.com/rubygems/rubygems/pull/5662?ref=rubycentral.org).
- added clear and descriptive messages when `gem update` fails to update some gems - [#5676](https://github.com/rubygems/rubygems/pull/5676?ref=rubycentral.org).
In June, RubyGems gained [168 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2022-06-01%7D...master@%7B2022-06-31%7D?ref=rubycentral.org), contributed by 13 authors. There were 1,610 additions and 1,233 deletions across 165 files.
## RubyGems.org news
In June, RubyGems.org saw several bug fixes and updates, some of which include the following:
- fixed confusion in MFA behaviour - [#3079](https://github.com/rubygems/rubygems.org/pull/3079?ref=rubycentral.org).
- added a prompt to notify users leaving without copying MFA recovery codes - [#3082](https://github.com/rubygems/rubygems.org/pull/3082?ref=rubycentral.org).
- removed API key `rubygems_id` from the form url query string - [#3085](https://github.com/rubygems/rubygems.org/pull/3085?ref=rubycentral.org).
- separated MFA methods from `User.rb` to its own concern `UserMultifactorMethods` \- [#3108](https://github.com/rubygems/rubygems.org/pull/3108?ref=rubycentral.org).
- added case insensitive uniqueness validation to user handles - [#3120](https://github.com/rubygems/rubygems.org/pull/3120?ref=rubycentral.org).
- added a per user rate limit to the `gem push` command - [#3121](https://github.com/rubygems/rubygems.org/pull/3121?ref=rubycentral.org).
- added a Capybara find method to wait for page to load when running tests - [#3124](https://github.com/rubygems/rubygems.org/pull/3124?ref=rubycentral.org).
This month, RubyGems.org gained [74 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2022-06-01%7D...master@%7B2022-06-31%7D?ref=rubycentral.org), contributed by 13 authors. There were 1,015 additions and 263 deletions across 63 files.
As always, we continue to fix bugs, review and merge PR’s and reply to support tickets.
## total spent
In June we completed 36.4 hours of development work @$150/hour, and spent $ 5,461.50.
Until next time,
Irene, André, and the Ruby Together team
### May 2022 Monthly Update
URL: https://rubycentral.org/news/may-2022-monthly-update/
Last updated: 2022-11-28T23:39:45.000Z
Hello! Welcome to the monthly update. During May, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), and many others.
## ruby together news
In May, Ruby Together was supported by 36 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org). On top of that we were supported by 133 developer members. Thanks to all of our members for making everything that we do possible. <3
# RubyGems News
This month in RubyGems, we released new versions of RubyGems [3.3.14](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3314--2022-05-18), [3.3.15](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3315--2022-06-01) and Bundler [2.3.14](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2314-may-18-2022), [2.3.15](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2315-june-1-2022).
The following is a non-exhaustive list of other improvements included in the above releases (see the changelog for further information):
- fixed a regression causing an error message when an incompatible Ruby version is used - [#5525](https://github.com/rubygems/rubygems/pull/5525?ref=rubycentral.org).
- fixed an issue with inline mode install output printing information about previously locked gems - [#5529](https://github.com/rubygems/rubygems/pull/5529?ref=rubycentral.org), [#5530](https://github.com/rubygems/rubygems/pull/5530?ref=rubycentral.org).
- fixed a regression when printing resolution conflicts on metadata requirements - [#3362](https://github.com/rubygems/rubygems/pull/5562?ref=rubycentral.org).
- refactored the code that handles finding a target version in `gem update --system` \- [#5568](https://github.com/rubygems/rubygems/pull/5568?ref=rubycentral.org).
- made an update to display better error messaging when previous installation fails to be removed -[#5664](https://github.com/rubygems/rubygems/pull/5564?ref=rubycentral.org).
- improved exception reporting in bug report template - [#5563](https://github.com/rubygems/rubygems/pull/5563?ref=rubycentral.org).
In May, RubyGems gained [84 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2022-05-01%7D...master@%7B2022-05-31%7D?ref=rubycentral.org), contributed by 9 authors. There were 851 additions and 472 deletions across 123 files.
# RubyGems.org News
In May, RubyGems.org saw several bug fixes and updates, some of which include the following:
- fixed access to undefined variable version in `GemcutterTaskshelper`\- [#3068](https://github.com/rubygems/rubygems.org/pull/3068?ref=rubycentral.org).
- fixed some lint failure issues - [#3069](https://github.com/rubygems/rubygems.org/pull/3069?ref=rubycentral.org).
- set UTC date format in `update_version_file_test` rake task - [#3066](https://github.com/rubygems/rubygems.org/pull/3066?ref=rubycentral.org).
- re-designed dependencies list on RubyGems UI - [#3062](https://github.com/rubygems/rubygems.org/pull/3062?ref=rubycentral.org).
- added a fix to find versions explicitly by name & platform - [#3060](https://github.com/rubygems/rubygems.org/pull/3060?ref=rubycentral.org).
This month, RubyGems.org gained [51 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2022-05-01%7D...master@%7B2022-05-31%7D?ref=rubycentral.org), contributed by 15 authors. There were 580 additions and 91 deletions across 35 files.
## total spent
In May we completed 56 hours of development work @$150/hour, and spent $8,398.50.
Until next time,
Irene, André, and the Ruby Together team
### RailsConf: Home Edition 2022 Speaker Spotlight: Thomas Countz
URL: https://rubycentral.org/news/railsconf--home-edition-2022-speaker-spotlight--thomas-countz/
Last updated: 2022-11-28T23:39:45.000Z
RailsConf2022 boasts an exciting variety of tracks and talks that highlight the creativity and interdisciplinary nature of the Ruby community. As a tech sector newcomer, I thought it would be fun to curate a series highlighting talks that immediately captured my curiosity, and get to know their respective speakers a little better. Read on for today’s speaker spotlight…
### Title of Talk:
Leveling Up from Planning to Production
### Speaker: Thomas Countz

### How Did you get into Ruby?
I was learning how to code from books and resources on the internet. Originally, I was really into Python because I enjoyed the “There should be one– and preferably only one –obvious way to do it” ethos codified in the Zen of Python (link: https://peps.python.org/pep-0020/). Python felt learnable to me.
Then, I found a resource called The Odin Project (link: https://www.theodinproject.com/) that vibed with the way that I enjoyed learning. It used a language called “Ruby” and taught a framework called “Ruby on Rails,” and that’s when I discovered web development, which seemed like a great way to enter the software engineering industry!
As luck would have it, at the same time of discovering this thing called “Ruby,” I was working at a coffee shop where a regular customer would come in and work. I got a peek at their screen one day and… WHAT?! “IS THAT RUBY?!” Sure enough, it was!
Not only was it Ruby, but the woman writing it ended up becoming my best friend and mentor. The story of “how I got into Ruby,” cannot be separated from, “how did you meet your best friend Christine,” because meeting Christine is the story of Ruby. Rubyists support each other, they teach, they get excited about expanding the community, they create resources, give back, and on top of it all, they’re wicked smart.
Having her invest and believe in me is the inciting incident that lead me to where I am today.
### What’s your favorite part about working on Open Source Software?
The reach, impact, and community. Working on OSS, rather than only using it, means you are on the forefront of solving issues that can have a huge impact! I love solving problems and it seems like the larger the impact, the more satisfying it is for me to contribute.
That being said, it’s not something I’ve done a lot of. Those who are consistent contributors are also often great community leaders. What motivates me most to becoming a contributor means giving back to the community which has given me so much!
### What’s your least favorite part about working on OSS?
The barrier to entry. I don’t know that there’s a silver bullet to this; maintainers can invest A LOT into getting people onboarded to contributing, but going from OSS user to OSS contributor can feel like a wide chasm.
That being said, because it’s my “least favorite part,” I’m fiercely interested in finding out how to make it easier for folks to get started!
### What inspired you to give this talk?
As I became more senior, I felt the structures around me beginning to fall down. As a junior, those “structures,” were patterns of work that I’d been taught to use in order to navigate small tasks: write tests, ask to pair, read about code smells, develop good PR hygiene…
As a senior, it seemed like there were no structures—no guidelines—for approaching bigger responsibilities. Everyone kind of just figured it out for themselves. How do we communicate about larger and larger systems? How do we look at a business priority and systematically know how to approach it from an engineering perspective? How do we become responsible for work that can span months, not just days?
I had to get more comfortable not knowing what I was doing. Getting good at not knowing sounds like it’s easy, but it’s actually a huge responsibility! You have to admit to what you don’t know and make a plan for how you’ll reduce those unknowns over time. As I had chats with colleagues about this, it turned out that lots of them felt this same dissonance.
### What do you want people to take away from it?
I hope that people will take away some practical examples of how to lean into unknowns, rather than shy away from them. Not only is it okay not to know something, it’s our job to recognize gaps in our knowledge and to develop a strategy for navigating them in order to get our work done.
### What are you most looking forward to at this conference?
I was really looking forward to maybe making a friend or two… As it turned out, I’d made dozens! Everyone at RailsConf was so eager to learn from each other. It was truly inspiring. I’m still riding the wave of encouragement and inspiration!
### Did you do anything fun in Portland during conference week?
While I was in Portland, I went to arcades and coffee shops and diners and bars… it was never ending, but I wouldn’t have had it any other way.
### Thank you, Thomas, for sharing a bit of your story. See you at RailsConf2022: Home Edition!
### April 2022 Monthly Update
URL: https://rubycentral.org/news/april-2022-monthly-update/
Last updated: 2022-11-28T23:39:45.000Z
Hello! Welcome to the monthly update. During April, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), and many others.
## ruby together news
In April, Ruby Together was supported by 37 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org). 1 company joined as a new member.
On top of that, 1 new developer, Jens Krämer, signed up as a member. In total, we were supported by 137 developer members. Thanks to all of our members for making everything that we do possible. <3
# RubyGems News
In April, we released new versions of RubyGems [3.3.11](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3311--2022-04-07), [3.3.12](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3312--2022-04-20) and Bundler [2.3.11](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2311-april-7-2022), [2.3.12](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2312-april-20-2022).
The main highlight of this month’s update is that RubyGems now has experimental built-in support for Rust extensions, thanks to the work done on [#5175](https://github.com/rubygems/rubygems/pull/5175?ref=rubycentral.org).
The following is a non-exhaustive list of other improvements included in the above releases (see the changelog for further information):
- added modern versions of Ruby as valid platform values in Gemfile DSL Spec file - [#5469](https://github.com/rubygems/rubygems/pull/5469?ref=rubycentral.org).
- stopped considering `RUBY_PATCHLEVEL` for resolution - [#5472](https://github.com/rubygems/rubygems/pull/5472?ref=rubycentral.org).
- enabled multi-factor authentication on specific keys during `gem signin` \- [#5305](https://github.com/rubygems/rubygems/pull/5305?ref=rubycentral.org).
This month, RubyGems gained [86 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2022-04-01%7D...master@%7B2022-04-30%7D?ref=rubycentral.org), contributed by 13 authors. There were 977 additions and 599 deletions across 64 files.
# RubyGems.org News
This month, RubyGems.org saw several bug fixes and updates, some of which include the following:
- replaced instances of `blacklist` with `blocklist`, and `whitelist` with `allowlist` \- [#3033](https://github.com/rubygems/rubygems.org/pull/3033?ref=rubycentral.org).
- updated ERD diagram to reflect the current database structure - [#3032](https://github.com/rubygems/rubygems.org/pull/3032?ref=rubycentral.org).
- updated `elasticsearch-rails` gems - [#3028](https://github.com/rubygems/rubygems.org/pull/3028?ref=rubycentral.org).
- migrated from using `kubernetes-deploy` to krane - [#3018](https://github.com/rubygems/rubygems.org/pull/3018?ref=rubycentral.org).
- added a validation step prior to updating unconfirmed emails - [#3009](https://github.com/rubygems/rubygems.org/pull/3009?ref=rubycentral.org).
In April, RubyGems.org gained [88 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2022-04-01%7D...master@%7B2022-04-31%7D?ref=rubycentral.org), contributed by 12 authors. There were 1,266 additions and 733 deletions across 79 files.
## total spent
In April we completed 48.5 hours of development work @$150/hour, and spent $7,275.00.
Until next time,
Irene, André, and the Ruby Together team
### RailsConf2022 Speaker Spotlight: Vladimir Dementyev
URL: https://rubycentral.org/news/railsconf2022-speaker-spotlight--vladimir-dementyev/
Last updated: 2022-11-28T23:39:45.000Z
RailsConf2022 boasts an exciting variety of tracks and talks that highlight the creativity and interdisciplinary nature of the Ruby community. As a tech sector newcomer, I thought it would be fun to curate a series highlighting talks that immediately captured my curiosity, and get to know their respective speakers a little better. Read on for today’s speaker spotlight…
### Title of Talk:
The pitfalls of realtime-ification
### Speaker: Vladimir Dementyev

### How Did you get into Ruby?
I was looking for an alternative tech to rebuild my product, and found an online course titled “Building SaaS web applications with Ruby on Rails”. That was a match.
### What’s your favorite part about working on Open Source Software?
An ability to share my work/thoughts with others, making something useful not just for myself (or my company), but everyone.
### What’s your least favorite part about working on OSS?
Lack of feedback when everything behaves as expected; you mostly hear from people when there are issues with your software.
### What inspired you to give this talk?
I realized that since the Rails 7 and Hotwire release, more and more people started asking me similar questions on how to properly design real-time features (chats or whatever). After yet another conversation I just sat down and wrote the outline of the talk.
### What do you want people to take away from it?
The answers. The solutions. The understanding that simply dropping Hotwire/Action Cable to the stack and using awesome Rails abstractions is not enough, you should do a paradigm shift.
### What are you most looking forward to at this conference?
Finally meeting people of meat and bones, of course.
### Do you have any other plans in Portland during conference week that you’re excited about?
Unfortunately, I’m coming only for the conference. I plan to get around the city, learn as much as possible about it and its surroundings to come back later with my family.
### Thank you, Vladimir, for sharing a bit of your story. See you at RailsConf2022!
### RailsConf On Tracks
URL: https://rubycentral.org/news/railsconf-on-tracks/
Last updated: 2022-11-28T23:39:44.000Z
If you’re looking for a curated conference experience this year, you can allow the RailsConf 2022 program committee to choose your adventure and sit back and enjoy your journey through the conference via a track.
The conference tracks are listed on the program and can be chosen up until the moment the first session starts. If you do select a track, there’s no obligation to stay on it. You’re free to move between tracks, move in and out of a track, or start on a track and then move on to general talks if you’d like.
Or, “there’s always the hallway track,” as RailsConf 2022 program committee member Aisha Blake puts it.
But if you do decide to stick to a track through the entirety of the conference, you’re in for a treat. The talks in each track aren’t simply grouped together by category, their sequence is considered and intentional.
“The talks are ordered,” RailsConf 2022 program co-chair Max Tiu explains, “and narratives are crafted.” As a result, “you get more of a cohesive experience around an area of interest.”
You may still be wondering: “Should I choose a conference track? And if so, which one?” Well, you’re in luck! I connected with the program committee curating this year’s tracks to ask why they chose each talk, and what to look forward to from each track. Read on to get a closer view of the RailsConf 2022 tracks…
### Make a switch
“What if you made a radical shift?” poses Brittany Martin, an Engineering Manager and cohost of the Ruby on Rails Podcast. She curated the “Make a Switch” track, which is officially described as:
> The track for the ambitious speakers who made a switch and the lessons they learned along the way. Left React for Hotwire? Refocused from logging to telemetry? In-sourced what you out-sourced? Bring your radical tooling, workflow and approach changes to this track.
“As a podcaster, I love storytelling so I was excited to craft a track where developers like us could share the ambitious risks they took and the technical takeaways.”
Martin anticipates that this track may lead to an “aha” moment for those who choose it, and she encourages teams to attend talks together, especially if they are relevant to your stack.
This track is ideal for developers at all levels who have influence over technical and process decisions on their team.
Martin encourages potential attendees with the reminder that “even if the subject in not in your wheelhouse (i.e. Frontend or DevOps tooling), you are not only attending for yourself but for your colleagues and friends.”
Interest piqued? Here are [the talks in the Make a Switch track](https://railsconf.org/program/sessions?ref=rubycentral.org#track-make-a-switch).
### Explain It Like I’m Five
If you’re seeking a crash course on some of the most fundamental concepts in Rails, “Explain It Like I’m Five” (or ELIF) is your perfect lane.
Software engineer Emily Giurleo organized this track. Like the popular subreddit, she hopes it will serve as a welcoming space for conference goers to get a breakdown of core concepts, tools and skills that may seem complicated on the surface.
“Too often, people think that certain concepts are too advanced for them to understand. I wanted to show that there is no such thing as ‘too advanced’ – with the right framing, any of us can understand concepts usually reserved for experts,” Giurleo explains.
She believes this track will appeal to developers at different levels for different reasons. For beginner and mid-level developers these talks will offer a chance to move toward mastery of the Ruby on Rails framework. Meanwhile, experienced developers will be able to sharpen their skills when it comes to communicating advanced topics in an approachable way.
If you’re looking to go in depth on specific topics, this track is not for you. Giurleo explains, “While the talks on this track do cover advanced topics, they are meant to serve as an entry point.”
Get started on a new concept with [the talks in the Explain It Like I’m Five track](https://railsconf.org/program/sessions?ref=rubycentral.org#track-explain-it-like-i-m-five).
### Open Source Maintenance
“There is no harder maintenance case than ‘thousands of people already use this and the core team is distributed all over the world working at different companies,’” says Chelsea Troy, Mozilla Staff Software Engineer and the curator of the Open Source Maintenance Track.
And yet according to Troy, most new developers are steered toward learning how to build something from scratch. “That’s almost never the case we’re talking about in the professional world,” she says.
As an educator, Troy specializes in highlighting the areas of software engineering that are undervalued and yet essential in the day-to-day context for developers.
Successful communication, versioning, and maintenance practices have been refined and standardized in popular open source projects out of necessity.
However, Troy contends these skills are “useful for all (or most) dev teams to learn from and adopt—including closed-source, private, or proprietary software teams like the ones that send their people to RailsConf.”
Common concerns like “testing for regressions, documentation, managing communities, and debugging” will be covered. Troy expects that the talks in this track will cater to a mixed-level audience.
She’s looking forward to talks that offer an exciting spin on topics that too often go under-appreciated.
Preview the lessons from open source in [the talks of the Open Source Maintenance track](https://railsconf.org/program/sessions?ref=rubycentral.org#track-open-source-maintenance).
### Community Content
Rubyists interested in starting or elevating their content, be it blogs, podcasts, tutorials, meetups, books, games and more, should head straight for the Community Content track.
Curated by Aisha Blake, director of developer relations for Pluralsight, the track will feature experienced creators of both digital and analogue content for the Ruby community.
“One of the questions that I get pretty frequently is: how do I how do I get started?”, says Blake about her desire to curate the track.
“You show up and you see the people who are giving the talks… hopefully, you learned something, or you’re moved by a story that they told. The exciting part about this track is that you can start to do those same things yourself. You can learn how to leverage your own story, your own work, your own interests to kind of elicit that same reaction in other people.”
Blake is passionate about the power of effective communication to “not only educate, but to excite, inspire, engage” audiences, and is looking forward to using this space to uplift creators and educators in the Ruby community, as well as help new ones get started.
She is excited about the “Give Your First Talk” workshop in this track, taking place in the morning on the last day of the conference. She encourages anyone who is even a little bit drawn to it to attend.
“Take the opportunity. Like, try it out. Go talk it through with people who are kind of in the same boat with you, and don’t be afraid to to put yourself out there a little bit.”
Learn ways you can start creating in [the talks from the Community Content track](https://railsconf.org/program/sessions?ref=rubycentral.org#track-community-content).
Whether you choose to go with a conference track, or freestyle RailsConf 2022, we hope this was helpful, and has you excited for the talks next week. We look forward to seeing you there!
### RailsConf2022 Speaker Spotlight: Andy Andrea
URL: https://rubycentral.org/news/railsconf2022-speaker-spotlight--andy-andrea/
Last updated: 2022-11-28T23:39:45.000Z
RailsConf2022 boasts an exciting variety of tracks and talks that highlight the creativity and interdisciplinary nature of the Ruby community. As a tech sector newcomer, I thought it would be fun to curate a series highlighting talks that immediately captured my curiosity, and get to know their respective speakers a little better. Read on for today’s speaker spotlight…
### Title of Talk:
Computer science you might (not) want to know
### Speaker:
Andy Andrea

### How Did you get into Ruby?
As I was finishing up school, I got lucky enough to land an internship at a great company that primarily used Ruby on their various projects. Since then, it’s been my language of choice.
### What’s your favorite part about working on Open Source Software?
Open source software is one of the greatest melting pots of the digital age: so many people with so many different backgrounds are teaching, learning and creating all at once, and the output ranges from useful to artistic to ridiculous.
### What’s your least favorite part about working on OSS?
In my current role where the code I write one day is likely owned by a different entity than the code I write the next, it’s often difficult to figure out what sections of the code–if any–can be open sourced. As a result, it can take a lot more communication and effort to write open source code than it does to stick with the status quo and leave everything in a private repo.
### What inspired you to give this talk?
I’m a huge believer that anyone can be a great dev regardless of their background if they’re given the right resources, so it’s always frustrating to see any needless barriers thrown up that make getting a career in software development harder or more discouraging. One such barrier is the sentiment that a formal degree in computer science is needed to be a great developer. I hope to show the flaws in this belief by demonstrating that even some of the topics in computer science that can be handy to know as developers are often not terribly relevant to the day-to-day problems that we encounter.
### What do you want people to take away from it?
I hope that everyone will pick up some good tips and tricks to inform their software development strategies and to better understand some of the problems they encounter, but I also hope to show that a formal computer science education is just one valid path among infinitely many that lead to becoming a talented software developer.
### What are you most looking forward to at this conference?
I love learning and meeting smart and caring people; in my experience, the Ruby community is great at providing both.
### Do you have any other plans in Portland during conference week that you’re excited about?
I always love to hike and wander around parks and other green spaces, and it looks like Portland has a lot to offer. As a book lover, I’m also definitely making a trip to Powell’s.
### Thank you, Andy, for sharing a bit of your story. See you at RailsConf2022!
### RailsConf2022 Speaker Spotlight: Kevin Murphy
URL: https://rubycentral.org/news/railsconf2022-speaker-spotlight--kevin-murphy/
Last updated: 2022-11-28T23:39:45.000Z
RailsConf2022 boasts an exciting variety of tracks and talks that highlight the creativity and interdisciplinary nature of the Ruby community. As a tech sector newcomer, I thought it would be fun to curate a series highlighting talks that immediately captured my curiosity, and get to know their respective speakers a little better. Read on for today’s speaker spotlight…
### Title of Talk:
Browser History Confessional: Searching My Recent Searches
### Speaker:
Kevin Murphy

### How Did you get into Ruby?
My manager bet me that I could write a basic application we were responsible for in Rails, when I had no prior experience with either Ruby or Rails, faster than I could using our existing Java toolchain. I took him up on it, and I’ve never looked back.
### What’s your favorite part about working on Open Source Software?
Learning from the contributions of others.
### What’s your least favorite part about working on OSS?
Figuring out how to sustainably contribute in a productive way.
### What inspired you to give this talk?
I thought it might be funny to come clean about some real things I had to search for recently to successfully do my job. Then the Program Committee selected my talk, and it got less funny - but hopefully people still enjoy it.
### What do you want people to take away from it?
We have a lot of tools at our disposal to do our jobs, and searching for external knowledge is one of them. That doesn’t mean it’s one we should reach for all the time, but when we do, we should do so intentionally. If we understand *why* we’re using the tool of search, we can better control the strategies we take to get the resolution we want. It doesn’t always work out that way, but that small amount of pre-work can save you some time in the end - or at least put you in the right frame of mind.
### What are you most looking forward to at this conference?
Reconnecting with old friends and meeting some in person for the first time.
### Do you have any other plans in Portland during conference week that you’re excited about?
If my plane is on time, I’ll have all day Monday to explore the city, but have no plans. I’ve never been to Portland before - I’ll accept any tips or suggestions!
### Thank you, Kevin, for sharing a bit of your story. See you at RailsConf2022!
### RailsConf2022 Speaker Spotlight: Adam Cuppy
URL: https://rubycentral.org/news/railsconf2022-speaker-spotlight--adam-cuppy/
Last updated: 2022-11-28T23:39:45.000Z
RailsConf2022 boasts an exciting variety of tracks and talks that highlight the creativity and interdisciplinary nature of the Ruby community. As a tech sector newcomer, I thought it would be fun to curate a series highlighting talks that immediately captured my curiosity, and get to know their respective speakers a little better. Read on for today’s speaker spotlight…
### Title of Talk:
Don’t Touch That!
### Speaker:
Adam Cuppy

### How Did you get into Ruby?
I came from acting/arts and not from computer software engineering. In 2008 I was working in marketing and moonlighting as a PHP software developer. From the outside, I was continually inspired by how many problems good software could solve. However, programming is such an abstract art form. For that reason, it’s hard to get involved. But then, I saw David’s video “Build a blog in 15-minutes with Ruby on Rails,” and I was blown away.
It was impressive that Rails could do what it does, but that the Ruby language was so elegant and intuitive - in Ruby talk, it was “developer-friendly.” I. Was. Hooked.
Since that video, I got more involved. By 2011 I had started my first software development agency. Our company leaned on Ruby and Ruby on Rails because it’s effective and well supported. We didn’t need a degree. We didn’t need a certificate. We just needed a code editor. Within a few years, we built new careers for ourselves and found a path to a new life.
I can thank many content creators for giving so much back to my professional life; however, nothing compares to Ruby and the Rails community. While I don’t appreciate all the strong opinions of David and others in the community, I can’t deny their impact on my life.
### What’s your favorite part about working on Open Source Software?
The community, and that it’s free. Money is a huge barrier for most projects. I understand why it’s important at some point, but for new people - going into anything - free matters.
### What’s your least favorite part about working on OSS?
Nothing. It’s fantastic.
### What inspired you to give this talk?
The students of LEARN academy (code school in San Diego).
### What do you want people to take away from it?
Never forget that experimenting, breaking, and putting things back together is how the best discoveries are made. Don’t play it safe while you’re learning. Get messy.
### What are you most looking forward to at this conference?
Seeing people. I’m an extrovert. Being around others is a big part of why I attend conferences. I’ve made so many friends in this community, and seeing them sans the virtual background is very exciting after two years.
### Do you have any other plans in Portland during conference week that you’re excited about?
I grew up in Portland, so seeing the city I love again. AND EATING THE FOOD! The best town for breakfast foodies.
### Thank you, Adam, for sharing a bit of your story. See you at RailsConf2022!
### Countdown to RailsConf2022!
URL: https://rubycentral.org/news/countdown-to-railsconf2022-/
Last updated: 2022-11-28T23:39:44.000Z
Welcome to our first dispatch from Ruby Central!
We’re currently coming to you from our temporary home on the Ruby Together Blog. The new Ruby Central blog website is still being developed — but with the conference approaching faster than a train on high speed rails ;), we couldn’t wait to start bringing you content.
Our first posts will be centered on the upcoming in-person RailsConf2022, happening in Portland, Oregon May 17 -19\. The program schedule is live and can be found [here](https://railsconf.org/program?ref=rubycentral.org).
We’re ecstatic to be able to continue to gather live for this conference despite the COVID-19 pandemic. In order to do so safely, we are asking all attendees to please adhere to our COVID safety requirements. You can find them [here](https://railsconf.org/covid?ref=rubycentral.org).
To RSVP for conference workshops [click here](https://www.eventbrite.com/e/railsconf-2022-rsvps-for-workshops-tickets-317806607117?ref=rubycentral.org), and make sure to check out and RSVP to our official social events ([here](https://www.eventbrite.com/e/railsconf-2022-rsvps-for-official-railsconf-social-events-tickets-317317534287?ref=rubycentral.org)) if you can!
Stay tuned to this space for more on the upcoming conference. Your blogger is not a tech industry expert and I’m excited to bring a fresh perspective and a focus on “the basics” to these posts. Enjoy!
### March 2022 Monthly Update
URL: https://rubycentral.org/news/march-2022-monthly-update/
Last updated: 2022-11-28T23:39:45.000Z
Hello! Welcome to the monthly update. During March, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), and many others.
## ruby together news
In March, Ruby Together was supported by 37 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org). 21 companies joined as new members.
On top of those companies, 21 new developers signed up as members, including Jason Knebel, Bryan Culver, Chris Sargeant, David Balatero, Misfit VN, David Blackmon, Matt Brooke-Smith, Joel E. Svensson, Jonathan R Wallace, Jordan Humphreys, Justin Kuepper, Justin Thiele, and Keith Tom. In total, we were supported by 138 developer members. Thanks to all of our members for making everything that we do possible. <3
# RubyGems News
This month, we released new versions of RubyGems [3.3.9](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#339--2022-03-09), [3.3.10](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3310--2022-03-23) and Bundler [2.3.9](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#239-march-9-2022), [2.3.10](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2310-march-23-2022).
Some notable changes include:
- worked on a small regression in Bundler 2.3.7 and released a fix with Bundler 2.3.9 - [#5386](https://github.com/rubygems/rubygems/pull/5386?ref=rubycentral.org).
- merged some improvements to RDoc documentation - [#5396](https://github.com/rubygems/rubygems/pull/5396?ref=rubycentral.org), [#5398](https://github.com/rubygems/rubygems/pull/5398?ref=rubycentral.org), [#5399](https://github.com/rubygems/rubygems/pull/5399?ref=rubycentral.org).
- enabled `net-http-persistent` to get in sync with the version we use in vendor - [#5394](https://github.com/rubygems/rubygems/pull/5394?ref=rubycentral.org).
- merged a PR that reports Github Actions as a CI provider within the user agent string by checking the `GITHUB_ACTIONS` env variable - [#5400](https://github.com/rubygems/rubygems/pull/5400?ref=rubycentral.org).
As always, see [the full changelog](https://github.com/rubygems/rubygems/compare/master@%7B2022-03-01%7D...master@%7B2022-03-31%7D?ref=rubycentral.org) for a complete list of changes.
In March, RubyGems gained [145 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2022-03-01%7D...master@%7B2022-03-31%7D?ref=rubycentral.org), contributed by 14 authors. There were 1,622 additions and 167 deletions across 88 files.
# RubyGems.org News
This month, RubyGems.org saw several bug fixes and updates, some of which include the following:
- increased `GEM_REQUEST_LIMIT` to fix the 422 response with `gem install aws` \- [#2991](https://github.com/rubygems/rubygems.org/pull/2991?ref=rubycentral.org).
- added `Toxiproxy` to `docker-compose` in host network mode - [#2981](https://github.com/rubygems/rubygems.org/pull/2981?ref=rubycentral.org).
- refactored `link_to_github` code - [#2980](https://github.com/rubygems/rubygems.org/pull/2980?ref=rubycentral.org).
- fixed deprecations recording when running tests - [#2979](https://github.com/rubygems/rubygems.org/pull/2979?ref=rubycentral.org).
In March, RubyGems gained [38 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2022-03-01%7D...master@%7B2022-03-31%7D?ref=rubycentral.org), contributed by 6 authors. There were 811 additions and 531 deletions across 30 files.
## total spent
In March we completed 32.4 hours of development work @$150/hour, and spent $4,860.00.
Until next time,
Irene, André, and the Ruby Together team
### February 2022 Monthly Update
URL: https://rubycentral.org/news/february-2022-monthly-update/
Last updated: 2022-11-28T23:39:44.000Z
Hello! Welcome to the monthly update. During February, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), and many others.
## ruby together news
In February, Ruby Together was supported by 35 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org). 1 company joined as a new member.
On top of that, 1 new developer, Ye Lin Aung, signed up as a member. In total, we were supported by 122 developer members. Thanks to all of our members for making everything that we do possible. <3
# RubyGems News
This month in RubyGems, we released new versions for RubyGems [3.3.7](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#337--2022-02-09), [3.3.8](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#338--2022-02-23) and Bundler [2.3.7](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#237-february-9-2022), [2.3.8](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#238-february-23-2022).
The following is a non-exhaustive list of the improvements included in the above releases (see changelogs for further information):
- resolved some long-standing issues with our CI workflow and worked on some long-standing configuration issues - [#5324](https://github.com/rubygems/rubygems/pull/5324?ref=rubycentral.org).
- fixed an issue with a corrupt lockfile that occurred when running `bundle check` and re-resolving locally - [#5344](https://github.com/rubygems/rubygems/pull/5344?ref=rubycentral.org).
- fixed a typo in the multiple gemfiles warning - [#5342](https://github.com/rubygems/rubygems/pull/5342?ref=rubycentral.org).
- added clarification for `bundle-config` `"with"` option - [#5346](https://github.com/rubygems/rubygems/pull/5346?ref=rubycentral.org).
- fixed an issue with `BUNDLE_WITH` and `BUNDLE_WITHOUT` environment variables being silently persisted locally - [#5335](https://github.com/rubygems/rubygems/pull/5335?ref=rubycentral.org).
- `bundle config` now saves configuration locally by default when run inside an application context - [#4512](https://github.com/rubygems/rubygems/pull/4152?ref=rubycentral.org).
In February, RubyGems gained [45 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2022-02-01%7D...master@%7B2022-02-31%7D?ref=rubycentral.org), contributed by 9 authors. There were 252 additions and 160 deletions across 58 files.
# RubyGems.org News
This month, RubyGems.org saw several bug fixes and updates, some of which include the following:
- enabled **Rails 6.1** default in `application.rb` \- [#2966](https://github.com/rubygems/rubygems.org/pull/2966?ref=rubycentral.org).
- disabled `mfa_required_since` usage - [#2965](https://github.com/rubygems/rubygems.org/pull/2965?ref=rubycentral.org).
- fixed Rubocop warning by re-enabling Ruby and excluding some files - [#2955](https://github.com/rubygems/rubygems.org/pull/2955?ref=rubycentral.org).
In February, RubyGems.org gained [60 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2022-02-01%7D...master@%7B2022-02-31%7D?ref=rubycentral.org), contributed by 6 authors. There were 350 additions and 208 deletions across 28 files.
## total spent
In February we completed 21.4 hours of development work @$150/hour, and spent $3,210.00.
Until next time,
Irene, André, and the Ruby Together team
### January 2022 Monthly Update
URL: https://rubycentral.org/news/january-2022-monthly-update/
Last updated: 2022-11-28T23:39:44.000Z
Hello! Welcome to the monthly update. During January, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), and many others.
## ruby together news
In January, Ruby Together was supported by 35 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org). One company joined as a new member.
On top of that, one new developer, Ye Lin Aung, signed up as a member. In total, we were supported by 122 developer members. Thanks to all of our members for making everything that we do possible. <3
## RubyGems News
This month in RubyGems, we released new versions for RubyGems [3.3.5](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#335--2022-01-12), [3.3.6](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#336--2022-01-26) and Bundler [2.3.5](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#235-january-12-2022), [2.3.6](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#236-january-26-2022).
The following is a non-exhaustive list of the improvements included in the above releases (see changelogs for more details):
- merged tentative support for `--enable-load-relative` Ruby configuration flag in our bin stubs to fix some `gem install` issues on Windows - [#2929](https://github.com/rubygems/rubygems/pull/2929?ref=rubycentral.org).
- published a blog post about [Bundler Version Switching](https://bundler.io/blog/2022/01/23/bundler-v2-3.html?ref=rubycentral.org) and released documentation for Bundler 2.3 on bundler.io.
- fixed regression with old marshaled specs having null `required_rubygems_version` \- [#5291](https://github.com/rubygems/rubygems/pull/5291?ref=rubycentral.org).
In January, Rubygems gained [113 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2022-01-01%7D...master@%7B2022-01-31%7D?ref=rubycentral.org), contributed by 14 authors. There were 1,623 additions and 864 deletions across 139 files.
## RubyGems.org News
This month, RubyGems.org saw several bug fixes and updates, some of which include the following:
- enabled `Rails 6.1` defaults - [#2917](https://github.com/rubygems/rubygems.org/pull/2917?ref=rubycentral.org).
- added a `rake task` to send [ownership request notifications](https://github.com/rubygems/rubygems.org/commit/4cb656a9cc342af171379915835a977c3e88ea91?ref=rubycentral.org).
- verified [session for Gem owners](https://github.com/rubygems/rubygems.org/commit/8368872dea4907d9c39b3f5125f4ea7b17df1232?ref=rubycentral.org) before showing adoptions page.
- published [RubyGems adoptions blog post](https://blog.rubygems.org/2022/01/19/rubygems-adoptions.html?ref=rubycentral.org).
In January, Rubygems.org gained [48 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2022-01-01%7D...master@%7B2022-01-31%7D?ref=rubycentral.org), contributed by 5 authors. There were 443 additions and 121 deletions across 37 files.
## total spent
In January we completed 31.4 hours of development work @$150/hour, and spent $4,713.00.
Now that we’ve [joined Ruby Central](https://rubytogether.org/news/2021-10-21-ruby-together-and-ruby-central-coming-together?ref=rubycentral.org), we don’t have dedicated income or overheads to report. We’ll keep reporting on the open source development work we’ve funded, and continue to keep you all updated as Ruby Central builds out a bigger, better membership program for all of you.
Until next time,
Irene, André, and the Ruby Together team
### December 2021 Monthly Update
URL: https://rubycentral.org/news/december-2021-monthly-update/
Last updated: 2022-11-28T23:39:44.000Z
Hello! Welcome to the monthly update. During December, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), and many others.
## ruby together news
In December, Ruby Together was supported by 35 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org). 2 companies joined as new members.
On top of those companies, 2 new developers signed up as members, including Kyoungwon Lee. In total, we were supported by 124 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems & bundler news
In December, we released new versions for RubyGems [3.3.0](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#330--2021-12-21), [3.3.1](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#331--2021-12-22), [3.3.2](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#332--2021-12-23), [3.3.3](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#333--2021-12-24), [3.3.4](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#334--2021-12-29) and Bundler [2.2.33](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2233-december-7-2021), [2.3.0](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#230-december-21-2021), [2.3.1](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#231-december-22-2021), [2.3.2](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#232-december-23-2021), [2.3.3](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#233-december-24-2021), [2.3.4](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#234-december-29-2021).
With this batch of releases, we finally shipped the Bundler automatic version switching feature, which had been planned for some time now, and provided final versions to be included with new Ruby 3.1 release.
This month, Rubygems gained [204 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2021-12-01%7D...master@%7B2021-12-31%7D?ref=rubycentral.org), contributed by 17 authors. There were 1,814 additions and 1,082 deletions across 186 files.
## rubygems.org news
In December, we enabled multifactor authentication on specific `api_keys` and updated the UI to reflect the change - [#2846](https://github.com/rubygems/rubygems.org/pull/2846?ref=rubycentral.org).
This month, Rubygems.org gained [34 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2021-12-01%7D...master@%7B2021-12-31%7D?ref=rubycentral.org), contributed by 5 authors. There were 377 additions and 112 deletions across 31 files.
As always, we continue to fix bugs, review and merge PR’s and reply to support tickets.
## budget & expenses
In December we spent a total of $10,529.13.
- Stripe Payment Processing Fees $13.70
- Employee Related $450.90
- General & Administrative $170.00
- IT & Software $1,042.58
- Professional services $219.00
- 57.6 Hours of development work at $150/hr $8,632.95
Until next time,
Irene, André, and the Ruby Together team
### November 2021 Monthly Update
URL: https://rubycentral.org/news/november-2021-monthly-update/
Last updated: 2022-11-28T23:39:44.000Z
Hello! Welcome to the monthly update. During November, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), and many others.
## ruby together news
In November, Ruby Together was supported by 34 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org). 3 companies joined as new members.
On top of those companies, 3 new developers signed up as members, including Naechrr and whysthatso. In total, we were supported by 124 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems & bundler news
This month, we released new versions for RubyGems [3.2.31](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3231--2021-11-08), and [3.2.32](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3232--2021-11-23), and Bundler [2.2.31](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2231-november-8-2021), and [2.2.32](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2232-november-23-2021).
Here are a few of the more interesting changes from those versions of RubyGems and Bundler. As always, see the changelogs for complete details.
- fixed a `gem fetch` vs. `gem install` inconsistency about platform-specific gems - [#5037](https://github.com/rubygems/rubygems/pull/5037?ref=rubycentral.org).
- fixed issues with `--destdir` and `--prefix` options to RubyGems installer to help OS packagers.
- improved an error message about git being missing - [#5036](https://github.com/rubygems/rubygems/pull/5036?ref=rubycentral.org), and fixed an issue where Bundler hid the system man pages - [#5039](https://github.com/rubygems/rubygems/pull/5039?ref=rubycentral.org).
- adapted both clients to a recent gemification of some libraries (`optparse,` `pathname`).
- improved `bundle install` usability by automatically unlocking dependencies if a lock file got expired by Gemfile changes, instead of logging an error message - [#5068](https://github.com/rubygems/rubygems/pull/5068?ref=rubycentral.org).
- fixed a `bundle update` issue related to not being able to downgrade Gemfile dependencies properly, and worked on some promising refactorings of Bundler internals in the context of ensuring we never generate corrupted lock files - [#5078](https://github.com/rubygems/rubygems/pull/5078?ref=rubycentral.org).
- started doing work on version locking for Bundler.
In November, RubyGems gained [134 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2021-11-01%7D...master@%7B2021-11-30%7D?ref=rubycentral.org), contributed by 12 authors. There were 3,815 additions and 743 deletions across 137 files.
## rubygems.org news
This month, RubyGems.org saw several bug fixes and updates, some of which include the following:
- updated and released support for ownership calls and requests - [#2748](https://github.com/rubygems/rubygems.org/pull/2748?ref=rubycentral.org).
- wrote a blog post for gem adoption - [#95](https://github.com/rubygems/rubygems.github.io/pull/95?ref=rubycentral.org).
- tested Ruby 3.0.3 for memory leak and deployed an update to Ruby 3 - [#2876](https://github.com/rubygems/rubygems.org/pull/2876?ref=rubycentral.org).
- debugged high CPU alert on Postgres.
In November, Rubygems.org gained [52 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2021-11-01%7D...master@%7B2021-11-30%7D?ref=rubycentral.org), contributed by 8 authors. There were 438 additions and 308 deletions across 63 files.
As always, we continue to fix bugs, review and merge PR’s and reply to support tickets.
## budget & expenses
In November, we saw $7,403.49 in total income, and spent a total of $10,251.14.
- Stripe Payment Processing Fees $272.25
- Employee Related $498.31
- General & Administrative $217.42
- IT & Software $1,169.15
- 52.5 Hours of development work at $150/hr $7,875.01
Until next time,
Irene, André, and the Ruby Together team
### October 2021 Monthly Update
URL: https://rubycentral.org/news/october-2021-monthly-update/
Last updated: 2022-11-28T23:39:44.000Z
Hello! Welcome to the monthly update. During October, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), and many others.
## ruby together news
In October, Ruby Together was supported by 35 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org). 12 companies joined as new members.
On top of those companies, 12 new developers signed up as members, including Mooktakim Ahmed, Valentino Stoll, Andrew Newell, Tim Tilberg, and Noah Stern. In total, we were supported by 121 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems & bundler news
In October, we released new versions of RubyGems: [3.2.29](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3229--2021-10-08), [3.2.30](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3230--2021-10-26) and Bundler: [2.2.29](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2229-october-8-2021), [2.2.30](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2230-october-26-2021).
The following is a non-exhaustive list of the improvements included in the above releases (see changelogs for more details):
- made `gem install` noticeably faster on Windows - [#4960](https://github.com/rubygems/rubygems/pull/4960?ref=rubycentral.org).
- made `bundle install` automatically reinstall deleted gems even when the lockfile is up to date - [#4974](https://github.com/rubygems/rubygems/pull/4974?ref=rubycentral.org).
- fixed an issue where lockfile checks were making Bundler crash - [#4941](https://github.com/rubygems/rubygems/pull/4941?ref=rubycentral.org).
- improved some errors when `bundle install` crashes due to permission issues, and also when gem tasks fail to run gem commands under the hood - [#4965](https://github.com/rubygems/rubygems/pull/4965?ref=rubycentral.org).
- added a couple of load improvements, like using `require_relative` in more places - [#4978](https://github.com/rubygems/rubygems/pull/4978?ref=rubycentral.org), and avoiding activating the digest gem from RubyGems - [#4979](https://github.com/rubygems/rubygems/pull/4979?ref=rubycentral.org).
This month, RubyGems gained [133 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2021-10-01%7D...master@%7B2021-10-31%7D?ref=rubycentral.org), contributed by 16 authors. There were 27,317 additions and 82,207 deletions across 2,572 files.
## rubygems.org news
This month, RubyGems.org saw several bug fixes and updates, some of which include the following:
- updated and released MFA requirement opt-in - [#2242](https://github.com/rubygems/rubygems.org/pull/2242?ref=rubycentral.org).
- wrote a guide for MFA requirement opt-in feature - [#297](https://github.com/rubygems/guides/pull/297?ref=rubycentral.org).
- debugged memory leaks after update to Ruby 3 was made, and reverted update - [#2843](https://github.com/rubygems/rubygems.org/issues/2843?ref=rubycentral.org).
- fixed race condition between version file update and version release - [#2811](https://github.com/rubygems/rubygems.org/pull/2811?ref=rubycentral.org).
- fixed broken transitive dependencies page for non-ruby platform versions - [#2816](https://github.com/rubygems/rubygems.org/pull/2816?ref=rubycentral.org).
- responded to pager calls for the database being overloaded by bot traffic and updated UI rate limit - [#2835](https://github.com/rubygems/rubygems.org/pull/2835?ref=rubycentral.org).
In October, RubyGems.org gained [49 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2021-10-01%7D...master@%7B2021-10-31%7D?ref=rubycentral.org), contributed by 7 authors. There were 873 additions and 120 deletions across 61 files.
As always, we continue to fix bugs, review and merge PR’s and reply to support tickets.
## budget & expenses
In October, we saw $7,549.37 in total income, and spent a total of $13,973.67.
- Stripe Payment Processing Fees $275.98
- Employee Related $696.16
- General & Administrative $172.31
- IT & Software $2,166.71
- 71.1 Hours of development work at $150/hr $10,662.51
Until next time,
Irene, André, and the Ruby Together team
### The New Ruby Central and How We Got Here
URL: https://rubycentral.org/news/the-new-ruby-central-and-how-we-got-here/
Last updated: 2022-11-28T23:39:44.000Z
You may have seen the [announcement](https://rubytogether.org/news/2021-10-21-ruby-together-and-ruby-central-coming-together?ref=rubycentral.org) in our latest news update, or heard word on the street, that the boards of Ruby Together and Ruby Central have combined under the umbrella of Ruby Central. It’s a fusion that felt like a long time coming, and one that will make things easier for members of both of our organizations, and for our teams too.
**So, what happened to Ruby Together?**
## What even *was* Ruby Together?
Ruby Together started as a trade organization that paid developers to work on RubyGems, Bundler, and more, using funds from members. Members could be any person or company who uses Ruby, and the work they paid for was free for anyone to use. Over the past six years Ruby Together grew to take on more ambitious projects and give back continuously to the Ruby ecosystem. Here’s a little bit of our story…
## Ruby Together was born out of necessity.
Back in the Ruby dark ages, everyone who worked on RubyGems.org was an unpaid volunteer. We were able to maintain this until… we weren’t. In 2013 RubyGems.org [went down completely](https://blog.rubygems.org/2013/01/31/data-verification.html?ref=rubycentral.org) — and stayed down for multiple days — all because no one had the time to fix a potential security issue fast enough. When the security issue was discovered everyone on the team was balancing work obligations. We decided that whichever one of us was done with work first would be the one to apply the security patches. As it turned out, no one was able to fix the problem before the weekend. Unfortunately, someone independently discovered the security issue and used it to hack the RubyGems.org server.
**The week that followed was a very bad week.** Multiple people who worked on RubyGems.org took unexpected time off from their paid jobs. We had to create completely new servers from scratch. We also had to download and verify every single one of the hundreds of thousands of .gem files, to make sure the hacker hadn’t replaced any of them while they had access. It felt like all the work we had done up until that point was a huge waste – and also showed us what a massive risk not having paid developers maintaining our systems could be.
After the incident, André, who was working on Bundler at the time, began to focus his efforts on finding funding to pay developers working on Bundler and RubyGems. In late 2014 he received an enthusiastic response from Stripe, who was the first to provide financial backing for the cause. Engine Yard followed soon after, and in February 2015 we launched Ruby Together as a trade organization.
In the years that have followed, we’ve funded the ongoing maintenance of Bundler and RubyGems, and managed to prevent any incidents of server downtime from occurring. On top of that, our members’ support has allowed us to expand our funded projects beyond infrastructure maintenance, making it possible to fund projects like [Ruby Toolbox](https://www.ruby-toolbox.com/?ref=rubycentral.org), [Ruby API](https://rubytogether.org/news/2021-07-01-a-new-approach-to-documentation-ruby-api?ref=rubycentral.org), and [SimpleCov](https://rubygems.org/gems/simplecov/versions/0.21.2?ref=rubycentral.org), and programs like [RubyMe](https://rubyme.org/?ref=rubycentral.org).
**We’ve also reached some huge milestones:**
- there are now over 175,000 gems (up from 101,000)
- there are over 1,216,000 versions of gems (up from 583,000)
- we have served 64 billion (!) gem downloads (up from 4.5 billion in 2015)
and made several other [accomplishments](https://rubytogether.org/news/2020-12-15-five-things-to-be-grateful-for-in-the-ruby-together-community?ref=rubycentral.org).
We’ve done all this while upholding [values](https://www.contributor-covenant.org/?ref=rubycentral.org) that support the wellness of the Ruby community.
## But there was an ongoing dilemma…
While we were carrying out our mission in more ways than we could have imagined when we started, Ruby users were confusing the mission and purpose of Ruby Together with that of Ruby Central. It was already an uphill battle to obtain support from companies for Ruby Together’s infrastructure-related open source work, as it’s work that is mostly invisible and has historically been done for free. The confusion between our two organizations only added to that challenge.
To try to address this, Ruby Together board member Jonan Scheffler put forward a vision of a single Ruby non-profit, and worked hard to get everyone on both boards engaged with that idea. Although at first there was some hesitation, it began to feel more and more like the right choice as the pandemic spurred Ruby Together towards new methods of community outreach and motivated Ruby Central to develop a membership program. Ultimately, both boards were able to hash out the details in a way everyone felt was a great fit.
We’re very happy to continue carrying out our original mission as a new organization that is still aligned with Ruby Together’s values.
## So, what’s next?
For Ruby Together members, your membership will continue to support the same work. We’ll continue to support paid development work on Bundler and RubyGems, and we will continue to fund other Ruby projects whenever we have funding to do so. You’ll still be able to connect with us in the ways that you were, and your Ruby Together membership will be transferred to the Ruby Central membership system automatically.
In addition, Ruby Central is launching a new membership program that will eventually include newsletters, virtual events, a dedicated Slack workspace, early registration and discounted tickets to our conferences. For corporate members, we plan to provide support with building brand awareness, and access to resources, people, and events.
Our goal is to grow our membership program and be the main hub for all Ruby programmers and institutions.
We know that combining the [mission](https://rubytogether.org/news/2021-10-18-staying-the-course?ref=rubycentral.org) of Ruby Together to financially support developers, with the immense value Ruby Central conferences provide our community, will only make us stronger. We look forward to continuing with you on this next chapter of our journey.
We’re excited to hear back from you! If you’re a member and have any questions or feedback at all about this transition, please [reach out to us](mailto:hello@rubytogether.org).
If you’re not a member, you can connect with us on [twitter](https://twitter.com/rubycentralorg?ref=rubycentral.org), or send us an [email](mailto:hello@rubytogether.org) and let us know what you think!
### Ruby Together and Ruby Central, coming together
URL: https://rubycentral.org/news/ruby-together-and-ruby-central--coming-together/
Last updated: 2022-11-28T23:39:44.000Z
Since Ruby Together was first started, we’ve worked together with [Ruby Central](https://rubycentral.org/). While Ruby Central has paid the server bills for RubyGems.org, Ruby Together has paid the software developers who keep it running. That cooperation has benefited the entire Ruby community for the last 6 years, ever since Ruby Together began.
While the cooperation has been beneficial, it’s been hard to explain. Many community members are surprised to learn that Ruby Together and Ruby Central are separate non-profits, and even those who know they are distinct struggle to keep track of exactly which one does exactly what things.
Last year, Ruby Together board member Jonan Scheffler pitched an idea: what if we were just one organization? After some non-profit business paperwork-handling, we’re proud to announce that dream has become a reality. Ruby Together and Ruby Central will become a single non-profit serving the Ruby community.
In the coming days, Ruby Together (the corporation) will dissolve. Ruby Together’s board of directors, memberships, and other resources will be joining Ruby Central, where we will continue to support Ruby open source the same way we have been for the last 6 years. We’re very excited to be working together, with less confusion, less business overhead, and more support for the Ruby community.
### September 2021 Monthly Update
URL: https://rubycentral.org/news/september-2021-monthly-update/
Last updated: 2022-11-28T23:39:44.000Z
Hello! Welcome to the monthly update. During September, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), and many others.
## ruby together news
In September, Ruby Together was supported by 36 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org). This month, 3 companies joined as new members.
On top of those companies, 3 new developers signed up as members, including Marco Roth, Kim Laplume, and Max Woolf. In total, we were supported by 110 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems & bundler news
This month in RubyGems, we saw some updates and fixes on the RubyGems and Bundler projects. Some of those changes include the following:
- released a new version for RubyGems [3.2.27](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3227--2021-09-03), which included:
- fixing an issue when installing some gems from GitHub private gem servers
- setting some unredacted credentials in verbose mode
- improving loading the library by using `require_relative` for internal requires.
- released version `3.2.28` for RubyGems, which included:
- fixing a regression introduced by the redaction fix in `3.2.27`, which adds support for the MINGW-UCRT platform
- making sure not to load the URI gem unnecessarily
- relaxing gem spec validations to allow descriptions that include the “TODO” string.
- made progress on a gem rebuild command that will allow exactly reproducing existing package builds (still unreleased).
- released Bundler version [2.2.27](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2227-september-3-2021), which fixed a couple of bundle check regressions, as well as issues with plugins and syntax errors on the generated Github Actions configuration in new gems. It also optimizes some requires and adds support for redacting credentials using the `x-oauth-basic` form.
- released Bundler version [2.2.28](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2228-september-22-2021), which made sure `bundle remove` automatically regenerates the lock file — deprecating the `--install` flag — and also updates the gemspec generated on new gems to use example.com as the sample gem server (instead of the potentially malicious mygemserver.com).
- made progress on the Bundler version locking RFC implementation (still to be released).
In September, Rubygems gained [36 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2021-09-01%7D...master@%7B2021-09-30%7D?ref=rubycentral.org), contributed by 10 authors. There were 154 additions and 21 deletions across 24 files.
## rubygems.org news
In September, RubyGems.org saw several bug fixes and updates, some of which include the following:
- investigated increased traffic and deployed a fix for tarpitting abusive clients.
- [updated Capybara](https://github.com/rubygems/rubygems.org/pull/2769?ref=rubycentral.org), [faraday\_middleware-aws-sigv4](https://github.com/rubygems/rubygems.org/pull/2794?ref=rubycentral.org), and [aws-sdk dependencies](https://github.com/rubygems/rubygems.org/pull/2344?ref=rubycentral.org) in preparation for the Ruby 3 update.
- fixed versions and v1/deps fastly cache not being purged on gem push - [#2793](https://github.com/rubygems/rubygems.org/pull/2793?ref=rubycentral.org).
- updated the ownerships call PR to fix styling and add authorization - [#2748](https://github.com/rubygems/rubygems.org/pull/2748?ref=rubycentral.org).
- thanks to [@matiaskorhonen](https://github.com/matiaskorhonen?ref=rubycentral.org), we are now storing the certificate chain used to sign the published versions - [#2444](https://github.com/rubygems/rubygems.org/pull/2444?ref=rubycentral.org).
This month, Rubygems.org gained [75 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2021-09-01%7D...master@%7B2021-09-30%7D?ref=rubycentral.org), contributed by 7 authors. There were 579 additions and 112 deletions across 53 files.
## ruby toolbox news
Hey everyone,
I hope this update finds you well! In September I added the ability to browse a project’s reverse dependencies - the list of gems that declare that project as a dependency - based on the RubyGems dependency data that I added to the Ruby Toolbox earlier this year.
Taking a look into which other open source projects are using a library can be a helpful indicator when choosing a gem, so I hope you will find this new addition useful!
In October I’d like to tackle a few topics I have had on my unwritten roadmap for quite some time but haven’t gotten around to so far: I’d like to gather and display lines of code statistics for all gems to give an indication of size and complexity: I’d also like to integrate with the Ruby Advisory DB data to display security warnings for libraries on the site.
Until next time!
Best, Chris
## budget & expenses
In September, we saw $10,100.67 in total income, and spent a total of $27,101.07.
- Stripe Payment Processing Fees $308.27
- Employee Related $578.40
- General & Administrative 218.92
- IT & Software $795.88
- 168 Hours of development work at $150/hr $25,199.60
Until next time,
Irene, André, and the Ruby Together team
### Falling Back On Our Strengths
URL: https://rubycentral.org/news/falling-back-on-our-strengths/
Last updated: 2022-11-28T23:39:44.000Z
Here at Ruby Together we feel it’s important to find ways to remind ourselves that time is, in fact, passing and that we are not, actually, living in one, long, eternal year. In that spirit, happy belated equinox and welcome to the other side!
We have officially entered a new phase in the year. Whether you’re entering the fall, as we are here in the US, or welcoming in another season, this turning point can be a good time to reflect on how far we’ve come this year, and how we’d like the remaining part of it to go. It’s a good time to review the goals we set out to meet and check whether they are on track, and if we want to make any adjustments going forward. It’s also a wonderful time to remember the importance of the work we do together and recommit to what we’ve been building.

Since we started almost seven years ago, Ruby Together’s vision has been to serve as a reliable, reinforcing framework in the Ruby ecosystem, not only for the stability of the infrastructure, and vitality of the projects, but also for the wellness of the community. We set out to bring that vision to life with a two-fold mission:
1. Cultivating healthy open source projects
2. Working for and with the Ruby community
## Cultivating healthy open source projects
The first challenge when cultivating healthy open source projects is agreeing about what “healthy” means. At Ruby Together we’ve focused on a few measures of project health where we can have the greatest impact. The first is increasing the number of open-source maintainers, to reduce burnout and the other risks that come with having a solo maintainer on a project. We’ve done this by choosing to bring in more developers with fewer hours per week, rather than aiming for only full-time developers.
The second is welcoming and encouraging new contributors with all levels of experience. We do this by making projects easy for anyone to contribute to, and establishing a collaborative, positive space for projects, with a clear enforcement policy. We also periodically do outreach, inviting developers who are just starting to become more frequent contributors.
One of our members Stephan Kämper shared, “I find a healthy, helpful and friendly community to be really important. Life, especially in these corona times, is hard enough. As a friend (and contributor to an ebook project I’m running) puts it in his contribution title: ‘We all are being hit the hardest’.”
Finally, when choosing new projects we strive for transparency with a publicly shared project proposal, evaluation and [funding process](https://rubytogether.org/projects?ref=rubycentral.org).
## Working for and with the Ruby community
You’ve heard it before on the Ruby official site: “The community that grows up around a programming language is one of its most important strengths.” We agree!
We are grateful to be supported by so many members of the large and longstanding Ruby developer community. We trust our members and invite them to hold us accountable in a number of ways. Our board is elected by our members, and maintains [a public feedback forum](https://github.com/rubytogether/feedback?ref=rubycentral.org). We also set limits on the amount of funding that companies can give. These limits prevent any one company from having too large an influence over the the projects we fund and the work we do.
“I value the idea that healthy open source languages, frameworks, and other foundational tooling isn’t ‘owned’ by any one company,” shares member Jared White. “A plethora of companies and individuals (and even governments!) is necessary to fund, maintain, and sustain open source software for the good of humanity.”
Speaking of the work we do, we report to you exactly what we’ve done with the money you contribute in an [update](https://rubytogether.org/news?ref=rubycentral.org) we publish every month, and [you can subscribe here](https://www.getdrip.com/forms/6239290/submissions/new?ref=rubycentral.org).
Finally, we collaborate with other Ruby community organizations: in the past we have worked with Ruby Central, RailsGirls, Google Summer of Code, and others to support the work they are doing for the Ruby community.
## Moving our mission forward
A lot more is possible! The more we cultivate our community the more we can bring your dream projects to fruition.
Member Jared White envisions “A ‘Ruby component’ specification of some kind for web frameworks. For example: GitHub’s ViewComponent is very cool, but it’s Rails-only. If there were a lower-level spec that VC could build on top of, in theory it would work in Rails or Bridgetown equally.”
We welcome your new ideas, too.
We’re grateful for your support over the years and we’d love to be able to grow and keep supporting the projects that Ruby developers like you use every day. If you or your company would like to help us do so, you can sign up [as a developer](https://rubytogether.org/developers?ref=rubycentral.org) or [as a company](https://rubytogether.org/companies?ref=rubycentral.org).
What are you reflecting on or revisiting this season? What would you like to see come together before the year is out? Feel free to share with us on on social media, and be sure to share this article too!
### August 2021 Monthly Update
URL: https://rubycentral.org/news/august-2021-monthly-update/
Last updated: 2022-11-28T23:39:44.000Z
Hello! Welcome to the monthly update. During August, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), and many others.
## ruby together news
In August, Ruby Together was supported by 38 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org). 2 companies joined as new members.
On top of those companies, 2 new developers signed up as members, including Jay Ang. In total, we were supported by 108 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems & bundler news
This month in RubyGems, we released a new version of RubyGems: [3.2.26](https://github.com/rubygems/rubygems/releases/tag/v3.2.26?ref=rubycentral.org). This release features experimental support for the `RUBYGEMS_GEMDEPS` environment variable, which allows using locked versions of executables without prepending them with `bundle exec`. It also fixes an issue with loading the RubyGems plugin, and improves error reporting inside operating system customizations of RubyGems.
On Bundler, we released Bundler [2.2.26](https://rubygems.org/gems/bundler/versions/2.2.26?ref=rubycentral.org), which includes several small fixes and improvements. Further details can be found in the [changelog](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2226-august-17-2021).
In August, Rubygems gained [133 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2021-08-01%7D...master@%7B2021-08-31%7D?ref=rubycentral.org), contributed by 11 authors. There were 1,299 additions and 896 deletions across 192 files.
## rubygems.org news
In August, RubyGems.org saw several bug fixes and updates, some of which include the following:
- drafted a PR for the Ruby 3 update to evaluate changes required - [#2760](https://github.com/rubygems/rubygems.org/pull/2760?ref=rubycentral.org).
- reduced Docker build time up to 5 minutes by caching the `bundle install` command -[#2761](https://github.com/rubygems/rubygems.org/pull/2761?ref=rubycentral.org).
- updated Rubocop as part of the updates for Ruby 3 - [#2768](https://github.com/rubygems/rubygems.org/pull/2768?ref=rubycentral.org).
- debugged the increased CPU usage on Postgres and added a rate limit on the `reverse_dependencies` page - [#2754](https://github.com/rubygems/rubygems.org/pull/2754?ref=rubycentral.org).
- contacted Zendesk support about spam mails and enabled a beta version of `Rspamd` spam filter system.
- evaluated performance impact on our database in `Gem Signature Verification` PR - [#2444](https://github.com/rubygems/rubygems.org/pull/2444?ref=rubycentral.org).
This month, Rubygems.org gained [34 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2021-08-01%7D...master@%7B2021-08-31%7D?ref=rubycentral.org), contributed by 3 authors. There were 135 additions and 129 deletions across 14 files.
As always, we continue to fix bugs, review and merge PR’s and reply to support tickets.
## budget & expenses
In August, we saw $57,698.27 in total income, and spent a total of $44,248.80.
- Stripe Payment Processing Fees $289.38
- Employee Related $718.66
- General & Administrative $460.93
- IT & Software $629.83
- 281 Hours of development work at $150/hr $42,150
Until next time,
Irene, André and the Ruby Together team
### Ruby In Google Summer of Code 2021
URL: https://rubycentral.org/news/ruby-in-google-summer-of-code-2021/
Last updated: 2022-11-28T23:39:44.000Z
We were delighted to act as fiscal sponsor for the Ruby organization as part of Google’s Summer of Code (GSOC) program. This year, the org was administrated by Ruby core team member Koichi Sasada. Read on to hear from two students who participated in this year.
王新宇 Wang Xinyu, a third year university student in software engineering at Tongji University, Shanghai, contributed to an event-based profiling tool inspired by Google Chromium. The profiler is designed to help analyze Ruby’s boot process and locate the bottleneck. The aim is to deliver faster gem loading for Ruby users, and provide a way to analyze Ruby VM performance intuitively for MRI developers.
The profiling tool won’t be delivered to Ruby app developers, but with a little bit of hacking, they should be able to use it to analyze their own C extensions.
Delton Ding is another GSOC student in the Ruby project this year. His work this summer focused on the fiber scheduler feature released with Ruby 3.0 last Christmas. “People like like Ruby on Rails because its syntax… is very easy to use, but the performance of that is very bad,” Ding shared. The fiber scheduler allows programmers to keep the syntax of \[their\] original Ruby code, but get performance that is “100 or 1000 times faster,” says Ding.
The project is still in its early phases, and Ding spent his summer experimenting with this part of the code.
GSOC allowed both Xinyu and Ding to become more integrated into the Ruby community, and learn how to most effectively move their projects forward.
One of the most exciting parts of the experience for Xinyu was the chance to connect with his mentor, Koichi Sasada. Sasada created the current Ruby VM (YARV). “I’ve learnt a lot Ruby internals and other programming knowledge from him,” says Xinyu. He also learned a bit of Japanese. “This is my first time to really touch Ruby… it’s mostly written by the Japanese team… and the documentation is English \[laughs\]… Sometimes I have to read Japanese… but, I’m Chinese.”
Luckily his mentor is a Japanese programmer and was able to help with the translation. “It’s a little bit challenging to let others know the exact idea we want to express, but so far it’s okay.”
A major part of Ding’s experience was also learning the communication process within the larger Ruby community. In particular he learned the importance of running his ideas by the maintainers of the code that he wants to change, before submitting a change request to Ruby itself.
“Once you submit the whole proposal then people are trying to review it instead of discussing it. In that case then, yeah, there may be a lot of, like, vulnerabilities or something for your project,” Ding explained.
More on Xinyu, Ding and all of the 2021 GSOC students’ final projects can be found [here](https://summerofcode.withgoogle.com/projects/?ref=rubycentral.org#4524421995298816).
GSOC just wrapped its 16th year of student software development mentorships. The program was designed by Google co-founder Larry Page in 2005 to help students retain programming skills during their school breaks, and learn a broader range of practical software development knowledge most easily gained through participating in open source projects. Ruby, Bundler and RubyGems have all participated in the Ruby language project for GSOC many times since the program started, and this is Ruby Together’s 6th year as the fiscal sponsor for the Ruby project in GSOC.
### July 2021 Monthly Update
URL: https://rubycentral.org/news/july-2021-monthly-update/
Last updated: 2022-11-28T23:39:44.000Z
Hello! Welcome to the monthly update. During July, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), and many others.
## ruby together news
In July, Ruby Together was supported by 39 different companies, and 3 companies joined as new members.
On top of those companies, 3 new developers signed up as members: Wayne Vucenic, Joe Winter, and Stephan Kämper. In total, we were supported by 108 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems & bundler news
This month in RubyGems, We released new versions of RubyGems ([3.2.22](https://github.com/rubygems/rubygems/releases/tag/v3.2.22?ref=rubycentral.org), [3.2.23](https://github.com/rubygems/rubygems/releases/tag/v3.2.23?ref=rubycentral.org), [3.2.24](https://github.com/rubygems/rubygems/releases/tag/v3.2.24?ref=rubycentral.org), and [3.2.25](https://github.com/rubygems/rubygems/releases/tag/v3.2.25?ref=rubycentral.org)) and Bundler ([2.2.22](https://github.com/rubygems/rubygems/releases/tag/bundler-v2.2.22?ref=rubycentral.org), [2.2.23](https://github.com/rubygems/rubygems/releases/tag/bundler-v2.2.23?ref=rubycentral.org), [2.2.24](https://github.com/rubygems/rubygems/releases/tag/bundler-v2.2.24?ref=rubycentral.org), and [2.2.25](https://github.com/rubygems/rubygems/releases/tag/bundler-v2.2.25?ref=rubycentral.org)).
We also simplified Bundler internals and achieved faster `bundler/setup` performance. In addition to that, RubyGems saw several bug fixes and updates this month, some of which include the following:
- investigated various RubyGems and Bundler issues on GitHub such as [#4717](https://github.com/rubygems/rubygems/pull/4717?ref=rubycentral.org) and [#4719](https://github.com/rubygems/rubygems/pull/4719?ref=rubycentral.org).
- worked on the Bundler Version Locking RFC - [#29](https://github.com/rubygems/rfcs/pull/29?ref=rubycentral.org).
- improved the `RUBYGEMS_GEMDEPS` environment variable, which allows running bundled commands without needing `bundle exec`.
- worked on automating the process of reproducing builds for gems - [#3118](https://github.com/rubygems/rubygems/issues/3118?ref=rubycentral.org).
- fixed several outdated definition issues (detecting whether there are Gemfile changes over the lockfile or not, to potentially reuse the information in the lockfile and avoid having to resolve dependencies at all).
- fixed the `--conservative` flag to allow finer-grained bundle updates.
- worked on smoothing the transition to secure RubyGems sources fully and fixed the regressions we create as we proceed.
In July, Rubygems gained [169 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2021-07-01%7D...master@%7B2021-07-31%7D?ref=rubycentral.org), contributed by 14 authors. There were 1,878 additions and 1,237 deletions across 152 files.
## rubygems.org news
In July, RubyGems.org saw several bug fixes and updates, some of which include the following:
- updated Kubernetes from version `1.16` to `1.20`.
- debugged and resolved CPU spikes on the database by removing page entries info from the gem index page - [#2738](https://github.com/rubygems/rubygems.org/pull/2738?ref=rubycentral.org).
- enabled `rails 6.1` default `preload_links_header` \- [#3737](https://github.com/rubygems/rubygems.org/pull/2737?ref=rubycentral.org).
This month, Rubygems.org gained [27 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2021-07-01%7D...master@%7B2021-07-31%7D?ref=rubycentral.org), contributed by 3 authors. There were 865 additions and 747 deletions across 13 files.
As always, we continue to fix bugs, review and merge PR’s and reply to support tickets.
## budget & expenses
In July, we saw $8,071.05 in total income, and spent a total of $9,654.81.
- Stripe Payment Processing Fees $298.37
- Employee Related $542.62
- General & Administrative $183.00
- IT & Software $893.32
- 39.6 Hours of development work at $150/hr $5,937.50
Until next time,
Irene, André and the Ruby Together team
### A Vision For Ethics In Open Source Software
URL: https://rubycentral.org/news/a-vision-for-ethics-in-open-source-software/
Last updated: 2022-11-28T23:39:44.000Z
Ruby Together board member Coraline Ada Ehmke has been working for almost a decade on infusing the ideas of justice and equity into the culture and practice of open source. However, like many, her journey in the open source space did not start there.
“I’ve been programming computers since I was a kid,” says Ehmke. “In the early days, you know, source code was in magazines. You’d get your Byte magazine and you’d turn to the back and there was a source code listing and you would type it in, and that’s how you got the program.”
To the creator of the widely-adopted [contributor covenant](https://www.contributor-covenant.org/?ref=rubycentral.org), and founder of the Organization for Ethical Source, open source was simply a formalization of the long tradition of sharing software for free. It was a way to make programming accessible and safer for users. Over time, though, she began to realize “open, as an ethical principle, was not sufficient.”
In 2018 large tech companies, including Palantir and Amazon, came [under fire](https://www.washingtonpost.com/politics/2020/09/29/technology-202-activists-slam-palantir-its-work-with-ice-ahead-market-debut/?ref=rubycentral.org) for providing data and surveillance infrastructure to governmental organizations in the US, including local police departments and Immigration and Customs Enforcement (ICE). That year the Latinx and Chicanx activist group Mijente launched the #NoTechForICE campaign, including protests and organizing against the use of technology to facilitate human rights violations, including the [violent treatment](https://www.cbsnews.com/news/dhs-inspector-general-report-reveals-squalid-conditions-at-migrant-detention-centers/?ref=rubycentral.org) of undocumented immigrant families, and [systemic racial profiling](https://www.dailydot.com/debug/amazon-hq-rekognition-ice-protest/?ref=rubycentral.org).
The powerful leverage companies like this have in the open source landscape was brought into sharp focus for many developers when Seth Vargo, a well known open source contributor and former employee of the Chef app, tried to participate in the protest. When he found out the company had a contract with ICE he removed his code from the platform in an act of solidarity, only to find within hours it had been restored. Even though he was the creator of the code and did not condone its use, he was left with no recourse.
The incident inspired Ehmke to create [the Hippocratic License](https://firstdonoharm.dev/?ref=rubycentral.org), an Ethical Source license prohibiting the use of software that is in violation of human rights. These efforts grew into the Ethical Source movement and what is now [the Organization for Ethical Source](https://ethicalsource.dev/?ref=rubycentral.org).

A common misconception about Ethical Source is that it is solely about licensing, due to its origins in the Hippocratic License. Ehmke notes that this is not true. Instead, the Ethical Source movement seeks to create a culture around seven organizing principles, including “our work is done in the open,” “our community strives to be welcoming and just” and “our work deserves support.”
Many of these values are shared with the founding principles at Ruby Together, where Ehmke became an early member of the board. “The Ruby community led the way in normalizing codes of conduct for open source projects and open source communities,” she says, “So I would love to see the Ruby community continue to demonstrate that leadership.” The Contributor Covenant, which Ehmke wrote in 2014 as a standard for Ruby Together supported projects, became one of the most popular codes of conduct in the open source community. It has been adopted by over a hundred thousand open source communities and projects including Google, Microsoft, Linux and Salesforce.
Endorsement by tech industry giants did not prevent the code of conduct from loud criticism from those who do not align with its ideals. Both the Contributor Covenant and the Ethical Source movement received similar backlash, albeit from different facets of the open source community. When it came to the code of conduct, the major pushback was from individual developers. The Ethical Source movement has received backlash at the institutional level as well, with organizations like the Open Source Initiative declaring that the movement does not align with the practice of open source. Even supporters of the effort [appear hesitant](https://eandt.theiet.org/content/articles/2021/04/open-source-software-freedom-from-ethics/?ref=rubycentral.org) to adopt the principles, for fear of legal repercussions and enforcement.
Ehmke acknowledges that widespread adoption of Ethical Source will not happen as easily or in the same way as the adoption of open source itself, due to the fact that they were created with different goals in mind. According to Ehmke, open source served to make source available software palatable to corporations. On the other hand, Ethical Source tries to level the playing field between the creator community and the companies that adopt their work. “It has to be a symbiotic relationship in order to be fair,” says Ehmke. As such, she believes these practices will become more widely disseminated as individual developers and communities adopt them, incentivizing corporations to do so as well.
The Organization for Ethical Source has been developing tools and resources that will be immediately applicable in open source communities, so that Ethical Source principals can be put into practice, tested and more easily understood. “We are drawing on the collective wisdom and expertise of people from different parts of the world with different specializations,” Ehmke asserts. These include a former Mozilla fellow whose project focused on how indigenous wisdom can inform open source communities, an anthropologist who has conducted ethnographic studies on software development communities, and a member of the Center for Democracy and Technology who works on governance in digital communities.
Ultimately, Ehmke says the Ethical Source movement is about “incorporating broadly shared values into the work we do, with the aim of producing better outcomes for the world at large.” Whether or not they succeed, she hopes to set an example for other organizations to follow. “And I hope someone else does,” she says, “because we just cannot go on pretending that tech is neutral.”
### June 2021 Monthly Update
URL: https://rubycentral.org/news/june-2021-monthly-update/
Last updated: 2022-11-28T23:39:44.000Z
Hello! Welcome to the monthly update. During June, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), and many others.
## ruby together news
In June, Ruby Together was supported by 40 different companies and 108 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems & bundler news
This month in RubyGems, we released new versions for **Bundler `2.2.20` and `2.2.21`** and **RubyGems `3.2.20` and `3.2.21`**.
RubyGems shipped a security fix for possible malicious code execution from [@sonalkr123](https://github.com/sonalkr132?ref=rubycentral.org).
In Bundler, we worked on improving the seamless migration of insecure lock files by automatically dealing with them when possible instead of printing a warning and still installing them - [#4647](https://github.com/rubygems/rubygems/pull/4647?ref=rubycentral.org) and [#4683](https://github.com/rubygems/rubygems/pull/4683?ref=rubycentral.org).
We also kept discussing how to improve the experience when bundler needs `sudo` access, making the behaviour less surprising or unexpected for our users -[#4031](https://github.com/rubygems/rubygems/issues/4031?ref=rubycentral.org).
In June, Rubygems gained [98 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2021-06-01%7D...master@%7B2021-06-30%7D?ref=rubycentral.org), contributed by 10 authors. There were 993 additions and 480 deletions across 231 files.
## rubygems.org news
In June, RubyGems.org saw several bug fixes and updates, some of which include the following:
- updated ElasticSearch to version 7.
- refactored and deployed autocomplete search feature - [#2047](https://github.com/rubygems/rubygems.org/pull/2047?ref=rubycentral.org).
- resolved reports with pending bounties on HackerOne.
This month, Rubygems.org gained [25 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2021-06-01%7D...master@%7B2021-06-30%7D?ref=rubycentral.org), contributed by 7 authors. There were 490 additions and 169 deletions across 30 files.
As always, we continue to fix bugs, review and merge PR’s and reply to support tickets.
## ruby api news
We worked on RubyAPI’s frontend project to reduce clutter and take advantage of existing open-source libraries. The goal is to utilize existing libraries such as Headless UI, ReactJS & Autocomplete.js, which provide a much richer UI/UX for users and lowers maintenance costs.
## budget & expenses
In June, we saw $18,659.30 in total income, and spent a total of $20,733.67.
- Stripe Payment Processing Fees $339.39
- Employee Related $917.75
- General & Administrative $274.63
- IT & Software $2,339.40
- 107.3 Hours of development work at $150/hr $16,087.50
Until next time,
Irene, André and the Ruby Together team
### A New Approach to Documentation: Ruby API
URL: https://rubycentral.org/news/a-new-approach-to-documentation--ruby-api-/
Last updated: 2022-11-28T23:39:44.000Z
*The [Ruby API](https://rubyapi.org/?ref=rubycentral.org) documentation site is an [open source project](https://github.com/rubyapi/rubyapi?ref=rubycentral.org), initially started by [Colby Swandale](https://twitter.com/oceanicpanda?ref=rubycentral.org), and supported by Ruby Together.*
Ruby API received an exciting update recently: the core Ruby type signatures are being imported into the app. Eventually the type signatures will be able to be parsed directly in Ruby API.
“It’s all about being able to offer a richer developer experience to people by seeing the exact details of each method,” says creator of the app Colby Swandale.
The current Ruby documentation is written in code comments, and as a result is not always consistent with the code itself.
This latest update eliminates that. Instead of method examples being written by humans, they will be written by a computer.

*preview of Ruby 3 type signatures*
Colby is excited about the ability of Ruby API to provide much more context about the return values of methods. For the user this means a better understanding of, for example, which arguments are optional and which are required, and which keys are needed in hash arguments.
“By being able to infer the type signatures you can infer directly from the code. So you can ensure that the accuracy is a lot better.”
With such a vast improvement to the documentation searchability on the horizon, it’s hard to believe that just a two years ago Ruby API almost ceased to exist.
### The Ruby API Story
Colby was inspired to create the Ruby API app in 2018\. He says it “was a passion project of mine but it was born out of frustration.”
At the time there was no one reliable place Ruby developers could easily search for items in the documentation they were looking for. A combination of the large number of sites using generated docs and Google’s difficulty understanding Ruby documentation, led to confusing and inconsistent search results. Often a search of the documentation would return several outdated or irrelevant versions of Ruby.
On the sites that were available (https://www.ruby-lang.org, Rubydoc.org and API doc) the UI on mobile and tablets left a lot to be desired. Over two years, and four iterations Colby set out to create a solution — having varying success with either the search feature or the UI but struggling to have both operate well at once.
Then, he had a eureka moment in a conversation with a friend who happened to be taking a course on Elastic Search. He did some research into the search engine to find out more. It turned out Elastic Search had the exact features he was looking for to improve the search, and provide the results he was looking for.
“You could do things like give priorities to arbitrary values, so if you search for a method that’s in, like, a string, the core Ruby class would get the highest search results.”
With a search feature that finally seemed ready, and a new found rush of motivation Colby got momentum to design a UI that was fully responsive on desktop, mobile and tablets. In early 2019 he shipped the first version of the app on Heroku. As a soft launch, he shared the link out with a few members of the Ruby community to test and received positive feedback. Then he posted the link publicly on twitter.
The result was basically, crickets. There wasn’t much site traffic. “I think it was like, maybe less than five people a day were using it,” he says.
Admittedly, Colby says he didn’t make a huge promotional push. He didn’t post about the app on Reddit, Hacker News or any other large platform where developer content often goes viral. Instead it was spread by word of mouth.
After a few months of low usage, Colby’s motivation to maintain the project was dwindling. He decided to shut the Ruby API site down, leaving the project open only on GitHub for users to run on their own. He made an announcement about it on twitter. It was then he realized just how useful the site was to Ruby users.
An outpouring of support came in from people who had been using the app. Users reached out to ask him not to take it down.
Friends in the Ruby community shared their enthusiasm for Ruby API on twitter, Hacker News, and the Ruby subreddit. It was even added to the list of resources on the official Ruby documentation website.
“People were very vocal, and that was a huge motivation,” says Colby.
Ruby API received a huge surge of traffic that day. Importantly it confirmed Colby’s initial hunch that the Ruby community needed a new and improved approach to documentation.
“They gave me validation that I was actually on the right path — that there actually is a problem, people know there is a problem and we’re all seeking for something better.”
### The Future of Ruby API (And How You Can Help!)
Aside from type signatures, there are a few other features Colby would like to add to the app down the line.
“I eventually want to bring all gem documentation into Ruby API,” he says.
The most important part of the Ruby API story to him is how crucial it is to hear from users.
From the chance conversation with a developer friend that spurred the app, to the community of beta testers, to the Ruby users whose feedback have resulted in some of the features the app has now (like being able to run code examples) — the app is what it is because of community support.
“This is a project that anyone can help make better. This is a project for the Ruby community and I would love to have their input to help make Ruby API better.”
### May 2021 Monthly Update
URL: https://rubycentral.org/news/may-2021-monthly-update/
Last updated: 2022-11-28T23:39:44.000Z
Hello! Welcome to the monthly update. During May, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), and many others.
## ruby together news
In May, Ruby Together was supported by 39 different companies, and 5 companies joined as new members. On top of those companies, 5 new developers signed up as members. In total, we were supported by 114 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems & bundler news
This month in RubyGems, we released new versions for Bundler [2.2.18, 2.2.19](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2218-may-25-2021) and RubyGems [3.2.18, 3.2.19](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3218--2021-05-25) and focused on shipping a definitive fix for the dependency confusion issues that have been affecting Bundler for years. We finally managed to provide a fix ([#4609](https://github.com/rubygems/rubygems/pull/4609?ref=rubycentral.org)) with `bundler 2.2.18`.
In addition to that, RubyGems saw several bug fixes and updates this month, some of which include the following:
- fixed a resolution issue where gems were being unintentionally removed from the lockfile - [#4580](https://github.com/rubygems/rubygems/pull/4580?ref=rubycentral.org).
- shipped a fix in RubyGems to improve the reproducibility of building packages - [#4610](https://github.com/rubygems/rubygems/pull/4610?ref=rubycentral.org).
- shipped other minor improvements, and some internal changes to our development environment like moving away from `minitest` in favor of `test-unit`.
Checkout [RubyGems](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#3218--2021-05-25) and [Bundler](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#2218-may-25-2021) for the full changelog of the new versions shipped this month!
In May, Rubygems gained [132 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2021-05-01%7D...master@%7B2021-05-31%7D?ref=rubycentral.org), contributed by 10 authors. There were 2419 additions and 2118 deletions across 228 files.
## rubygems.org news
In May, RubyGems.org saw several bug fixes and updates, some of which include the following:
- investigated and fixed cache poisoning by using `x-forwarded-scheme` header. The issue was reported on HackerOne.
- set form-action and frame-ancestor CSP policy to mitigate bypass of X-Frame-Options using a proxy - [#2718](https://github.com/rubygems/rubygems.org/pull/2718?ref=rubycentral.org).
- researched verified publisher implementation for package manager - [#2698](https://github.com/rubygems/rubygems.org/pull/2698?ref=rubycentral.org#issuecomment-846356370).
- added copy link to recovery code page and disabled continue link - [#2717](https://github.com/rubygems/rubygems.org/pull/2717?ref=rubycentral.org).
- tested upgrade of Elasticsearch 7 on staging environment and estimated downtime requirements.
For this month, Rubygems.org gained [23 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2021-05-01%7D...master@%7B2021-05-31%7D?ref=rubycentral.org), contributed by 3 authors. There were 155 additions and 100 deletions across 11 files.
As always, we continue to fix bugs, review and merge PR’s and reply to support tickets.
## ruby toolbox news
Hey everyone!
As mentioned in the last update I’ve been working on bringing gem dependencies to the Ruby Toolbox project pages, and I’m happy to say that via this pull request they have now been launched. You can find them on each project page, for example take a look at the http gem over here.
A specialty of this feature is that right next to the dependency you can also find the corresponding project health indicators so if you’re looking at a library you can also see an indication of the status of it’s dependencies as well.
Now that this is out of the door, in June I want to spend a bit of time on maintenance of the data syncing mechanisms as they haven’t received much attention apart from being built at some point and are causing some noise for example when API rate limits are hit.
Stay safe and healthy and until next time!
Best, Chris
## budget & expenses
In May, we saw $8,649.97 in total income, and spent a total of $10,003.58.
- Stripe Payment Processing Fees $318.69
- Employee Related $609.34
- General & Administrative $189.84
- IT & Software $1,210.71
- 51.2 Hours of development work at $150/hr $7,675
Until next time,
Irene, André and the Ruby Together team
### April 2021 Monthly Update
URL: https://rubycentral.org/news/april-2021-monthly-update/
Last updated: 2022-11-28T23:39:44.000Z
Hello! Welcome to the monthly update. During April, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), and many others.
## ruby together news
In April, Ruby Together was supported by 40 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org). 3 companies joined as new members.
On top of those companies, 3 new developers signed up as members, including Chris Houhoulis, Josh Mills, and Emmanuel Hayford. In total, we were supported by 113 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems & bundler news
This month in RubyGems, we released new versions for **RubyGems** [v3.2.16](https://github.com/rubygems/rubygems/blob/bb93b974100e9ddff7043e648d762e8a412be04e/CHANGELOG.md?ref=rubycentral.org#3216--2021-04-08), [v3.2.17](https://github.com/rubygems/rubygems/blob/bb93b974100e9ddff7043e648d762e8a412be04e/CHANGELOG.md?ref=rubycentral.org#3217--2021-05-05) and corresponding versions for **Bundler** ([v2.2.16](https://github.com/rubygems/rubygems/blob/bb93b974100e9ddff7043e648d762e8a412be04e/bundler/CHANGELOG.md?ref=rubycentral.org#2216-april-8-2021) and [v2.2.17](https://github.com/rubygems/rubygems/blob/bb93b974100e9ddff7043e648d762e8a412be04e/bundler/CHANGELOG.md?ref=rubycentral.org#2217-may-5-2021)).
As part of those releases, we made the following improvements and fixes:
- fixed an issue preventing users from upgrading their sidekiq-pro version from the `sidekiq-pro` custom gem server - [#4563](https://github.com/rubygems/rubygems/pull/4563?ref=rubycentral.org).
- made Bundler more secure by preventing any credentials from being logged to the screen, thus potentially preventing users from unintentionally leaking them when pasting them to a Github issue or similar situations - [#4564](https://github.com/rubygems/rubygems/pull/4564?ref=rubycentral.org), [#4566](https://github.com/rubygems/rubygems/pull/4566?ref=rubycentral.org).
- fixed a few resolution and materialization issues in Bundler - [#4556](https://github.com/rubygems/rubygems/pull/4556?ref=rubycentral.org), [#4562](https://github.com/rubygems/rubygems/pull/4562?ref=rubycentral.org), and also improved RubyGems handling of repositories including symlinks - [#2836](https://github.com/rubygems/rubygems/pull/2836?ref=rubycentral.org).
In April, RubyGems gained [101 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2021-04-01%7D...master@%7B2021-04-30%7D?ref=rubycentral.org), contributed by 15 authors. There were 1,591 additions and 391 deletions across 134 files.
## rubygems.org news
In April, RubyGems.org saw several bug fixes and updates, some of which include the following:
- enabled support of non-SNI traffic on rubygems.org by migration of fastly endpoints to a dedicated IP - [#4228](https://github.com/rubygems/rubygems/issues/4228?ref=rubycentral.org).
- [enabled auth. requirement for URL purge requests to Fastly](https://github.com/rubygems/rubygems.org/commit/da99700a6c727a4381648e4b687d4d3f08f67a25?ref=rubycentral.org).
- fixed failing background jobs for sending the email confirmation - [#2694](https://github.com/rubygems/rubygems.org/pull/2694?ref=rubycentral.org), [#2695](https://github.com/rubygems/rubygems.org/pull/2695?ref=rubycentral.org).
- added validation for `unconfirmed_email` regex - [#2694](https://github.com/rubygems/rubygems.org/pull/2694?ref=rubycentral.org).
- fixed `RecordNotFound` in `OwnershipConfirmation` mailer - [#2695](https://github.com/rubygems/rubygems.org/pull/2695?ref=rubycentral.org).
- reduced abusers rate limit to 30 rps - [#2703](https://github.com/rubygems/rubygems.org/pull/2703?ref=rubycentral.org).
- enabled Multi-Factor Authentication (MFA) instruction only if `current_user` has MFA disabled - [#2705](https://github.com/rubygems/rubygems.org/pull/2705?ref=rubycentral.org).
- thanks to [@arthurnn](https://github.com/arthurnn?ref=rubycentral.org) and [@greysteil](https://github.com/greysteil?ref=rubycentral.org), we now support automatic revocation of API keys committed to GitHub repositories - [#2687](https://github.com/rubygems/rubygems.org/pull/2687?ref=rubycentral.org). Note that this is only supported for new API key format. Please check our [guide for migration from legacy API key](https://guides.rubygems.org/api-key-scopes/?ref=rubycentral.org#migration-from-legacy-api-key).
For this month, [RubyGems.org](https://github.com/rubygems/rubygems.org?ref=rubycentral.org) gained [45 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2021-04-01%7D...master@%7B2021-04-30%7D?ref=rubycentral.org), contributed by 9 authors. There were 424 additions and 52 deletions across 34 files.
## ruby toolbox news
Hey everyone,
I hope this update finds you well! Last month I have been busy with all kinds of general maintenance work, like fixing random failures in the Ruby Toolbox visual regression CI tests, a whole set of dependency upgrades, renaming default git branches to main across rubytoolbox repos and fixes on webhook reception.
As mentioned in my last update I’m currently also working on bringing gem dependencies display to the Ruby Toolbox. The data is in place and I have been working on showing it on the site. In that regard I have settled on the UI layout for this feature but still have to spend a bit more work on this to make it ready for production, but I hope to get this ready in May.
Stay safe and healthy and until next time!
Best, Chris
## ruby API news
This month for Ruby API I have been working on importing the core Ruby type signatures using the RBS gem where the current definitions are being maintained. Our aim is for the type signatures be parsed inside Ruby API so they can be presented to the user in an easy to understand and digestible fashion.
We’ve also been working hard on merging PRs from our contributors and keeping our dependencies up to date.
– Colby
## budget & expenses
In April, we saw $7,960.27 in total income, and spent a total of $22,603.95.
- Stripe Payment Processing Fees $289.24
- Employee Related $1,618.35
- General & Administrative $6,983.42
- IT & Software $1,037.94
- 84.5 Hours of development work at $150/hr $12,675
Until next time,
Irene, André and the Ruby Together team
### March 2021 Monthly Update
URL: https://rubycentral.org/news/march-2021-monthly-update/
Last updated: 2022-11-28T23:39:44.000Z
Hello! Welcome to the monthly update. During March, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), and many others.
## ruby together news
In March, Ruby Together was supported by 40 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org). We were also supported by 111 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems & bundler news
In March, we released 4 new versions of RubyGems [(from 3.2.12 to 3.2.15)](https://rubygems.org/gems/rubygems-update/versions?ref=rubycentral.org) and Bundler [(from 2.2.12 to 2.2.15)](https://rubygems.org/gems/bundler/versions?ref=rubycentral.org). Additionally, we worked on making the client tools more secure, and making Git sources faster and more disk efficient.
For this month, [RubyGems](https://github.com/rubygems/rubygems?ref=rubycentral.org) gained [150 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2021-03-01%7D...master@%7B2021-03-31%7D?ref=rubycentral.org), contributed by 10 authors. There were 2124 additions and 753 deletions across 107 files.
## rubygems.org news
This month in RubyGems.org, we [enabled Rails 6.0 defaults](https://github.com/rubygems/rubygems.org/pull/2674?ref=rubycentral.org) and [deployed an update to Rails 6.1.3](https://github.com/rubygems/rubygems.org/pull/2675?ref=rubycentral.org).
In addition, RubyGems.org saw various bug fixes and other work this month, including:
- fixed upload of test coverage report to code climate. - [#2673](https://github.com/rubygems/rubygems.org/pull/2673?ref=rubycentral.org)
- made users’ emails private by default and updated existing accounts to hide emails. - [#2663](https://github.com/rubygems/rubygems.org/pull/2663?ref=rubycentral.org)
- added text-only versions of emails to support more email clients. - [#2652](https://github.com/rubygems/rubygems.org/pull/2652?ref=rubycentral.org)
- upgraded ES instance type and storage, and added a strict rate limit on the Search API endpoint. - [#2665](https://github.com/rubygems/rubygems.org/pull/2665?ref=rubycentral.org)
- updated nginx to latest mainline to fix `cache file .. has too long header` issue that landed in `v1.19.3`. - [#2660](https://github.com/rubygems/rubygems.org/pull/2660?ref=rubycentral.org)
- replied to support tickets on Zendesk and Tenderapp
For this month, [RubyGems.org](https://github.com/rubygems/rubygems.org?ref=rubycentral.org) gained [60 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2021-03-01%7D...master@%7B2021-03-31%7D?ref=rubycentral.org), contributed by 8 authors. There were 546 additions and 515 deletions across 48 files.
## budget & expenses
In March, we saw $8,842.52 in total income, and spent a total of $27,189.93.
- Stripe Payment Processing Fees $325.31
- Employee Related $1,950.50
- General & Administrative $821.12
- IT & Software $1,355.50
- 151.6 Hours of development work at $22,737.50
Until next time,
Irene, André and the Ruby Together team
### February 2021 Monthly Update
URL: https://rubycentral.org/news/february-2021-monthly-update/
Last updated: 2022-11-28T23:39:44.000Z
Hello! Welcome to the monthly update. During February, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), and many others.
## ruby together news
In February, Ruby Together was supported by 40 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org) and Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). 8 companies joined as new members.
On top of those companies, 8 new developers signed up as members, including Abdullah Esmail, Grant Hutchins, Dwight VanTuyl, and Niklaus Giger. In total, we were supported by 113 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems & bundler news
This month on RubyGems, we worked on fixing an issue about source priority that received attention due to a [popular blog post](https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610?ref=rubycentral.org). In particular, the lockfile now has separated RubyGems sources, limiting the issue to fresh installs without a lockfile and allowing for a workaround in the other cases (running `bundle lock` and reviewing the result before installing).
In February, [RubyGems](https://github.com/rubygems/rubygems?ref=rubycentral.org) gained [114 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2021-02-01%7D...master@%7B2021-02-28%7D?ref=rubycentral.org), contributed by 12 authors. There were 743 additions and 204 deletions across 56 files.
## rubygems.org news
This month on RubyGems.org, we reduced the nginx rate limit to mitigate the load on Postgres ([#2634](https://github.com/rubygems/rubygems.org/pull/2634?ref=rubycentral.org)) and evaluated the impact of reducing `random_page_post` in Postgres config.
In addition to that, we made the following improvements and fixes:
- updated Elasticsearch to **v6.8**.
- setup notifications for AWS health events.
- updated script to block a user from resetting API keys. - [#2647](https://github.com/rubygems/rubygems.org/pull/2647?ref=rubycentral.org)
- reduced font size of title and subtitle on reverse dep page. - [#2637](https://github.com/rubygems/rubygems.org/pull/2637?ref=rubycentral.org)
- enabled safe-site lax cookie policy. - [#2638](https://github.com/rubygems/rubygems.org/pull/2638?ref=rubycentral.org)
- enabled `return_only_media_type_on_content_type` rails 6.0 default. - [#2639](https://github.com/rubygems/rubygems.org/pull/2639?ref=rubycentral.org)
- thanks to [simi](https://github.com/simi?ref=rubycentral.org), we significantly improved the delay in our build time by migrating from Travis to Github Actions. - [#2626](https://github.com/rubygems/rubygems.org/pull/2626?ref=rubycentral.org).
In February, [RubyGems](https://github.com/rubygems/rubygems?ref=rubycentral.org) gained [52 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2021-02-01%7D...master@%7B2021-02-28%7D?ref=rubycentral.org), contributed by 3 authors. There were 249 additions and 168 deletions across 23 files.
As always, we continue to fix bugs, review and merge PR’s and reply to support tickets.
## ruby toolbox news
Hey everyone,
I hope this update finds you well!
I have recently worked on improving the search response times on the Ruby Toolbox as they had become pretty unbearable in recent months. After some initial prototyping had shown promising results I decided to swap the search index to utilize MeiliSearch instead of Postgres’ built-in full text search. Benchmarks between both on the live site showed that this changed response times from \~13 seconds back to a more reasonable \~1 second. You can also find a [corresponding blog post on the Ruby Toolbox.](https://www.ruby-toolbox.com/blog/2021-03-19/search-speed-improvements?ref=rubycentral.org)
I have also upgraded the site to [run on Ruby 3](https://github.com/rubytoolbox/rubytoolbox/pull/801?ref=rubycentral.org) and the [latest version of Rails](https://github.com/rubytoolbox/rubytoolbox/pull/800?ref=rubycentral.org) early this year.
Next up I want to bring display of a gem’s dependencies (and reverse dependencies later on) to the site and have some follow-up work in removing code regarding the old search indexing.
Stay safe and healthy and until next time!
Best, Chris
## budget & expenses
In February, we saw $37,721.27 in total income, and spent a total of $10,573.93.
- Stripe Payment Processing Fees $259.21
- Employee Related $577.63
- General & Administrative $152.11
- IT & Software $697.48
- Professional Fees $0
- 56.3 Hours of development work at $8,437.5
Until next time,
Irene, André and the Ruby Together team
### January 2021 Monthly Update
URL: https://rubycentral.org/news/january-2021-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello! Welcome to the monthly update. During January, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), and many others.
## ruby together news
In January, Ruby Together was supported by 40 different companies, including Ruby member [Zendesk](https://www.zendesk.com/?ref=rubycentral.org) and Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). 6 companies joined as new members.
On top of those companies, 6 new developers signed up as members, including Abdullah Esmail, Marco Roth, Shaun McCormick, and Chance Feick. In total, we were supported by 106 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems & bundler news
In January, we released new versions of Bundler `v2.2.5`, `v2.2.6`, `v2.2.7`, and `v2.2.8`, and corresponding versions of RubyGems `v3.2.5`, `v3.2.6`, `v3.2.7`, and `v3.2.8`. The main improvements in these releases are **resolver correctness** and **better performance**. Learn more about specific changes made from the changelogs: [Bundler Changelog](https://github.com/rubygems/rubygems/blob/master/bundler/CHANGELOG.md?ref=rubycentral.org#228-february-2-2021) and [RubyGems Changelog](https://github.com/rubygems/rubygems/blob/master/CHANGELOG.md?ref=rubycentral.org#328--2021-02-02). We’re refining our RFC for Bundler Version Locking -[#29](https://github.com/rubygems/rfcs/pull/29?ref=rubycentral.org) and plan to move on to the implementation soon.
As usual, we’re routinely triaging new issues and reviewing pull requests from contributors.
This month, [RubyGems](https://github.com/rubygems/rubygems?ref=rubycentral.org) gained [172 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2021-01-02%7D...master@%7B2021-01-31%7D?ref=rubycentral.org), contributed by 12 authors. There were 53,323 additions and 1,646 deletions across 2,565 files.
## rubygems.org news
This month on RubyGems.org, we reduced delay in update of versions endpoint after `gem push` from the worst-case of **3,660 seconds** to **60 seconds** \- [#2612](https://github.com/rubygems/rubygems.org/pull/2612?ref=rubycentral.org), [#2614](https://github.com/rubygems/rubygems.org/pull/2614?ref=rubycentral.org), [#2616](https://github.com/rubygems/rubygems.org/pull/2616?ref=rubycentral.org).
In addition to that, we made the following improvements and fixes:
- debugged delay in versions endpoint update on `gem push` and set surrogate key on versions to reduce Fastly cache expiry. - [#2612](https://github.com/rubygems/rubygems.org/pull/2612?ref=rubycentral.org), [#2614](https://github.com/rubygems/rubygems.org/pull/2614?ref=rubycentral.org)
- worked on pre-update changes for **Rails 6.1** and updated and deployed **Rails 6.1** update. - [#2607](https://github.com/rubygems/rubygems.org/pull/2607?ref=rubycentral.org), [#2597](https://github.com/rubygems/rubygems.org/pull/2597?ref=rubycentral.org), [#2598](https://github.com/rubygems/rubygems.org/pull/2598?ref=rubycentral.org)
- created Fastly support tickets for dedicated IPs and incorrect status code on matching If-None-Match.
- worked on updating `RubyGems-terraform` root files to sync with current state.
- thanks to [@iMacTia](https://github.com/iMacTia?ref=rubycentral.org), we added a new MFA level UI and `gem signin` \- [#2601](https://github.com/rubygems/rubygems.org?ref=rubycentral.org#2601) \- find out more about this on [RubyGems Guides](https://guides.rubygems.org/setting-up-multifactor-authentication/?ref=rubycentral.org#authentication-levels).
As always, we continue to fix bugs, review and merge PR’s and reply to support tickets.
In January, Rubygems.org gained [89 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2021-01-01%7D...master@%7B2021-01-31%7D?ref=rubycentral.org), contributed by 8 authors. There were 651 additions and 377 deletions across 70 files.
## budget & expenses
In January, we saw $8,744.92 in total income, and spent a total of $5,809.74.
- Stripe Payment Processing Fees $306.84
- Employee Related $568.48
- General & Administrative $96.14
- IT & Software $888.28
- Professional Fees $0
- 26.3 Hours of development work at $3,950.00
Until next time,
Irene, André and the Ruby Together team
### December 2020 Monthly Update
URL: https://rubycentral.org/news/december-2020-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello! Welcome to the monthly update. During December, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Bleacher Report](http://www.bleacherreport.com/?ref=rubycentral.org), and many others.
## ruby together news
In December, Ruby Together was supported by 41 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org) and Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). 2 companies joined as new members.
On top of those companies, 2 new developers signed up as members, including Sinan Taifour and Nick Willever. In total, we were supported by 105 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems & bundler news
In December, we finally released Bundler 2.2 and RubyGems 3.2\. 🎉 On the Bundler side, this minor release provides some major enhancements in how Bundler treats platforms, and also a few extra features. Check out [the Bundler 2.2 release blog post](https://bundler.io/blog/2020/12/09/bundler-v2-2.html?ref=rubycentral.org) for details. On the RubyGems side, the release provides several bug fixes, a noticeable boot time speed-up, better integration in ruby-core and alternative implementations, and adds support for a change in the server side that allows using scoped API keys.
After the releases, we also received the corresponding feedback and regression reports, and addressed almost everything reported through 4 patch level releases of each library. In particular, we made it on time for Ruby’s Christmas release and managed to include RubyGems 3.2.3 and Bundler 2.2.3 with the final release of Ruby 3.0.
This month, [RubyGems](https://github.com/rubygems/rubygems?ref=rubycentral.org) gained [203 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2020-12-01%7D...master@%7B2020-12-21%7D?ref=rubycentral.org), contributed by 13 authors. There were 4191 additions and 2066 deletions across 1184 files.
## rubygems.org news
This month, we published a guide on RubyGems.org about [API keys, their scopes, and CLI usage](https://guides.rubygems.org/api-key-scopes/?ref=rubycentral.org) ([#275](https://github.com/rubygems/guides/pull/275?ref=rubycentral.org)). We also investigated and removed `ruby-bitcoin` and `pretty_color` gems for containing malicious code which could steal sensitive information; this issue was reported by [@mensfeld](https://github.com/mensfeld?ref=rubycentral.org) for obfuscated code. We have updated the corresponding wiki page of [gems yanked and accounts locked](https://github.com/rubygems/rubygems.org/wiki/Gems-yanked-and-accounts-locked?ref=rubycentral.org#14-dec-2020).
In addition to that, we made the following improvements and fixes:
- deployed a PR to update `versions_downloads` in elastic search and reindex to fix the mismatch in downloads count. [#2534](https://github.com/rubygems/rubygems.org/pull/2534?ref=rubycentral.org)
- deployed an API key with scopes and migrated legacy per account keys to the new API keys with encrypted storage. [#1962](https://github.com/rubygems/rubygems.org/pull/1962?ref=rubycentral.org)
- setup insecure.rubygems.org to not redirect dependency endpoints to HTTPS. [#2590](https://github.com/rubygems/rubygems.org/pull/2590?ref=rubycentral.org)
- worked on a PR to block throw-away domains from signup. [#2579](https://github.com/rubygems/rubygems.org/pull/2579?ref=rubycentral.org)
- merged a PR to update a failing test on ruby 2.7\. [#2580](https://github.com/rubygems/rubygems.org/pull/2580?ref=rubycentral.org)
- worked on a PR to update to Rails 6.1\. [#2584](https://github.com/rubygems/rubygems.org/pull/2584?ref=rubycentral.org)
- worked on a PR to update gem dependencies to support elastic search 6\. [#2585](https://github.com/rubygems/rubygems.org/pull/2585?ref=rubycentral.org)
- updated a PR to update clearance. [#2446](https://github.com/rubygems/rubygems.org/pull/2446?ref=rubycentral.org)
- enabled a few more Rails 6 defaults. [#2583](https://github.com/rubygems/rubygems.org/pull/2583?ref=rubycentral.org)
- updated the rubygems.org TLS certificate to support TLS 1.3.
- deployed a PR and backfilled `canonical_versions` to disallow publishing of duplicate canonical version numbers. It resolves the issue of clients installing potentially malicious versions of existing releases. [#2559](https://github.com/rubygems/rubygems.org/pull/2559?ref=rubycentral.org)
- updated `version_downloads` to use the most\_recent version implementation. [#2534](https://github.com/rubygems/rubygems.org/pull/2534?ref=rubycentral.org)
- fixed a script to block users with handles that had uppercase letters. [#2570](https://github.com/rubygems/rubygems.org/pull/2570?ref=rubycentral.org)
- merged a PR to enable Rails 6 default for `return_false_on_aborted_enqueue`. [#2571](https://github.com/rubygems/rubygems.org/pull/2571?ref=rubycentral.org)
As always, we continue to fix bugs, review and merge PR’s and reply to support tickets.
In total, [RubyGems.org](https://github.com/rubygems/rubygems.org?ref=rubycentral.org) gained [77 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2020-12-01%7D...master@%7B2020-12-31%7D?ref=rubycentral.org), contributed by 10 authors. There were 2154 additions and 596 deletions across 96 files.
## budget & expenses
In December, we saw $10,000.31 in total income, and spent a total of $12,566.23.
- Stripe Payment Processing Fees $398.74
- Employee Related $601.39
- General & Administrative $90.28
- IT & Software $812.11
- Professional Fees $0
- 71.1 Hours of development work at $10,663.71
Until next time,
Irene, André and the Ruby Together team
### November 2020 Monthly Update
URL: https://rubycentral.org/news/november-2020-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello! Welcome to the monthly update. During November, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), and many others.
## ruby together news
In November, Ruby Together was supported by 41 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org) and Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). 1 company joined as a new member.
On top of those companies, Dan Milne signed up as a new developer member. In total, we were supported by 102 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems & bundler news
In November, we worked on the [Bundler Version Locking RFC](https://github.com/rubygems/rfcs/pull/29?ref=rubycentral.org) that allows a user to specify a required Bundler version in the Gemfile/gemspec with a working [proof of concept](https://github.com/rubygems/rfcs/pull/29?ref=rubycentral.org#issuecomment-731333194). We also made improvements to platform support by enabling the `specific_platform` functionality by default, and decided to delay the change to resolve all Gemfile platforms automatically.
In addition to that, we made the following improvements and fixes:
- fixed a missing require issue. [#4036](https://github.com/rubygems/rubygems/pull/4036?ref=rubycentral.org)
- fixed a couple of minor “Windows paths” issues. [#4038](https://github.com/rubygems/rubygems/pull/4038?ref=rubycentral.org), [#4039](https://github.com/rubygems/rubygems/pull/4039?ref=rubycentral.org)
- fixed gem specification `--platform`. [#4043](https://github.com/rubygems/rubygems/pull/4043?ref=rubycentral.org)
- added an `--all-platforms` flag that optionally allows generating Windows binstubs from non-Windows platforms. [#3886](https://github.com/rubygems/rubygems/pull/3886?ref=rubycentral.org)
- merged a PR to fix a bundle remove bug where it was removing comments. [#4045](https://github.com/rubygems/rubygems/pull/4045?ref=rubycentral.org)
- merged a PR to support the new signin endpoints. [#3840](https://github.com/rubygems/rubygems/pull/3840?ref=rubycentral.org)
- merged a PR to improve the `-C` flag to gem build. [#3983](https://github.com/rubygems/rubygems/pull/3983?ref=rubycentral.org)
- added a fix to slightly improve some “**gem not found**” error messages. [#4019](https://github.com/rubygems/rubygems/pull/4019?ref=rubycentral.org)
- fixed an intermittent spec failure. [#4060](https://github.com/rubygems/rubygems/pull/4060?ref=rubycentral.org)
- fixed an issue with changelog generation. [#4059](https://github.com/rubygems/rubygems/pull/4059?ref=rubycentral.org)
- fixed an issue with nested bundler invocations. [#4063](https://github.com/rubygems/rubygems/pull/4062?ref=rubycentral.org)
- fixed a discrepancy between executing with or without bundle exec. [#4063](https://github.com/rubygems/rubygems/pull/4063?ref=rubycentral.org)
- added more descriptive errors about default network errors. [#4061](https://github.com/rubygems/rubygems/pull/4061?ref=rubycentral.org)
- fixed a CI issue that appeared under Windows. [#4068](https://github.com/rubygems/rubygems/pull/4068?ref=rubycentral.org)
- merged a tweak to the bundle gem default skeleton. [#4066](https://github.com/rubygems/rubygems/pull/4066?ref=rubycentral.org)
- extended `gem` DSL with a `force_ruby_platform` option. [#4049](https://github.com/rubygems/rubygems/pull/4049?ref=rubycentral.org)
In November, [RubyGems & Bundler](https://github.com/rubygems/rubygems?ref=rubycentral.org) gained [58 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2020-11-01%7D...master@%7B2020-11-30%7D?ref=rubycentral.org), contributed by 10 authors. There were 816 additions and 426 deletions across 79 files.
## rubygems.org news
This month, we coordinated with Fastly support to enable Globalsign certs and AAAA records in our TLS config. We updated [RubyGems CLI gem signin](https://github.com/rubygems/rubygems/pull/3840?ref=rubycentral.org) according to changes requested in a review and also made the following fixes and improvements:
- added a new way to match RubyGems versions using the `build-arg` in docker image. [#2548](https://github.com/rubygems/rubygems.org/pull/2548?ref=rubycentral.org)
- fixed failing tests in `shoulda-matchers` update and reported an issue of invalid objects should `belong_to` tests on `shoulda-matchers` repo. [#1375](https://github.com/thoughtbot/shoulda-matchers/issues/1375?ref=rubycentral.org)
- investigated `DelegationError` for ownership records with nil `user_id`.
- updated our DMARC policy to ensure that spoofed emails with [rubygems.org](https://rubygems.org/?ref=rubycentral.org) in sender get marked as spam.
- worked on a PR to resolve a HackerOne report, disallowing duplicate canonical version numbers. [#2559](https://github.com/rubygems/rubygems.org/pull/2559?ref=rubycentral.org)
- read the privacy policies of other package manager websites and researched the requirements for CCPA and GDPR.
- added `Pagerduty` integration for Cloudwatch ALB alerts.
As always, we continue to fix bugs, review and merge PR’s and reply to support tickets.
In November, [RubyGems.org](https://github.com/rubygems/rubygems.org?ref=rubycentral.org) gained [23 new commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2020-11-01%7D...master@%7B2020-11-30%7D?ref=rubycentral.org), contributed by 3 authors. There were 89 additions and 15 deletions across 12 files.
## budget & expenses
In November, we saw $7,839.53 in total income, and spent a total of $12,992.05.
- Stripe Payment Processing Fees $274.76
- Employee Related $500.60
- General & Administrative $115.43
- IT & Software $737.26
- Professional Fees $2,388.00
- 59.8 Hours of development work at $8,975.00
Until next time,
Irene, André and the Ruby Together team
### Five Things To Be Grateful For in the Ruby Together Community
URL: https://rubycentral.org/news/five-things-to-be-grateful-for-in-the-ruby-together-community/
Last updated: 2022-11-28T23:39:42.000Z
It’s hard to believe that December is here. Even more mind-boggling: in the next few weeks we’ll be winding down a decade. This was a tough year. We want to commend and thank all of the developers who helped us maintain healthy projects and a kind community in a year where no connection or offer of support was taken for granted.
It might be easy for any of us to list all the ways this year seemed to limit us. We’d love to offer you a moment to reflect with us on what we’re grateful for in the Ruby Together community.
**1\. Five years of Ruby Together!**
We can’t let the end of this year pass without acknowledging our five year anniversary! In 2015 Ruby Together incorporated as a solution to the dire need for consistent contributors to Ruby projects that provide infrastructure for the entire community; in particular Bundler, RubyGems and RubyGems.org. Five years and a pandemic later… and we’re still being supported by our community. We can’t thank you enough for demonstrating how valuable and worthwhile funding this work is to you.
**2\. A Source of stability this year**
We really want to brag about our uptime. Before Ruby Together, with Bundler and Ruby Gems run entirely by just a couple of extremely part-time volunteers, outages could last a day and even — on a few occasions — multiple days in a row. In fact, a week-long outage due to a security issue directly led to the founding of Ruby Together.
All of Ruby Together’s work has been worth it: as of December 8, we have managed 99.997% uptime in 2020 — less than 15 minutes of downtime during the entire year.
**3\. Features that make us feel festive**
Since Ruby Together launched in 2015, we’ve reached some huge milestones:
- there are now over 175,000 gems (up from 101,000)
- there are over 1,216,000 versions of gems (up from 583,000)
- we have served 64 billion (!) gem downloads (up from 4.5 billion in 2015)
One of the accomplishments we’re most proud of is designing and shipping the compact index that keeps track of every gem and dependency. It’s been the key to faster installs and updates, as well as ensuring that developers get gem versions that will work with their version of Ruby.
At the same time, we migrated all of RubyGems.org to use the Fastly content delivery network, dramatically increasing the speed of downloading gems around the world.
**4\. Maintenance, money…and maids**
A few reasons to be grateful according to our team members — especially if you use Ruby every day:
“\[Ruby Together\] ensures that chores of keeping shared infrastructure up and running is well compensated and the burden of maintaining a shared project doesn’t fall on a single contributor or a company.”
“\[Ruby Together\] seems more like the housemaid of Ruby community to me. It does the work we all agree we need to do but no one wants to do it themselves.”
**5\. Our incredible developer community**
We’re lucky that developers we’ve connected with in the Ruby Together community are welcoming and inclusive, and we actively work to keep it that way. We have a commitment to only fund projects with a code of conduct. The most popular code of conduct in the Ruby community, the [Contributor Covenant](https://www.contributor-covenant.org/?ref=rubycentral.org), was created by Ruby Together board member [Coraline Ada Ehmke](https://github.com/coralineada?ref=rubycentral.org).
We’re cautiously optimistic about what the next year holds. For now, we’re thankful to be able to continue this work and to be a part of your community.
(**Extra thanks:** Of course, we can’t let the end of this decade pass without acknowledging 25 years of Ruby programming language. We’re grateful to Yukihiro Matsumoto and the early developers who help make the language what it is today. The world of open source has transformed in massive ways since then. One thing that hasn’t changed: open source is valuable and open source developers deserve to be compensated for their work.)
### October 2020 Monthly Update
URL: https://rubycentral.org/news/october-2020-monthly-update/
Last updated: 2022-11-28T23:39:44.000Z
Hello! Welcome to the monthly update. During October, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [Bleacher Report](http://www.bleacherreport.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), and many others.
## ruby together news
In October, Ruby Together was supported by 43 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org) and Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). 5 companies joined as new members.
On top of those companies, 5 new developers signed up as members, including Aleksandar Krastev, Exequiel Rozas, and Joel Hawksley. In total, we were supported by 104 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems news
In October we released Bundler version `2.2.0.rc.2` and RubyGems version `3.2.0.rc.2`.
In addition to shipping those releases, we also:
- upgraded Bundler & RubyGems vendored Molinillo to **0.7.0** (it’s latest release). - [#3402](https://github.com/rubygems/rubygems.org/pull/3402?ref=rubycentral.org), [#3388](https://github.com/rubygems/rubygems.org/pull/3388?ref=rubycentral.org)
- fixed an [issue with the specific\_platform setting](https://github.com/rubygems/rubygems/pull/4022?ref=rubycentral.org).
- merged a PR that stops changing the CWD for building extensions, which should allow concurrent extension compilation without any contention. - [#3498](https://github.com/rubygems/rubygems/pull/3498?ref=rubycentral.org)
- worked on PRs to improve independence between test and lib code (simplifies and helps packagers), and added some changes to improve specs.
- added improvements to require more default gems lazily.
- fixed an issue with help commands when Bundler has been installed by `ruby-core` installer and `man` is not available. - [#3997](https://github.com/rubygems/rubygems/pull/3997?ref=rubycentral.org)
- wrapped up a PR to allow installing plugins from local paths. - [#4020](https://github.com/rubygems/rubygems/pull/4020?ref=rubycentral.org)
- fixed daily Bundler CI by marking the new `pathname` default gem as unsupported. - [#4029](https://github.com/rubygems/rubygems/pull/4029?ref=rubycentral.org)
- fixed a `Kernel.warn` stackoverflow. - [#3987](https://github.com/rubygems/rubygems/pull/3987?ref=rubycentral.org)improved the deprecation path for gem query. - [#4021](https://github.com/rubygems/rubygems/pull/4021?ref=rubycentral.org)
- fixed issues with Bundler not loading RubyGems plugins in `$LOAD_PATH` locations, which was affecting some version managers. - [#3534](https://github.com/rubygems/rubygems/pull/3534?ref=rubycentral.org)
As always, we continue responding to RubyGems & Bundler issues and PRs, doing issue triage on both old and new issues, and reducing the number of open tickets.
This month, RubyGems gained 143 new commits, contributed by 11 authors. There were 2,889 additions and 1,705 deletions across 889 files.
## rubygems.org news
This month we implemented a [bulk update to RubyGem downloads count](https://github.com/rubygems/rubygems.org/pull/2527?ref=rubycentral.org) to reduce the processing time for `FastlyLogProcessor` by about 20 seconds. We studied an old HackerOne Report and proposed a solution for it that will get implemented into RubyGems.org.
We also made the following changes and improvements:
- imported Fastly rubygems.org production configuration to Terraform.
- updated Fastly `vcl` to unset X-Forwarded-Host from requests to fix a HO report.
- added regex whitelist for URL on honeycomb logs export to ensure we don’t inadvertently send any sensitive information.
- fixed total count shown on search pagination. - [#2526](https://github.com/rubygems/rubygems.org/pull/2526?ref=rubycentral.org)
- rebased and updated a PR to separate the edit profile and account settings, making options like MFA registration easier to find. - [#2537](https://github.com/rubygems/rubygems.org/pull/2537?ref=rubycentral.org)
- updated staging.rubygems.org to support **TLS 1.3** as recommended by the most recent TLS documentation of Fastly.
- created a support ticket on Fastly to request a limit increase on TLS certificates and enable the limited offering of GlobalSign certificates.
- updated **DMARC** record of rubygems.org to use Slack group and Postmarkapp.
- replied to support tickets and google group threads.
Finally, we [deployed an option to review changes](https://github.com/rubygems/rubygems.org/pull/2499?ref=rubycentral.org) thanks to [@mensfeld](https://github.com/mensfeld?ref=rubycentral.org); users can now compare differences between releases.
In total, Rubygems.org gained 46 new commits, contributed by 8 authors. There were 694 additions and 442 deletions across 63 files.
## gemstash news
This month we made a couple of improvements to the Gemstash project documentation: we added [documentation about Gemstash](https://github.com/rubygems/guides/pull/269?ref=rubycentral.org) and [documentation recommending Gemstash instead of gem server](https://github.com/rubygems/guides/pull/269?ref=rubycentral.org) (due to the fact that we plan to deprecate gem server).
## budget & expenses
In October, we saw $13,962.51 in total income, and spent a total of $11,479.85.
- Stripe Payment Processing Fees $303.26
- Employee Related $215.88
- General & Administrative $286.18
- IT & Software $776.29
- Professional Fees $319.00
- 65.9 Hours of development work at $9,882.50
Until next time,
Irene, André, and the Ruby Together team
### September 2020 Monthly Update
URL: https://rubycentral.org/news/september-2020-monthly-update/
Last updated: 2022-11-28T23:39:44.000Z
Hello! Welcome to the monthly update. During September, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Bleacher Report](http://www.bleacherreport.com/?ref=rubycentral.org), and many others.
## ruby together news
In September, Ruby Together was supported by 42 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). One company joined as a new member, and Loic Nageleisen signed up as a developer member. In total, we were supported by 102 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems news
This month, we did a lot of work triaging issues and so far we’re “winning the pulse” with over 80 issues closed vs only 14 opened, and 44 PRs merged vs 8 opened. We’ve also fixed a couple of new and outstanding issues some of which include:
- [fixes for the resolver](https://github.com/rubygems/rubygems/pull/3965?ref=rubycentral.org), which until recently was generating duplicate spec groups, making debug output much more verbose than it should.
- improving install for a local `gemspec` to prevent dependencies [unnecessarily hitting the network](https://github.com/rubygems/rubygems/pull/3968?ref=rubycentral.org).
- fixing bundler showing [some unnecessary warnings](https://github.com/rubygems/rubygems/pull/3969?ref=rubycentral.org) from git when using submodules.
- fixing the `--build-root` option to gem install which was [broken on Windows](https://github.com/rubygems/rubygems/pull/3975?ref=rubycentral.org) and broken when [gems with rubygems plugins](https://github.com/rubygems/rubygems/pull/3972?ref=rubycentral.org) were present on the system.
- fixing `ruby setup.rb` [unnecessarily rewriting the bundler gemspec](https://github.com/rubygems/rubygems/pull/3980?ref=rubycentral.org).
- fixing situations where [bundler would crash](https://github.com/rubygems/rubygems/pull/3854?ref=rubycentral.org) if running on a path including brackets.
- responding to HackerOne reports for RubyGems.
- adding a note about [credentials in the rubygems.org repo being fake](https://github.com/rubygems/rubygems.org/pull/2530?ref=rubycentral.org), in response to a HackerOne report.
- merging a PR [adding docs about Gemstash.](https://github.com/rubygems/guides/pull/266?ref=rubycentral.org)
- [Updating docs](https://github.com/rubygems/guides/pull/269?ref=rubycentral.org) to recommend Gemstash instead of gem server.
- catching up with changes in `ruby-core` regarding versioning default gems. ([#3937](https://github.com/rubygems/rubygems/pull/3937?ref=rubycentral.org) and [#3938](https://github.com/rubygems/rubygems/pull/3938?ref=rubycentral.org))
- fixing an issue with [configuration priority.](https://github.com/rubygems/rubygems/pull/3933?ref=rubycentral.org)
- deprecating [bundle cache –all.](https://github.com/rubygems/rubygems/pull/3932?ref=rubycentral.org)
- creating a unified release & changelog management workflow.
- working on breaking [#3317](https://github.com/rubygems/rubygems/issues/3317?ref=rubycentral.org) into multiple more actionable issues. ([#3317](https://github.com/rubygems/rubygems/issues/3317?ref=rubycentral.org#issuecomment-692449034) and [#3957](https://github.com/rubygems/rubygems/issues/3957?ref=rubycentral.org))
- fixing some issues with CI to adapt to `ruby-core` changes.
- [Shipping the bundle fund command](https://github.com/rubygems/rubygems/pull/3390?ref=rubycentral.org) that lists out all the URLs for `gems` whose maintainers are actively looking for funding (!).
We also worked on enabling `disable_multisource` and figuring out the different new behaviours it enables, several other `test/dev` issues and reviewing PRs from external contributors.
This month, Rubygems gained 150 new commits, contributed by 12 authors. There were 1263 additions and 4300 deletions across 176 files.
## rubygems.org news
In September we released the [work](https://github.com/rubygems/rubygems.org/pull/2357?ref=rubycentral.org) done during Google Summer of Code (GSoC) 2020 related to adding support of [managing owners using UI](https://guides.rubygems.org/managing-owners-using-ui/?ref=rubycentral.org) and confirmation of ownership addition. Many thanks to rubygems.org GSoC student [@vachhanihpavan](https://github.com/vachhanihpavan?ref=rubycentral.org) for doing an excellent job.
We also made the following updates and improvements:
- profiled the `#perform` method of Fastly log processor job and [updated it to fetch versions from DB in bulk](https://github.com/rubygems/rubygems.org/pull/2510?ref=rubycentral.org).
- updated a client side PR to identify scope as per the command, and update scope in case of forbidden response. ([#1962](https://github.com/rubygems/rubygems.org/pull/1962?ref=rubycentral.org) and [#3840](https://github.com/rubygems/rubygems/pull/3840?ref=rubycentral.org))
- [updated the IPv4 fallback PR](https://github.com/rubygems/rubygems/pull/2662?ref=rubycentral.org) to add configuration, and flag and tests for the configuration, and began work on adding tests for the fallback.
- [verified ownership and deploy namespace release of ruby stdlib](https://github.com/rubygems/rubygems.org/pull/2506?ref=rubycentral.org).
- updated API scopes client PR [to fix OTP fallback and with tests](https://github.com/rubygems/rubygems/pull/3840?ref=rubycentral.org).
- set up a new Zendesk slack integration and explored using their web widget as stand alone web form.
- removed gauges javascript file from [rg.org](https://rg.org/?ref=rubycentral.org) site and made a PR to migrate help links to Zendesk. ([#3840](https://github.com/rubygems/rubygems/pull/3840?ref=rubycentral.org) and [#2518](https://github.com/rubygems/rubygems.org/pull/2518?ref=rubycentral.org))
- deprecated [help.rubygems.org](https://help.rubygems.org/?ref=rubycentral.org) in favor of [support@rubygems.org](mailto:support@rubygems.org) to resolve the issue of genuine help tickets being marked as spam.
- responded to support tickets and google group threads.
This month, Rubygems.org gained 31 new commits, contributed by 5 authors. There were 2,467 additions and 292 deletions across 85 files.
## ruby toolbox news
Hey everyone,
I hope you’re well! I added displaying of repo README files to the Ruby Toolbox recently, which will hopefully be useful for quickly evaluating projects more in depth on top of the usual metrics directly on the site. Apart from that and the usual maintenance some topics I have looked into recently are:
Bringing lines-of-code stats to the site so you can have an indication of the size and complexity of the library at a glance. This is the one I hope to ship next
An official command line client that gives you quick access to data served by the recently launched API, including a report on the health status of your dependencies
Looking into options for improving the search, especially the response times
Providing an alternate database dump that excludes historical gem download stats, since they make up the majority of the dump size and make imports very slow, so if you just want some real data to work with it’s become a bit cumbersome at this point
Be safe and stay healthy!
Best, Chris
## budget & expenses
In September, we saw $19,818.70 in total income, and spent a total of $10,506.19.
- Stripe Payment Processing Fees $339.61
- Employee Related $221.22
- General & Administrative $242.18
- IT & Software $756.46
- Professional Fees $319.00
- 59.8 Hours of development work at $8,967.33
Until next time,
Irene, André and the Ruby Together team
### August 2020 Monthly Update
URL: https://rubycentral.org/news/august-2020-monthly-update/
Last updated: 2022-11-28T23:39:44.000Z
Hello! Welcome to the monthly update. During August, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [Bleacher Report](http://www.bleacherreport.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), and many others.
## ruby together news
In August, Ruby Together was supported by 43 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org) and Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org). 2 companies joined for the first time this month.
In addition to those companies, 2 new developers signed up as members, including Efstathios Stivaros. In total, we were supported by 101 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems news
This month we made improvements to our [man page generation process](https://github.com/rubygems/rubygems/pull/3923?ref=rubycentral.org) to ease contribution to the Bundler documentation, and reviewed and merged some PRs from various contributors. We’re thankful for our supportive community. <3
We coordinated with the Ruby core team about versioning default gems in [#3937](https://github.com/rubygems/rubygems/pull/3937?ref=rubycentral.org) and [#3938](https://github.com/rubygems/rubygems/pull/3938?ref=rubycentral.org), as well as [fixing an issue with configuration priority](https://github.com/rubygems/rubygems/pull/3933?ref=rubycentral.org).
We also deprecated [bundle cache --all](https://github.com/rubygems/rubygems/pull/3932?ref=rubycentral.org) in favor of explicitly configuring `bundle config set --local cache_all true`.
As always, we continue to fix bugs, review and merge PRs, and follow up with issue triaging.
In total, RubyGems gained 71 new commits, contributed by 15 authors. There were 639 additions and 262 deletions across 173 files.
## rubygems.org news
In August, we added a webhook configuration to Slack, set up Terraform modules sending Slack notifications from AWS Lambda, and completed the following tests, improvements and fixes:
- tested and deployed a PR for [blocking -/\_ variations of the gem names](https://github.com/rubygems/rubygems.org/pull/2341?ref=rubycentral.org) (which are most commonly abused by malicious actors) and fixed a missing index in the SQL query.
- debugged failing rspec failing builds and [updated the backfill required\_rubygems\_version task to also backfill required\_ruby\_version](https://github.com/rubygems/rubygems.org/pull/2474?ref=rubycentral.org).
- [added basic auth to staging.rubygems.org](https://github.com/rubygems/rubygems.org/pull/2486?ref=rubycentral.org), [loaded a production dump](https://github.com/rubygems/rubygems.org/pull/2489?ref=rubycentral.org), and did a test run of the backfill task.
- ran the backfill task in production, regenerated the `versions.list` file, verified `info_checksum` mismatches, and purged info keys on memcached and Fastly. This will ensure `bundle install` is able to run quickly when resolving more than 30k gem versions that previously caused `Gem::RuntimeRequirementNotMetError`.
- added Terraform modules for CloudWatch alerts on `alb`, `ec`, `es`, `rds` and `sqs`, and created alert thresholds.
- reduced docker image size of RubyGems.org by 100 MB by [removing sass-rails from the production image](https://github.com/rubygems/rubygems.org/pull/2478?ref=rubycentral.org).
- resolved tickets on help.rubygems.org.
This month, RubyGems.org gained 74 new commits, contributed by 6 authors. There were 225 additions and 118 deletions across 23 files.
## budget & expenses
In August, we saw $16,316.33 in total income, and spent a total of $15,661.84
- Stripe Payment Processing Fees $303.74
- Employee Related $237.31
- General & Administrative $217.18
- IT & Software $1,154.51
- Professional Fees $319.00
- 91.6 Hours of development work $13,733.84
Until next time,
Irene, André and the Ruby Together team
### July 2020 Monthly Update
URL: https://rubycentral.org/news/july-2020-monthly-update/
Last updated: 2022-11-28T23:39:44.000Z
Hello! Welcome to the monthly update. During July, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [Stripe](https://stripe.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Bleacher Report](http://www.bleacherreport.com/?ref=rubycentral.org), and many others.
## ruby together news
In July, Ruby Together was supported by 44 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org), and 102 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems news
In July, we improved [Bundler’s Issue Template](https://github.com/rubygems/rubygems/pull/3784?ref=rubycentral.org) for our maintainers and contributors. We also worked on [improving performance optimizations](https://github.com/rubygems/rubygems/pull/3793?ref=rubycentral.org), and simplified our CI Workflow to make all [Bundler testing combinations easier to maintain.](https://github.com/rubygems/rubygems/pull/3769?ref=rubycentral.org)
We made improvements and cleaned up PRs related to JRuby ([#3770](https://github.com/rubygems/rubygems/pull/3770?ref=rubycentral.org), [#3771](https://github.com/rubygems/rubygems/pull/3771?ref=rubycentral.org), [#3774](https://github.com/rubygems/rubygems/pull/3774?ref=rubycentral.org)) and merged a follow up [PR to have a clean rubocop on new gems.](https://github.com/rubygems/rubygems/pull/3765?ref=rubycentral.org)
[We implemented gem update --system --silent](https://github.com/rubygems/rubygems/pull/3789?ref=rubycentral.org) and configured RubyGems branch protection. We’ve also fixed `rake release` failing in the following instances:
- [when the credentials file is missing](https://github.com/rubygems/rubygems/pull/3783?ref=rubycentral.org)
- when a deprecation warning is triggered in the Github API
- when all [local tags are pushed instead of only the release tag.](https://github.com/rubygems/rubygems/pull/3785?ref=rubycentral.org)
Finally, we proposed a [new workflow for managing our changelog](https://github.com/rubygems/rubygems/pull/3792?ref=rubycentral.org) and merged more PRs integrating this workflow. [#3808](https://github.com/rubygems/rubygems/pull/3808?ref=rubycentral.org), [#3798](https://github.com/rubygems/rubygems/pull/3798?ref=rubycentral.org), [#3807](https://github.com/rubygems/rubygems/pull/3807?ref=rubycentral.org).
As always, we continue to fix bugs, review PRs, follow up with issues and perform ongoing maintenance.
This month, RubyGems and Bundler gained 227 new commits, contributed by 15 authors. There were 146 additions and 170 deletions across 1,070 files.
## rubygems.org news
RubyGems.org saw a lot of activity this month with 30 merged pull requests.
We updated our sendgrid account subscription to allocate dedicated IP, and setup rDNS and gmail postmaster. We also filed a support ticket with [Fastly](fastly.com) for an IPv6 connection issue, searched honeycomb’s RubyGems.org dataset for API keys and disabled their Fastly integration, and sent an email notification about it to our users.
We’ve migrated to sidecar nginx proxy running on EKS cluster from legacy SPOF nginx running on a dedicated host. We also updated our EKS cluster to v1.16.
Over on we resolved tickets, fixed a TypeError on the signup page, and removed unused daemons gems from the Gemfile.
In addition to those improvements, we completed the following:
a [fix for rack\_attack test failing on Travis with 429](https://github.com/rubygems/rubygems.org/pull/2451?ref=rubycentral.org)
searched 22 months of logs from s3 and [created a new email](https://github.com/rubygems/rubygems.org/pull/2463?ref=rubycentral.org) to [remediate a possible API key leak](https://blog.rubygems.org/2020/07/28/api-key-leak.html?ref=rubycentral.org).
debugged Outlook marking RubyGems.org mails as spam and filed a support ticket for shared IP update
worked on a PR for client side support of API key scopes and updated the server-side PR
cleaned up failed jobs with `retry/delete`.
ran `rake task` to delete dangling dependency reports and set `unresolved_name` manually.
fixed `NoMethodError` on transitive dependency page
removed unused dependencies from dockerfile ([#2449](https://github.com/rubygems/rubygems.org/pull/2463?ref=rubycentral.org))
In total, RubyGems.org gained 72 new commits, contributed by 8 authors. There were 335 additions and 111 deletions across 53 files.
## gemstash news
We worked on the S3 backend for Gemstash.
## budget & expenses
In June, we saw $14,718.48 in total income, and spent a total of $23,091.84.
- Stripe Payment Processing Fees $386.99
- Employee Related $301.99
- General & Administrative $225.22
- IT & Software $707.86
- Professional Fees $319.00
- 143.6 Hours of development work $21,537.77
Until next time,
Irene, André and the Ruby Together team
### June 2020 Monthly Update
URL: https://rubycentral.org/news/june-2020-monthly-update/
Last updated: 2022-11-28T23:39:43.000Z
Hello! Welcome to the monthly update. During June, our work was supported by [Stripe](https://stripe.com/?ref=rubycentral.org), [Bleacher Report](http://www.bleacherreport.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), and many others.
## ruby together news
In June, Ruby Together was supported by 44 different companies, including Ruby member [Zendesk](https://zendesk.com/?ref=rubycentral.org) and Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). Those companies were joined by 102 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems news
In June, RubyGems saw significant improvements to the Bundler and RubyGems development process. We released [Bundler 2.2.0.rc.1](https://github.com/rubygems/rubygems/releases/tag/bundler-v2.2.0.rc.1?ref=rubycentral.org) and [RubyGems 3.2.0.rc.1](https://github.com/rubygems/rubygems/releases/tag/v3.2.0.rc.1?ref=rubycentral.org)! 🎉
We also worked on synchronizing the latest versions of both libraries with ruby-core, and fixed issues that came up. We also [enforced our ruby-core workflow](https://github.com/rubygems/rubygems/pull/3725?ref=rubycentral.org) to try to prevent further tedious integrations with ruby-core in the future by catching issues early and minimizing the back and forth of patches between upstream and downstream.
We changed [bundler specs to raise by default when any subcommand fails](https://github.com/rubygems/rubygems/pull/3685?ref=rubycentral.org). This action helped reveal two bugs (which we of course, fixed!). We’ve adapted bundler release tasks to a [new repository layout](https://github.com/rubygems/rubygems/pull/3703?ref=rubycentral.org) and now have the changelog draft up-to-date.
We’ve also implemented a fix to [stop soft-validating gemspecs](https://github.com/rubygems/rubygems/pull/3668?ref=rubycentral.org) (i.e. giving validations that only warn) except for in gem-authoring contexts. We also added a [slack notification](https://github.com/rubygems/rubygems/pull/3689?ref=rubycentral.org) to the maintainers channel that triggers whenever the ruby-head builds starts failing. We also [simplified our CI Workflows](https://github.com/rubygems/rubygems/pull/3769?ref=rubycentral.org) and did some final cleanup PRs related to CI failures on jruby.
Outside of these major highlights, we continue to fix bugs, review PRs, improve our documentation, cleanup test suites, and continue our usual ongoing maintenance.
In total, RubyGems gained 243 new commits, contributed by 15 authors. There were 3003 additions and 2432 deletions across 313 files.
## rubygems.org news
This month, we added terraform module for RDS monitors and added alerts on `rubygems-production`, `rubygems-staging` and `shipit` instances. We followed up with fixes on RubyGems.org that have now been deployed and verified! We also debugged failed delayed jobs in production, created a [fix for issues with validating user emails](https://github.com/rubygems/rubygems.org/pull/2389?ref=rubycentral.org), [solved some search errors](https://github.com/rubygems/rubygems.org/pull/2406?ref=rubycentral.org), and [removed some pointless emails](https://github.com/rubygems/rubygems.org/pull/2388?ref=rubycentral.org).
In addition to that, we made a PR to [send mail update confirmation when a user changes their email address](https://github.com/rubygems/rubygems.org/pull/2392?ref=rubycentral.org), added a RubyGems.org guide for rate limits, and made the following improvements:
increased Strict-Transport-Security max-time to ensure HTTPS-only access.
updated [rake task to remove duplicate runtime dependencies](https://github.com/rubygems/rubygems.org/pull/2382?ref=rubycentral.org).
updated `versions.list` [source location from bundler-api to s3](https://github.com/rubygems/rubygems.org/pull/2380?ref=rubycentral.org) and added cronjob to update the file monthly.
ran rake tasks related to `compact_index` which enabled bundler to make fewer requests to our server when installing some gems and fixed install of gems with multiple Ruby or Rubygems requirements.
updated correct checksum task to use non-caching info\_checksum calc, rerun the task, and expire info cache of gems changed from production.
[rebased and updated API keys scope PR](http://https//github.com/rubygems.org/pull/1962?ref=rubycentral.org).
updated and deployed rate limit changes to fix merge conflict and use test helpers. [rubygems.org#2330](https://github.com/rubygems.org/pull/2330?ref=rubycentral.org)
reset a few leaked API keys and send mail to affected users.
As always, we continued to fix bugs, and provide help on [help.rubygems.org](https://help.rubygems.org/?ref=rubycentral.org) and ongoing support work.
In June, RubyGems.org gained 119 new commits, contributed by 10 authors. There were 1256 additions and 489 deletions across 86 files.
## budget & expenses
In June, we saw $16,342.97 in total income, and spent a total of $21,419.67.
- Stripe Payment Processing Fees $394.11
- Employee Related $ 331.94
- General & Administrative $ 151.60
- IT & Software $ 801.97
- Professional Fees $ 319.00
- 142.8 Hours of development work $ 21,419.67
Until next time,
Irene, André and the Ruby Together team
### May 2020 Monthly Update
URL: https://rubycentral.org/news/may-2020-monthly-update/
Last updated: 2022-11-28T23:39:43.000Z
Hello! Welcome to the monthly update. During May, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [Stripe](https://stripe.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Bleacher Report](http://www.bleacherreport.com/?ref=rubycentral.org), and many others.
## ruby together news
In May, Ruby Together was supported by 45 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). Five companies joined as new members.
On top of those companies, five new developers signed up as members, including Lola Odelola and Jakob Waller. In total, we were supported by 102 developer members. Thanks to all of our members for making everything that we do possible. <3
Stay safe out there, and have a good [Juneteenth](https://www.nytimes.com/article/juneteenth-day-celebration.html?ref=rubycentral.org)! Black lives matter, and if you support Ruby Together’s mission to provide fair compensation for open source work, you should support organizations working to end racism and discrimination, too. Donate to the [NAACP](https://www.naacp.org/?ref=rubycentral.org), the [SPLC](https://www.splcenter.org/?ref=rubycentral.org), or even better a local [bail fund](https://bailfunds.github.io/?ref=rubycentral.org) or local direct action organization. While you’re at it, [change your git default branch names](https://andre.arko.net/2020/06/06/changing-git-and-githubs-default-branch-name/?ref=rubycentral.org), too. See you next month! — André
## rubygems news
This month, we refactored the spec suite to be faster and collated changes that will be shipped in the next bundler release. We also fixed an [activation issue on old versions of Bundler](https://github.com/rubygems/rubygems/pull/3626?ref=rubycentral.org). In addition, we fixed several regressions in RubyGems custom require and made specific tests work when running from ruby-core (thanks to [@David Rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org)). Other work we did included revisiting a bunch of old PRs and work from the old repo and getting them ready to merge into the new repo.
In May, RubyGems gained 248 new commits, contributed by 19 authors. There were 2227 additions and 1857 deletions across 892 files.
## rubygems.org news
In May, we worked on reviewing several fixes on RubyGems.org that, once deployed, will unblock the next Bundler release. We’ve also done work on refining the upcoming release, and handling some deprecation message issues and a few problems with the integration with ruby-core. On top of this, we investigated Honeybadger reports and created PRs to fix all of them. RubyGems.org saw several bug fixes and updates this month, some of which include the following:
ran rake task to delete extraneous dependencies locally, and update tasks to update version info\_checksum.
verified feasibility of using updated\_at column to order versions for the generation of versions.list file.
added original\_script\_name to kaminari params blacklist, which prevents XSS and unintended URL redirect.
updated rack-attack tests and config to fix dependency update build.
resolved tickets on [Help.RubyGems.org](https://help.rubygems.org/?ref=rubycentral.org).
added rake task to update check of version with multi ruby/rubygems ([rubygems/rubygems.org#2370](https://github.com/rubygems/rubygems.org/issues/2370?ref=rubycentral.org)).
verified compact\_index update and running rake task don’t introduce new mismatches.
updated compact\_index to remove whitespace change and released a new version.
debugged checksum mismatch due to incomplete SQL ordering and unresolved dependencies.
worked on PR to fix SQL ordering of dependencies in info and update correct\_info\_checksum rake task ([rubygems/rubygems.org#2374](https://github.com/rubygems/rubygems.org/issues/2374?ref=rubycentral.org)).
fixed rack-attack failing tests due to merge issues ([rubygems/rubygems.org#2369](https://github.com/rubygems/rubygems.org/issues/2369?ref=rubycentral.org)).
restarted work on moving RubyGems.org‘s CI to Github Actions.
We continue to attend to tickets, update dependencies, and review patches and PRs on RubyGems.org.
For this month, RubyGems.org gained 58 new commits, contributed by 8 authors. There were 646 additions and 102 deletions across 46 files.
## budget & expenses
In May, we saw $15,966.16 in total income, and spent a total of $24,103.34.
- Stripe Payment Processing Fees $410.30
- Employee Related $317.17
- General & Administrative $180.77
- IT & Software $883.77
- Professional Fees $319.00
- 141.3 Hours of development work $21,195.46
Until next time,
Irene, André and the Ruby Together team
### April 2020 Monthly Update
URL: https://rubycentral.org/news/april-2020-monthly-update/
Last updated: 2022-11-28T23:39:43.000Z
Hello! Welcome to the monthly update. During April, our work was supported by [Zendesk](https://www.zendesk.com/?ref=rubycentral.org), [Stripe](https://stripe.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Bleacher Report](http://www.bleacherreport.com/?ref=rubycentral.org), and many others.
## ruby together news
> What a long month. Stay safe, healthy, and be understanding with yourselves, everyone. <3
> — André
Since our last update, Ruby Together was supported by 46 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). Five companies joined as new members.
On top of those companies, five new developers signed up as members, including Jared White, Manuel Meurer, and Ilya Zub. In total, we were supported by 105 developer members. Thanks to all of our members for making everything that we do possible. <3
## rubygems news
In case you missed our announcement last month: all ongoing work on Bundler and RubyGems now takes place inside `RubyGems/RubyGems` as, excitingly, we completed [merging](https://rubytogether.org/news/2020-04-02-March-2020-monthly-update?ref=rubycentral.org#bundler.news) the two projects into one repository.
RubyGems changes in April included a fix for a recent regression in RubyGems to interfere with common bundler usages, improvement to a missing spec error, and shipping a new RSpec runner that works better with parallelization. We also updated our CI to ruby 2.7 and made a PR to manage bundler development dependencies through bundler.
This month, Rubygems gained 181 new commits, contributed by 15 authors. There were 1,857 additions and 1,015 deletions across 132 files.
## rubygems.org news
In April, we worked on keeping RubyGems.org dependencies up to date. We also sent an email notification requesting users to enable MFA, leading to a threefold increase in MFA enabled accounts (Thank you [@aditya](https://github.com/aditya?ref=rubycentral.org)!).
In addition to those developments, we worked on the following:
- Merging bundler-site and RubyGems guides PRs.
- Updating our ElasticSearch Index to support prefix queries; previously these were returning incomplete search results.
- Investigating intermittent CI failure rubygems/bundler-site/issues/519.
- Working on a PR to add validation to string columns with user input rubygems/rubygems.org#2346.
- Fixing the broken animation on the stats page and ensuring Github stars count were using the metadata URI attributes rubygems/rubygems.org#2335.
- Working on optimizations for our stats and just\_updated endpoints; this will help us reduce 1200ms and 600ms in response time respectively. rubygems/rubygems.org#2333.
- Finishing the rate limit reset after a successful gem push rubygems/rubygems.org#2311.
[@johnfrancismccann](https://github.com/johnfrancismccann?ref=rubycentral.org) helped us to make sure our releases page shows a consistent number of items per page.
For the month, Rubygems.org gained 70 new commits, contributed by 8 authors. There were 337 additions and 143 deletions across 39 files.
## ruby toolbox news
Hey everyone,
I hope you’re safe and well! As mentioned in the previous update I investigated and fixed an issue with the github repo syncing mechanism via [rubytoolbox/rubytoolbox#649](https://github.com/rubytoolbox/rubytoolbox/pull/649?ref=rubycentral.org) and did some additional maintenance like Rails 6 upgrade, other dependency upgrades and such. The API has now also received the [official announcement blog post](https://www.ruby-toolbox.com/blog/2020-04-29/api-for-project-data?ref=rubycentral.org).
In May I will do some additional maintenance like Ruby 2.7 upgrade and review catalog submissions, plus looking into some additional tooling around the API.
Best and stay safe, Chris
## budget & expenses
In April, we saw $20,283.95 in total income, and spent a total of $18,975.44.
- Stripe Payment Processing Fees $415.53
- Employee Related $310.23
- General & Administrative $184.91
- IT & Software $691.00
- Professional Fees $3,369.00
- 96.1 Hours of development work $14,420.30
Until next time,
Irene, André, and the Ruby Together team
### March 2020 Monthly Update
URL: https://rubycentral.org/news/march-2020-monthly-update/
Last updated: 2022-11-28T23:39:43.000Z
Hello! Welcome to the monthly update. During March, our work was supported by [Handshake](https://handshake.org/?ref=rubycentral.org), [Stripe](https://stripe.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Bleacher Report](http://www.bleacherreport.com/?ref=rubycentral.org), and many others.
## ruby together news
> Phew. It’s been a long time since we posted an update. Some overwhelming life events happened, and I prioritized keeping the open source work happening over writing updates every month. And now it’s a global pandemic, which is not exactly un-overwhelming.
> Trying to backfill everything that happened would be a herculean task, so we’ll have to summarize: in 2019, Ruby Together paid open source developers $233,000 for over 1,550 hours of Ruby open source development and maintenance work. Those hours were spread across Bundler, RubyGems, RubyGems.org, Gemstash, the Ruby Toolbox, BridgeTroll, SimpleCov, and other projects. We also ran a session of RubyMe, spending $16,200 to ensure 6 pairs of mentors and apprentices could work together on various Ruby open source projects for 12 weeks. Now that we’ve summarized 2019, we’ll have a full update for the last month and then try to keep up from here on out.
> The good news is that we’ve got new additions to the team to keep the updates flowing, which should make them significantly more consistent. A very enthusiastic welcome is due to Irene Kannyo and Gift Egwuenu, who will be helping with content/copywriting and technical writing, respectively.
> — André
Since our last update, Ruby Together was supported by 46 different companies, including Ruby members [Stripe](https://stripe.com/?ref=rubycentral.org) and [Handshake](https://handshake.org/?ref=rubycentral.org). In that time, 4 other companies joined as new members.
On top of those companies, 26 new developers signed up as members, including Matt Sias, Ollie Bennett, @MikeRogers0, Mike Boone, Crawford Wynnes, Philip Arndt, Jimmy Chu, Tobias Pfeiffer, Thomas Powell, Shupport, Brandon Weaver, Michelle Ng SY, Pascal Wengerter, David Revelo, Michael Verret Jr, and Jared White. In total, we were supported by 108 developer members. Thanks to all of our members for making everything that we do possible. <3
## ruby me news
Although our last RubyMe session wasn’t in March, we wanted to highlight our successful RubyMe session during 2019\. We received almost 100 applications from prospective apprentices and about a dozen applications from prospective mentors. Our budget let us accept six mentor/apprentice pairs, and each pair worked together for 12 weeks between May and August 2019\. They were able to contribute to several Ruby open source projects including [Ruby on Rails](https://rubyonrails.org/?ref=rubycentral.org), If-me, Dev.to, Homebrew, Gemstash, and Babywearing from Ruby for Good.
We’re proud to report that two of our mentees landed jobs shortly after the session closed. Congrats to both of them!
If you want to know right away next time we’re able to open applications, sign up for our RubyMe-only newsletter at [rubyme.org](https://rubyme.org/?ref=rubycentral.org).
Future RubyMe sessions will happen as often as we are able to set aside budget for them, but current circumstances mean we’re not sure how soon that will be. If your company would be interested in sponsoring our next RubyMe session, please [get in touch](mailto:hello+rubymesponsor@rubytogether.org)!
## google summer of code news
Google Summer of Code is upon us again, and this year the inimitable volunteers [@hiren](https://github.com/hmistry?ref=rubycentral.org) and [@zoras](https://github.com/zoras?ref=rubycentral.org) have stepped up from mentoring last year to running the program this year. Ruby Together is less directly involved, but is still providing advice, backup administrators, and mentorship for some student projects. Students have finished applying, and the selection process is currently ongoing. We’re excited to see what they’re able to accomplish this summer!
## bundler news
Amazingly, all that work that the entire Bundler and RubyGems teams have been working at for years has paid off in a really big way: Bundler and RubyGems have merged repositories! On GitHub, `bundler/bundler` is archived, and all ongoing work on both projects now takes place inside `RubyGems/RubyGems`. All other repositories from the Bundler organization have either been archived (if unused) or moved to the RubyGems organization.
Not just the repositories have changed, either: the Bundler and RubyGems teams have merged as well. It’ll take us some time to work through 20 years worth of documentation and webpages, but we’ll be combining and updating them as fast as we can.
From this point forward, Bundler news will be reported together with RubyGems news. Hooray! 🎉
## rubygems news
As mentioned above, the huge news is that Bundler merged into RubyGems! Major props to @hsbt for sending the PR to combine repositories, as well as @deivid-rodruiguez for helping troubleshoot, fix CI, and get the PR landed.
On top of that huge accomplishment, RubyGems saw ongoing maintenance and bugfixes, improved tests on JRuby, better deprecation warnings, and fixes for the internal bot that labels PRs and issues. The RubyGems team spent time to get more familiar with newly imported Bundler issues, and the Bundler team spent time getting more familiar with RubyGems, as well as the usual PR review and issue triage.
In March, RubyGems gained [more than 10,000 new commits](https://github.com/rubygems/rubygems/compare/master@%7B2020-03-01%7D...master@%7B2020-03-31%7D?ref=rubycentral.org) (which includes all of Bundler’s history!) contributed by 21 authors. There were 96,617 additions and 961 deletions across 1,423 files.
## rubygems.org news
In March, thanks to Aditya and Colby we were able to update most of our gem dependencies, which included a security release to Rails. Additionally, he helped us fix the incorrect rate limit on the gem push endpoint. This should be a big improvement for users with high release volume like AWS, which publishes hundreds of gems every time they update `aws-sdk`. We also resolved some related rate limit issues with multi-factor authentication.
To mitigate against typo-squatting, we were previously maintaining a protected list of gem names using the Levenshtein distance. Unfortunately, the check turned out to be too strict, and caused more problems than it was solving. We have disabled it for now, and we are looking into other ways to deal with typo-squatting. Thank you for bearing with us while we figure this out.
Aditya was also able to complete a grab bag of other useful work, including:
- revisit adoptions PR/issues
- help a gsoc student write RFC for the ownership changes [rubygems/rfcs#25](https://github.com/rubygems/rfcs/issues/25?ref=rubycentral.org)
- fix incorrect backoff on mfa endpoints beside gem push [rubygems/rubygems.org#2270](https://github.com/rubygems/rubygems.org/issues/2270?ref=rubycentral.org)
- PR to migrate nginx to sidecar in staging deployment [rubygems/rubygems.org#2291](https://github.com/rubygems/rubygems.org/issues/2291?ref=rubycentral.org)
- PR to support prefix match [rubygems/rubygems.org#2308](https://github.com/rubygems/rubygems.org/issues/2308?ref=rubycentral.org)
- PRs to fix several open issues [rubygems/rubygems.org#2315](https://github.com/rubygems/rubygems.org/issues/2315?ref=rubycentral.org), [#2316](https://github.com/rubygems/rubygems.org/issues/2316?ref=rubycentral.org), [#2317](https://github.com/rubygems/rubygems.org/issues/2317?ref=rubycentral.org).
- debug 429 for info endpoint on nginx
- debug partial requests being logged as not cacheable by fastly
For the month, RubyGems.org received [80 commits](https://github.com/rubygems/rubygems.org/compare/master@%7B2020-03-01%7D...master@%7B2020-03-31%7D?ref=rubycentral.org) from 6 authors, who made 294 additions and 206 deletions across 17 files.
## ruby toolbox news
Hey everyone,
last month I wrapped up and launched an API for Ruby Toolbox which allows you to query project data. While it has not received the full announcement blog post treatment yet, you can still [read the project API docs](https://www.ruby-toolbox.com/pages/docs/api/projects?ref=rubycentral.org), and an official API client is available as a gem at [rubytoolbox/rubytoolbox-api](https://github.com/rubytoolbox/rubytoolbox-api?ref=rubycentral.org).
For this month apart from officially launching the API I will mainly investigate and resolve some issues on the project updates that recently emerged, leading to many projects displaying wrongly their github repos being gone, see [rubytoolbox/rubytoolbox#615](https://github.com/rubytoolbox/rubytoolbox/issues/615?ref=rubycentral.org).
I hope you all get through the ongoing crisis well and wish you all the best, Chris
## budget & expenses
Since our last update, we’ve changed bookkeepers, and we plan to use budget reports directly from the professionals from now on. With that said, here’s our budget for March 2020.
In March, we saw $21,351.16 in total income, and spent a total of $25,995.27.
- Stripe Payment Processing Fees $376.94
- Employee Related $135.71
- General & Administrative $3,328.13
- IT & Software $1,072.74
- Professional Fees $319.00
- 123.5 hours of development work $18,519.59
Until next time,
Irene, André, and the Ruby Together team
### Growing Ruby Together
URL: https://rubycentral.org/news/growing-ruby-together/
Last updated: 2022-11-28T23:39:43.000Z
Recently I joined [Ruby Together](https://rubytogether.org/?ref=rubycentral.org) to help grow the membership community. Having been a Ruby developer for nearly 15 years, this represents a truly exciting opportunity to give back to the community and be a part of a meaningful organization. But the first question I had to figure out was, why grow? Ruby Together has nearly 200 members, which is a great start. Our current membership base allows us to make critical security and bug fixes to RubyGems and Bundler, as well as fund mentorship programs and grants for open source Ruby software.
The obvious answer is more members means more resources to improve Ruby projects. But the less obvious answers are also exciting and represent a transformative opportunity for the future of Ruby and our community. So I hope you will join me as I share why Ruby Together is so important, what we have accomplished, and what the future holds.
## Why is Ruby Together important?
Bundler, RubyGems, and the Ruby Toolbox, the primary open source projects supported by Ruby Together, are used tens of billions of times a year. Bundler and RubyGems make up not just the most important pieces of Ruby infrastructure, but also serve as critical tools for millions of sites across the internet. Without the support of our members, we would not be able to hire developers to make improvements to these tools and reliably keep them secure. By ensuring these services remain stable, Ruby Together helps foster a diverse ecosystem of open source libraries, plugins, and repositories able to coexist among multiple Ruby, gem, and code versions.
The Ruby language is also deeply intertwined with open source software. The language is open source, its most popular libraries are open source, and by and large, Ruby developers contribute greatly to open source projects. Traditionally, open source has been maintained by volunteers. While a net positive, this can pose some disadvantages, including lack of documentation, technical support, sustainability, and timely security fixes. Ruby Together was created to solve these problems by financially supporting open source maintainers, ensuring the long term success, security, and stability of the Ruby ecosystem.
As the Ruby community has grown and matured, Ruby Together has played an essential role in ensuring the long term stability of core Ruby projects by paying developers, thereby avoiding having to rely solely on volunteers. Bundler and RubyGems.org continue to serve billions of additional requests each year, making volunteer support unsustainable. Since our inception, Ruby Together has paid for over 5,000 hours of open source developer work, as well as advocated for the professional advancement of our members, and encouraged the next generation of Ruby developers by creating a welcoming and inclusive community through grant and mentorship opportunities.
## What else have we accomplished?
In addition to funding thousands of hours of improvements to Bundler, RubyGems, RubyGems.org, Gemstash and more, it is important to highlight some of the other outreach and impactful work Ruby Together does for the community.
Ruby Together [helped resurrect](https://www.ruby-toolbox.com/blog/2018-02-01/lets-push-things-forward?ref=rubycentral.org) the [Ruby Toolbox](https://www.ruby-toolbox.com/?ref=rubycentral.org), a comprehensive resource for developers to find maintained and popular open source Ruby libraries. The Ruby Toolbox has been one of my favorite resources over the years and recently [turned 10 years old](https://www.ruby-toolbox.com/blog/2019-05-01/time-flies?ref=rubycentral.org)! Our funding has helped the site’s creator, [Christoph Olszowka](http://olszowka.de/?ref=rubycentral.org), to maintain, open source, and redesign the site, as well as keep the data and projects up to date. Great work Christoph!
Ruby Together also [recently launched RubyMe](https://rubytogether.org/news/2018-09-18-announcing-ruby-me?ref=rubycentral.org), a mentorship program to help early-career developers improve their skills and confidence by contributing to Ruby projects, paying both mentor and mentee to pair program on open source software for 8 hours per month. To see a real world example of how RubyMe has benefited a new developer, check out our article on [career switching into code](https://rubytogether.org/news/2019-06-30-career-switching-into-code?ref=rubycentral.org). And if you are interested in participating in our next cohort as an apprentice or mentor, please check out [RubyMe.org](https://rubyme.org/?ref=rubycentral.org) and sign up for our newsletter to be notified when applications re-open.
On a quarterly basis, Ruby Together evaluates proposals for funding specific Ruby open source or community projects through our [grant program](https://rubytogether.org/projects?ref=rubycentral.org). If you are looking for funding for your open source project, [apply here](https://rubytogether.org/proposal?ref=rubycentral.org)! Recently we profiled the progress of one our funded projects, [Bridge Troll](https://www.bridgetroll.org/events?ref=rubycentral.org). Bridge Troll makes it easier to discover workshops around the world helping people learn to code. Learn more about [how Ruby Together funding has helped benefit the Bridge Troll project](https://rubytogether.org/news/2019-07-07-helping-everyone-learn-to-code?ref=rubycentral.org).
Last but not least, we [announced an partnership with Tidelift](https://blog.tidelift.com/tidelift-teams-up-with-ruby-together-to-support-infrastructure-for-every-ruby-developer?ref=rubycentral.org), enabling their enterprise subscribers to financially contribute to Ruby Together’s open source maintenance. With this initiative, Tidelift will support and broaden Ruby Together’s reach to professional teams that primarily use other languages, but also have a lot of Ruby packages in their technology stack.
## What’s next for Ruby Together as we grow?
Lots of great things are coming down the pipeline as we grow:
- Merging Bundler and RubyGems into a single, unified project, simplifying updates and installation, eliminating version mismatches, and making the overall Ruby experience more seamless for new and existing Ruby developers.
- Hiring more developers to provide a steady cadence of ongoing maintenance and improvements for Bundler, RubyGems, the Ruby Toolbox, and other projects that benefit the Ruby community.
- Increased opportunities for [RubyMe](https://rubyme.org/?ref=rubycentral.org) applicants and more awards through our open source [grant program](https://rubytogether.org/projects?ref=rubycentral.org).
- Expanding [RubyBench.org](https://rubybench.org/?ref=rubycentral.org) into a public benchmark for every commit of Bundler, Rails, and Ruby itself. RubyBench is a long running benchmarking tool to ensure new code commits do not negatively impact performance.
- Creating a public Ruby ecosystem analytics dashboard with vastly expanded statistics for Ruby, Bundler, and each gem.
- A new member portal with news, job postings, career developments tools, and special events, along with resources to help new developers get started on their journey.
- Advocacy programs to encourage and nurture new programmers to pursue learning the Ruby programming language.
**But**, we can’t do any of this without your help.
## How Can I Get Involved?
First and foremost, become a member! Join organizations such as Stripe, Bleacher Report, DigitalOcean, Triplebyte and [more](https://rubytogether.org/members?ref=rubycentral.org) and show your support for the Ruby community. We have flexible membership options for both [companies](https://rubytogether.org/companies?ref=rubycentral.org) and [individuals](https://rubytogether.org/developers?ref=rubycentral.org). As a nonprofit trade association, your membership dues are generally tax deductible. Or if you are feeling generous, you could also make a [one time gift](https://rubytogether.org/developers?ref=rubycentral.org).
We are always looking for new [Ruby open source project grant proposals](https://rubytogether.org/proposal?ref=rubycentral.org) to fund, as well as mentors and apprentices for our [RubyMe](rubyme.org) mentorship program. Apply today!
Check out the swag at the [Ruby Together Shop](https://shop.rubytogether.org/?ref=rubycentral.org) and show your support at community events. All proceeds benefit Ruby Together’s work.
Finally, don’t forget to stay up to date with all the latest news. Follow us on Twitter at [@rubytogether](https://twitter.com/rubytogether?ref=rubycentral.org) and sign up for our newsletter. Tweet out this post and email me your address and I’ll make sure to send you some awesome swag!
If you have any questions or are interested in learning more about Ruby Together and our activities, please don’t hesitate to reach out to me at matt@rubytogether.org.
Looking forward to hearing from you!
Matthew Solt, Community Growth for Ruby Together
### June 2019 Monthly Update
URL: https://rubycentral.org/news/june-2019-monthly-update/
Last updated: 2022-11-28T23:39:43.000Z
Hello! Welcome to the monthly update. During June, our work was supported by [Handshake](https://handshake.org/?ref=rubycentral.org), [Stripe](https://stripe.com/?ref=rubycentral.org), [Triplebyte](https://triplebyte.com/os/rubytogether?ref=rubycentral.org), [Bleacher Report](http://www.bleacherreport.com/?ref=rubycentral.org), and many others.
## ruby together news
In June, Ruby Together was supported by 57 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). 3 new companies joined in the last month. On top of those companies, 3 new developers joined as new members in the last month, including Balo. In total, we were supported by 119 developer members.
Thanks to all of our members for making everything that we do possible. <3
We had a quieter month in June, but both [Ruby Me](https://rubyme.org/?ref=rubycentral.org) apprentices and [Google Summer of Code](https://summerofcode.withgoogle.com/?ref=rubycentral.org) students continued to work on Ruby open source projects.
## bundler news
In June, Bundler saw ongoing fixes, including better support for Ruby 2.6 and integration with ruby-core. In addition, the `bundle clean` command was fixed for git gems in a symlinked location, and the gem management task `rake release` also added support for 2FA when pushing gems to RubyGems.org.
This month, Bundler gained 151 new commits, contributed by 12 authors. There were 1,308 additions and 1,224 deletions across 137 files.
## rubygems.org news
RubyGems.org had the usual ongoing security and dependency updates. It also saw improvements to the Fastly and Nginx configuration that will help us make it faster for newly uploaded gems to be able to be installed. Email notifications got visual design, password resets gained support for 2FA, API keys are now reset at the same time as passwords, and administrators now have more automation to deal with malicious gems or users more easily.
This month, Rubygems.org gained 55 new commits, contributed by 8 authors. There were 2,458 additions and 1,961 deletions across 200 files.
## rubygems news
RubyGems saw the usual ongoing fixes, including a fix for the `rubygems-update` gem that allows updating older versions of RubyGems to newer ones. David Rodriguez also did a huge amount of work on the RubyGems test suite, fixing many, many tests that either didn’t clean up after themselves or didn’t always pass.
This month, Rubygems gained 103 new commits, contributed by 17 authors. There were 728 additions and 592 deletions across 37 files.
## gemstash news
Gemstash had a calm month, seeing fixes for some rubocop and codeclimate issues, as well as fixes for some broken links.
This month, Gemstash gained 4 new commits, contributed by 4 authors. There were 19 additions and 18 deletions across 7 files.
## bridge troll news
We’ve gotten two updates so far on work on Bridge Troll, which we’ve posted to [the Ruby Together news page](https://rubytogether.org/news?ref=rubycentral.org). If you’re interested in following the project, check out [the Bridge Troll project interview and updates](https://rubytogether.test/news/2019-07-07-helping-everyone-learn-to-code?ref=rubycentral.org).
## budget & expenses
In June, we saw $11,474.28 in total income, and spent a total of $36,196.47.
- $2,117.50 for 14.1 hours worked on Bundler at $150/hour
- $650 for 4.3 hours worked on RubyGems.org at $150/hour
- $4,157.50 for 27.7 hours worked on RubyGems at $150/hour
- $2,187.50 for 14.6 hours worked on other OSS and devtools at $150/hour
- $9,018.09 for 60.1 hours of open source pairing in Ruby Me
- $76.68 on dedicated servers for RubyBench.org
- $391.22 on payment processing fees
- $8,674.12 on company overhead like hosting, services, software, hardware, taxes, etc
- $5,221.44 on accounting, copywriting, design, and other professional services
- $3,702.42 on marketing, evangelism, and community outreach
Until next time,
André and the Ruby Together team
### Helping Everyone Learn To Code
URL: https://rubycentral.org/news/helping-everyone-learn-to-code/
Last updated: 2022-11-28T23:39:43.000Z
Ruby Together is a non-profit trade organization that funds open source Ruby projects. This is a deep dive into one of our current funded projects including the backstory on the person who submitted the proposal and updates on project progress.
### How One Woman Is Helping Everyone, Even Grandmothers, Learn To Code
> It’s really important that everyone learns how to program at least a little bit. It’s going to be part of every future job. — Rachel Ober
[Over 65% of new developers are self-taught](https://research.hackerrank.com/student-developer/2018?ref=rubycentral.org). Rachel Ober is not part of that statistic. She’s among the surprising minority who learned to code in school, dual majoring in computer science and psychology—a compelling combination driven by a desire to learn how people think when they’re using computer systems.
Early in her career Rachel became interested in the front end of Ruby on Rails, and during that time she became involved with volunteer-run [RailsBridge](http://railsbridge.org/?ref=rubycentral.org), started by Sarah Allen and Sarah Mei. Their mission was bold and much needed: make it easier for people to learn Ruby on Rails in a welcoming and accessible environment. Even if somebody had never programmed, there was a place for them and a curriculum for absolute newbies.
The free workshops, still active today, go as far as to offer free childcare. Rachel recalls an entire family, grandmother included, driving from New Jersey to New York City on a Friday night to attend a weekend workshop. RailsBridge started as a grassroots initiative in 2009 targeting an underserved community and continues going strong with “events focused on increasing diversity in tech, so that people of all backgrounds can feel welcome and comfortable in the industry.”
In 2013, Rachel discovered a passion for teaching after being invited to develop General Assembly’s first Ruby on Rails course. The opportunity allowed her to experiment with teaching techniques to see what worked with new and experienced Ruby on Rails students. Tech was moving into New York City more and a lot of people interested in Ruby on Rails were expressing that it was hard to get started. All the dots started connecting and Rachel set off on a course to bring more Ruby on Rails workshops to New York City.
It was through this experience that [Bridge Troll](https://www.bridgetroll.org/events?ref=rubycentral.org) was born as an event management tool for all of [Bridge Foundry](https://bridgefoundry.org/?ref=rubycentral.org)’s Bridge communities. The function is to make it easier to surface novice to advanced workshops happening around the world so that more people can learn to code. “I found out about Ruby Together through Twitter and learned that the organization funded open source projects.
For Bridge Troll to happen, I needed funding to support the time I would dedicate to working on the tool, so I put an application together and made a case for it.” With her proposal reviewed and accepted by the Ruby Together board, Rachel shares updates on where Bridge Troll is today after four weeks into the Ruby Together program.
#### Update #1
Our first two weeks managing the Bridge Troll project were basically figuring out the scope of the Bridge Troll project!
To give some history, Bridge Troll was created in order to make it easier to surface workshops that were happening around the world.
All of our bridges are entirely volunteer-run and largely run independently from each other. This leads to flexibility, but what can occur is that organizers can feel lost or worse that there is no one else in the organization available to help them with their needs.
Unfortunately, this real-world reality is often reflected in the code base of Bridge Troll itself!
Bridge Troll was originally led by a core team of individuals who have rolled off the project over the years without finding a replacement core team to pick up the reins and lead development of features and manage bugs. Because the application had certain quirks originally meant just for RailsBridge and a USA-based workshop, we now run into problems where not all of our Bridge workshops are recorded in this important piece of software.
After many discussions with Sarah Allen on this subject, our first objective, and quite possibly the only objective of this project that we will likely focus on, is to create processes and lines of communication so that by the end of the 12 weeks we will have a new core team of contributors who will be set up for success to support the application and support new contributors who would like to help us out with the development.
My first objective for this 2-week period was to get introductions to the previous core contributors and begin conversations with those on the different program Boards for the different Bridge sub-organizations.
My second objective was to start documenting everything that I was working on, this included:
- Development log: to track what I was working on to report to Ruby Together
- Program Board: this can include daily updates of new files I created or documentation for the project or investigations into bugs that came in that I could triage right away.
- Communication log: to document who I was reaching out to and what decisions had been made
- Ongoing Questions file: if I had a conversation with someone and they ask something like “How do I get access to x?” and if I didn’t know how to answer that, I would add it to this file so that we could create the proper process to get people access.
- User Interview questions: as I began to schedule a time to talk to contributors and stakeholders, I wanted to make sure I was consistent in what I was asking them but also had two different paths depending on who I was talking to.
Contributors were those who worked in the internals of the Bridge Troll code base and know the history of why things are the way they are.
Program board members and workshop organizers were users of the application itself. I want to find out more where Bridge Troll is excelling as a tool but also failing to provide the support for running workshops.
There is a lot of work to be done on the project and most of it is just finding out what is the most important thing to focus on first!
Sarah Allen and I have regular weekly meetings set up to track progress and bounce ideas off of each other as I work through creating processes and triage bug issues over the next few weeks!
#### Update #2
Our second two-week batch of work focused on triage of new bugs, setting up more communication channels between code contributors, board members, and Bridge Troll users, and a deep look into the [Core Infrastructure Badge Program](https://www.coreinfrastructure.org/programs/badge-program/?ref=rubycentral.org).
*Triage of bugs*
One issue that constantly comes up is who has the permissions to approve new workshops on Bridge Troll? This is a question that spans both the core contributors (how exactly does someone get permission via the code base?) and the board members (which people get permission to approve events?)
The code base currently lets those who are bridge leaders, e.g. someone who is on the board, to approve events. But if that person is unresponsive—we have had issues where workshops have gone weeks without being approved—this can affect anything from attendance levels —because the workshop isn’t published on the platform—to the workshop’s organizers ability to get sponsorship funding because they can’t prove to the sponsor that the event is actually happening.
After a conversation with a past core contributor, we found that we could only add new admins via a Heroku console command and made a ticket to create an admin panel in Bridge Troll itself to better facilitate this action in the future. Additionally, we added 3 new admins (including myself, another core contributor, and a board member) to pick up the slack to approve new workshops.
We also recognized that the emails we send out to those who can approve workshops are ambiguous at best. The email itself does not have a clear “call to action” to say how to approve or what qualifications an event should have before approval. So that too was added to the backlog of things to address including a look into all of the emails we send!
*Core Infrastructure Badge Program*
I started to look into this after a conversation with Sarah Allen. Her feeling was that this program was a great first step to address the different parts of what a “successful” open source project includes in its documentation. I took a working session to run Bridge Troll through their system and set up a [public project status page](https://bestpractices.coreinfrastructure.org/en/projects/2769/?ref=rubycentral.org).
Going through each of these benchmarks is a time-consuming ordeal and even after I went through it independently, I needed to also speak to Sarah about this and ask more detailed questions about whether we hit the criteria, could do better at hitting the criteria or didn’t hit it at all. We definitely were better at certain sections than others, but unfortunately, we didn’t make it through the entire document in one sitting and will have to revisit it again.
*Top Hit List*
This session we also started to develop our most important hit list of items that we felt could make the biggest impact in addition to the Core Infrastructure Badge Program that would help show potential contributors that the project was active and looking for contribution. I started investigating the way we display dates and times on the site (which ended up being quite varied!) and caused confusion to our international workshop organizers and attendees.
Stay tuned for more updates on the 12-week Bridge Troll project. Interested in getting paid to work on a Ruby open source project? [Learn more and apply for funding!](https://rubytogether.org/projects?ref=rubycentral.org)
### Career Switching Into Code
URL: https://rubycentral.org/news/career-switching-into-code/
Last updated: 2022-11-28T23:39:43.000Z
*She thought politics was her future, turns out it was programming.*

Alicia envisioned a future in politics. The California native studied political science and anthropology in college and then made the move to Washington DC to pursue a career on The Hill. After a few jobs—with a think tank, a bank, and an NGO—she learned of an opportunity thanks to [Women Who Code](https://www.womenwhocode.com/?ref=rubycentral.org) DC, where other women her age or younger were problem-solving and gaining financial independence through careers in software development.
Ready for the career change, [Alicia](https://twitter.com/OptimistAlicia?ref=rubycentral.org) dropped everything, enlisted in a coding bootcamp, moved from DC to Atlanta, and started her dedicated journey into programming. Since she started learning, her goal has always been to land a full time role as a software engineer. Today, Alicia works as a Support Software Engineer at SalesLoft and has recently been accepted into Ruby Me, a paid mentorship program created by Ruby Together giving early-career Ruby developers the opportunity to build up professional development experience by contributing to open source projects with the help of a mentor. We chatted with her about the lessons learned and what it takes to make it in programming.
**Ruby Together: Can you describe your experience with Ruby Me?**
Jumping into open source can be intimidating, Ruby Me has given me the confidence and paid opportunity to get my feet wet. After I left DC, I got in touch with the Women Who Code chapter in Atlanta. A friend of mine there saw the Ruby Me apprentice opportunity and I applied. The process was straightforward and when I received the great news that I’d been accepted, it was one of my proudest moments.
My mentor, [Juan C. Ruiz](https://twitter.com/JuanCrg90?ref=rubycentral.org), is based in Mexico and we talk once per week. We have a good rhythm—create an action plan, execute, and then write a follow up report. I’ve submitted my first pull request and realized success here isn’t only measured through the number of PRs, but also the learning you gain by working through the obstacles.
**RT: What are you hoping to gain from this experience?**
I’m really looking forward to making contributions to the Ruby open source community. I’m also looking to grow confidence and use what I learn to help me land a full-time software engineering role.
**RT: What advice would you offer someone who’s considering jumping careers and getting into learning Ruby?**
A friend of mine, Ray Gesualdo, reminded me, “don’t go solo, self-taught is really community taught.” While you’re on this path, people will lend their knowledge to help you. For example, the Women Who Code community has been my strongest and most helpful ally. I found the local chapter in Atlanta to be supportive of my learning and amazing at helping me find opportunities like Ruby Me and SalesLoft.
I think it’s also wise to identify the job and company that you want and then work backwards from the skillsets. When you approach this field, it can be like, “learn everything, learn it well,” and that can be inefficient.
In terms of access to educational content, there are a lot of resources online. It certainly helps, but it isn’t essential to enroll in a coding bootcamp. Just be ready to put in the work. Finding a company to hire you right out of the bootcamp can be challenging, but there are also those who are jumping right out of bootcamp into a full time job.
Learning to code requires discipline, so don’t give up and keep working at it. Take feedback from people who are successful in this field and those you admire. It’s so helpful to have a community of people behind you; you’ll definitely need it. The Atlanta Women Who Code organization put me in front of my internship, the support engineer role I have today, and also the Ruby Me opportunity. They essentially helped put me on the radar.
**About Ruby Me**
Ruby Me is a three-month long paid mentorship program where early-career developers (with a firm grasp of Ruby fundamentals) get matched with experienced Ruby developers to work on an open source project of their choice. If you’re a recent bootcamp grad, career switcher, or developer employed at the junior level, we’re looking for you.
We’re also looking for experienced developers with a knack for teaching. Mentors and mentees work together remotely up to 8 hours every month, including documenting and sharing the results of their work. Each mentor and mentee earns USD$75 per hour for their work at the end of each month.
Ruby Me is run by RubyTogether. We accept applications for apprentices and mentors about once every 3 months. Learn more about Ruby Me [here](https://rubyme.org/?ref=rubycentral.org) and follow RubyTogether on [Twitter](https://www.twitter.com/rubytogether?ref=rubycentral.org) to catch the next application window.
### May 2019 Monthly Update
URL: https://rubycentral.org/news/may-2019-monthly-update/
Last updated: 2022-11-28T23:39:43.000Z
Hello! Welcome to the monthly update. During May, our work was supported by Ruby member [Handshake](https://handshake.org/?ref=rubycentral.org), and Sapphire members [Stripe](https://stripe.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), and [Triplebyte](https://triplebyte.com/os/rubytogether?ref=rubycentral.org), as well as many others. 1 company and 1 developer signed up as new members during the month. In total, we were supported by 59 companies and 119 developers. Thanks to all of our members for making everything that we do possible. <3
## ruby together news
It’s been a busy month! We launched the new [Ruby Me handbook](https://rubyme.org/handbook?ref=rubycentral.org), and the second group of apprentices and mentors began their work. This session, there are 5 apprentices and 5 mentors. They’re working on a wide variety of Ruby open source projects, and some are even already seeing PRs merged. We’re super excited to introduce more developers to open source.
Speaking of introducing developers to open source, we are also administrating the Google Summer of Code organization for Ruby again this year. Out of dozens of applications, we were able to accept six students to work on their proposed projects over the summer. You can [read more about those projects on the Summer of Code website](https://summerofcode.withgoogle.com/organizations/5542255322988544/?ref=rubycentral.org).
Finally, but importantly for Ruby Together members, we launched new membership tiers! When we first started, there was just one level for developers and one level for companies. Over time, things got overly complicated: some monthly contributions didn’t make you a member, and companies had a dizzying array of 9 levels to choose from.
We’ve drastically simplified and improved things: there are now 3 levels for developers ($10, $50, and $100), and 3 levels for companies ($500, $2000, $5000). Not only is that way easier to understand, it means everyone who contributes is now a member! All existing members have been migrated to one of the new levels, but will continue to pay the old price for as long as they keep their membership active.
This is just the first step of our work to provide more benefits for members, so keep an eye on future updates for more. 🙂
## bundler news
Bundler saw some great maintenance and testing improvements, including fixes for running the tests on Azure pipelines (which will mean running the Bundler tests on Windows!), as well as test order randomization to ensure no tests depend on other tests running before them. We also fixed a surprising bug where Bundler 2.0 did not actually change git sources from http to https, despite the docs and warning messages. 😬
The most exciting thing we did this month, by far, is [moving forward with the Bundler and RubyGems merger](https://github.com/rubygems/rfcs/blob/master/text/0003-merge-with-rubygems.md?ref=rubycentral.org#merge-bundler-and-rubygems)! As discussed and agreed on by the Bundler and RubyGems teams, the “maintainer” teams for both repos have been combined into one. Then, we reviewed all the repos in the Bundler GitHub organization, and archived all repos that are not currently being used.
Next, the repos `gemstash`, `rfcs`, `gemx`, `cacache-rb`, `bundler-slackin`, and `ruby-ssl-check` were all moved from the Bundler org to the RubyGems org. Assuming nothing explodes, we will shortly move the four remaining repos: `bundler-changelog`, `bundler-site`, `bundler.github.io`, and of course `bundler` itself.
This month, Bundler gained 66 new commits, contributed by 7 authors. There were 421 additions and 493 deletions across 69 files (nice).
## rubygems.org news
RubyGems.org saw general maintenance and dependency updates. The codebase also continued to settle in on Rails 5.2, enabling the new defaults that come with that version of Rails. Webhooks also saw some fixes, both only being sent on successful pushes, and starting to be sent again on yanks.
Overall, RubyGems.org gained 39 new commits, contributed by 7 authors. There were 117 additions and 136 deletions across 37 files.
## rubygems news
RubyGems mostly got fixes this month, including for untarring files with large UID/GID values, as well as a bunch of test improvements and fixes. In total, Rubygems gained 46 new commits, contributed by 10 authors. There were 904 additions and 538 deletions across 29 files.
## gemstash news
Gemstash got some documentation updates, as well as dependency updates, but the biggest change was moving the repo to `rubygems/gemstash` as part of the Bundler/RubyGems merge. Hooray!
This month, Gemstash gained 13 new commits, contributed by 4 authors. There were 40 additions and 24 deletions across 11 files.
## bridgetroll news
This quarter, Ruby Together is [funding a project](https://rubytogether.org/projects?ref=rubycentral.org) to maintain and improve [BridgeTroll](https://www.bridgetroll.org/?ref=rubycentral.org). Here’s the introduction to her project, and we’ll post her updates to the [Ruby Together blog](https://rubytogether.org/news?ref=rubycentral.org).
> Founded in 2008, RailsBridge started offering free workshops aimed at introducing women to Ruby on Rails in a judgment-free environment. Since then, many more “Bridges” have been created with the same mission statement and the Bridge Foundry mother organization was created to manage the financial and organizational objectives for the mostly volunteer organization.
> Bridge Troll is part of Bridge Foundry’s core infrastructure, supporting independent community initiatives all over the world with the great potential to increase impact. Bridge Troll is the online engine to ensure that we manage the inflow of students, give a framework to prospective organizers looking to run events, as well as track how many students are benefitting from these workshops. This software helps us apply for further grant funding to ensure that we can continue to run workshops for many years to come. We also want to use this tool as a way to create processes where people can level-up through active open source work with opportunities for a kind and respectful mentorship.
> Over the next 3 months, Rachel Ober will be facilitating work to streamline and develop processes to remove roadblocks from Bridge Troll’s backlog and issues database. The main goal during these 3 months is to come up with a process in order to facilitate future collaboration and contributions to the Bridge Troll project and make it clear what our most important goals are.
> Rachel will be making monthly updates via the [Ruby Together newsletter](https://rubytogether.org/news?ref=rubycentral.org) and the [Bridge Foundry blog](https://bridgefoundry.org/blog?ref=rubycentral.org). If you’re interested in more granular updates on choices and decisions during the project, you can subscribe to her newsletter at [developer.recipes](https://www.developer.recipes/?ref=rubycentral.org).
## budget & expenses
In May, we saw $12,572 in total income, and spent a total of $43,041.34, while funding 129 hours of development work.
- $10,030 for 66.9 hours worked on Bundler at $150/hour
- $1,800 for 12.0 hours worked on RubyGems.org at $150/hour
- $4,891.88 for 32.6 hours worked on RubyGems at $150/hour
- $2,628.12 for 17.5 hours worked on other OSS and devtools at $150/hour
- $76.53 on dedicated servers for RubyBench.org
- $423.95 on payment processing fees
- $14,415.39 on company overhead like payroll, services, software, hardware, taxes, etc
- $1,601.69 on accounting, copywriting, design, and other professional services
- $7,173.78 on marketing, evangelism, and community outreach
Until next time,
André and the Ruby Together team
### April 2019 Monthly Update
URL: https://rubycentral.org/news/april-2019-monthly-update/
Last updated: 2022-11-28T23:39:43.000Z
Hello! Welcome to the monthly update. During April, our work was supported by [Handshake](https://handshake.org/?ref=rubycentral.org), [Stripe](https://stripe.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Triplebyte](https://triplebyte.com/os/rubytogether?ref=rubycentral.org), and many others.
## ruby together news
The big news of April is that we grew our team to include new roles! [Matt Solt](https://twitter.com/mattsolt?ref=rubycentral.org) joined us as our new head of growth, and [Monica Silvestre](https://twitter.com/monicasilvestre?ref=rubycentral.org) is our new head of community. We’re super excited to work with both of them to grow Ruby Together into a bigger and better resource for the entire Ruby community.
In April, Ruby Together was supported by 60 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org) and Ruby member [Handshake](https://handshake.org/?ref=rubycentral.org). 1 new company joined as a member. In addition to those companies, we were supported by 62 individual members and 62 friends of Ruby Together. Thanks to all of our members for making everything that we do possible. <3
## bundler news
In April, Bundler saw ongoing fixes for Windows, as well as progress on getting the test suite passing on Windows in Azure Pipelines. @deivid-rogriguez continued to clean up the test suite, making it more consistent, reliable, and organized. He also tested and repaired the mechanics for upcoming deprecations messages, ensuring that nothing will break, as well as introducing [original\_env](https://github.com/bundler/bundler/pull/7052?ref=rubycentral.org) to clean up previous confusion around what `clean_env` might mean.
We also fixed several other issues: - Bundler could sometimes try to install versions that were not compatible with the running Ruby if it was rate-limited by RubyGems.org. - The Bundler gemspec shipped with Ruby would sometimes be empty, because `git` is not available in the environment ruby-core uses to package default gems - The `clean` command would not clean up unused extensions built for git gems - Vendored dependencies like `fileutils` and `automatiek` were outdated - The `info` command was missing some intended functionality - The `exec` command was unable to run default gems that ship with Ruby
Finally, in extremely exciting news, the process of merging Bundler and RubyGems has been [written down, discussed, and approved](https://github.com/bundler/rfcs/pull/18/?ref=rubycentral.org) by both the RubyGems and Bundler maintainer teams! We’ll keep you updated as we make progress on combining Bundler and RubyGems together.
This month, Bundler gained 187 new commits, contributed by 10 authors. There were 2,613 additions and 1,743 deletions across 142 files.
## rubygems.org news
Over on RubyGems.org, the yank rate limit was increased, password resets were updated to include two factor authentication, we added a webhook for yanking versions (thanks, @greysteil!), the Japanese translation was updated, and several other smaller issues were resolved.
This month, Rubygems.org gained 36 new commits, contributed by 9 authors. There were 668 additions and 172 deletions across 43 files.
## rubygems news
Various issues were resolved in RubyGems this month, including:
- Always expanding globbed file paths
- Setting permissions for non-owners on installed files
- Fixing `Gem::Requirement` so `~> 5.2` and `~> 5.2.0` are different, as intended
- Using `%x{}` for better Windows compatibility
- Removed a circular require in `rubygems/text`
- Added missing gem wrapper for default gem Bundler
- Bring back prompt for version if `uninstall` has multiple version options
In addition to those issues, many old deprecations and other legacy code and test issues were cleaned up.
This month, Rubygems gained 108 new commits, contributed by 9 authors. There were 618 additions and 219 deletions across 48 files.
## gemstash news
Gemstash was pretty quiet this month, and only saw the test suite bumped to run against the latest versions of Ruby and some style fixes. There were 8 new commits from 4 contributors, including 8 additions and 8 deletions across 4 files.
## budget & expenses
In April, we saw $13,057 in total income and $31,285.63 in total expenditure, to fund a total of 128.7 hours of developer work on Ruby open source.
- $10,000 for 66.7 hours worked on Bundler at $150/hour
- $1,562.50 for 10.4 hours worked on RubyGems.org at $150/hour
- $4,678.12 for 31.2 hours worked on RubyGems at $150/hour
- $2,559.38 for 17.1 hours worked on other OSS and devtools at $150/hour
- $487.50 for 3.3 hours worked on The Ruby Toolbox at $150/hour
- $77.18 on dedicated servers for RubyBench.org
- $441.01 on payment processing fees
- $7,023.65 on company overhead like hosting, services, software, hardware, taxes, etc
- $1,952.33 on accounting, copywriting, design, and other professional services
- $2,503.96 on marketing, evangelism, and community outreach
Until next time,
André and the Ruby Together team
### March 2019 Monthly Update
URL: https://rubycentral.org/news/march-2019-monthly-update/
Last updated: 2022-11-28T23:39:43.000Z
Hello! Welcome to the monthly update. During March, our work was supported by [Handshake](https://handshake.org/?ref=rubycentral.org), [Stripe](https://stripe.com/?ref=rubycentral.org), [Triplebyte](https://triplebyte.com/os/rubytogether?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), and many others.
## ruby together news
In March, Ruby Together was supported by 61 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). 2 companies joined as new members. On top of those companies, 2 new developers signed up as members or friends of Ruby Together, including Michael Jacobson. In total, we were supported by 66 individual members and 64 friends of Ruby Together. Thanks to all of our members for making everything that we do possible. <3
The response to our job posting for a Head of Growth was amazing, with over 175 applications submitted. We’ve been busily interviewing and working to find someone who shares our values and can help us with our goals. Keep an eye out, and we’ll announce the results soon!
In conference news, Ruby Together will be co-sponsoring [Board Game Night](https://ti.to/contributed-systems/railsconf-2019-board-game-night/en?ref=rubycentral.org) at [RailsConf 2019](https://railsconf.com/?ref=rubycentral.org) in Minneapolis! If you’ll be attending RailsConf, come visit for a chance to play games, eat snacks, talk with us, and pick up some Ruby Together stickers, pins, or other goodies.
## ruby me news
Ruby Me applications are back open! You can apply to our paid Ruby open source internship program as either an apprentice or a mentor until 6pm Pacific Time on April 15\. To learn more, visit [rubyme.org](http://rubyme.org/?ref=rubycentral.org).
## bundler & rubygems news
This month, Bundler merged new helpers named `with_original_env` and `with_unbundled_env` to replace the old confusingly-named `with_clean_env`. We also started merging fixes for issues on Windows, supported by last month’s changes to run the Bundler tests on Windows using Azure Pipelines. Overall, Bundler gained 179 new commits, contributed by 10 authors. There were 2,414 additions and 1,654 deletions across 136 files.
At the same time, RubyGems saw a bunch of cleanup as well as several security fixes. Update to the latest Ruby (or latest RubyGems if you can’t update your Ruby) to prevent several possible exploits while installing and using gems. Rubygems gained 101 new commits, contributed by 9 authors. There were 494 additions and 131 deletions across 47 files.
Back in January, we selected David Rodriguez for our first three-month long funded project, to work on Bundler and RubyGems. Here’s his third report from that work:
> Hello everyone!
> It’s been two weeks with a lot of activity, not only in terms of code but also in terms of team discussion. We have established the goal of discussing the future of the bundler and rubygems integration with ruby-core at Ruby Kaigi. We’ve also had interesting discussions in the team on how to handle breaking changes going forward, and when and how we should deliver an upcoming release including deprecations.
> On bundler, I continued the work on the deprecations themselves. At this point, I have a clear view of the set of changes that we plan to release, and how we plan to deprecate the old behavior. I’m now closed to the point where I’ll feel comfortable cutting a release from master with deprecations enabled. I’ve also been compiling the work on each deprecation into a UPGRADING.md document that explains the reason for each change, and how to migrate to the new behavior. I plan to use this document as a draft for a release blog post.
> In another line of work, I’ve been polishing the CLI in general to give better error messages. In particular, I’m preparing a patch to thor to allow specifying multiple synopsis for a command. The idea here is to ease breaking changes like `bundle update` no longer upgrading all gems. In order to make this transition easier, I want to make sure `bundle update` gives a proper and helpful error message when being run that points the user to the different correct alternatives to run the command. Given the complicated synopsis of the current `bundle update`command, this patch to thor aims to make this kind of error messages simpler for the user to understand.
> In addition to all that, I continue with the regular work as a bundler maintainer, making code cleanups, trying to incorporate PRs to master that had been blocked in the past because of having to support old rubies, and also continuing the work on getting ready for a docker-based CI (which we’ve also discussed internally too).
> On rubygems, I continued to cleanup code in master and deprecated a bunch of unused methods. I also continued the discussion on how to get `gem install` respecting ruby version and rubygems version constraints on the gem being installed. Migrating rubygems to use Bundler’s Compact API seems like the best solution since other experiments we’ve been doing on making the filtering on the client side require downloading an excessive amount of gems, which causes installation to be unbearably slow. Adding support for the compact API in rubygems is the hardest solution, but the best one, and will also be a big step forward towards a future unification of rubygems & bundler.
> Will keep you posted in future reports.
> Best,
> David.
Two weeks later, here’s his fourth report overall:
Hi friends, > > Already eight weeks, phew. Lots of stuff going on, bundler & rubygems > are slowly becoming better software :) > > During the previous two weeks I kept making progress as we move towards > a release including deprecations enabled. The more work I do on > providing a proper deprecation path for our users, the more stuff I find > out that needs to be done. But, I feel I’ve done a lot of progress with > this and I’ve now gone through most things. I wrote an upgrading > document where I talk about each breaking change, the motivations behind > it, and what the migration path will be. I also managed to remove some > unnecessary breaking changes and feature toggles. Besides that, I think > all these efforts have led to the core team have a better and more > consensual vision of the changes that will be made and their > motivations. Many of these changes have been there waiting on master for > a long time, so I think it was useful to have another pass over them, > and evaluate whether they still make sense, and whether the planned > migration still works. > > Something I have also made progress with is to keep improving the > integration of default gems in the ecosystem. Default gems are great but > require rubygems and bundler to be very careful about which gemified > libraries they use, and when. Loading default gems too early results in > a specific versions of them being activated, which might conflict with > the final version end users end up specifying inside their gemfiles. I > have fixed several of these issues, and kept improving the installation > of default gems, making it more consistent with the installation of > standard gems, and more similar to ruby-core’s default gem installer. > > We have also started several important conversations that I hope will > lead to further progress: > > \* The bundler & rubygems merge. We started deduplicating some code, and > I improved the current infrastructure that ensures master-to-master > compatibility between both repositories. I also started several > experiments about how the merge should happen. We will have deeper > discussions with the ruby-core team about this soon. > > \* The default Rails binstub. I started a discussion in Rails about > whether it should become a standard bundler binstub, thus making > maintenance easier and conflicts less likely. > > And as always, I try to keep fully involved in the regular maintenance > of both repositories, by reviewing PRs, fixing bugs, making the > development environment friendlier to other developers and keeping > master CI’s green against the latest versions of ruby. > > I’ll keep you posted in future reports, > > Best, > > David.
## rubygems.org news
In March, we migrated from a self-hosted Postgres instance to RDS. After we did that, we noticed a reduction in response time of some of our slowest endpoints by up to half! It was a pleasant surprise. We also updated our webhook functionality to send requests for yank events, which will help third party applications keep their state in sync with rubygems.org. We fixed the issue of password reset not asking the OTP from users who have enabled MFA. We also dropped a dependency on an unmaintained gem (dynamic\_form) and incorporated the section of code we were using into our own repository. Lastly, we added Japanese translation to our site, thanks to @m1kit.
This month, RubyGems.org gained 34 new commits, contributed by 9 authors. There were 668 additions and 172 deletions across 43 files.
## gemstash news
Gemstash had a relatively quiet month, with some ongoing investigation of a memory leak and some general cleanup and maintenance of the test suite to run against the latest versions of Ruby. This month, Gemstash gained 8 new commits, contributed by 4 authors. There were 8 additions and 8 deletions across 4 files.
## budget & expenses
In March, we saw $25,145.47 in total income, and spent a total of $25,995.27.
- $14,163 for 94.4 hours worked on Bundler at $150/hour
- $4,670 for 31.1 hours worked on RubyGems.org at $150/hour
- $915 for 6.1 hours worked on RubyGems at $150/hour
- $1,740 for 11.6 hours worked on other OSS and devtools at $150/hour
- $80.37 on dedicated servers for RubyBench.org
- $812.12 on payment processing fees
- $1,976.62 on company overhead like hosting, services, software, hardware, taxes, etc
- $375.0 on accounting, copywriting, design, and other professional services
- $1,263.66 on marketing, evangelism, and community outreach
Until next time,
André and the Ruby Together team
### January February 2019 Monthly Update
URL: https://rubycentral.org/news/january-february-2019-monthly-update/
Last updated: 2022-11-28T23:39:43.000Z
Hello! Welcome to the monthly update. During January and February, our work was supported by [Handshake](https://handshake.org/?ref=rubycentral.org), [Stripe](https://stripe.com/?ref=rubycentral.org), [Bleacher Report](http://www.bleacherreport.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), and many others.
*Yearly update update:* Wondering why you didn’t get the 2018 yearly update last month? Our email sending system was down last month due to a denial of service attack. You can [read the 2018 yearly update from last month on our website](https://rubytogether.org/news/2019-02-09-december-monthly-and-2018-yearly-update?ref=rubycentral.org).
## ruby together news
In January and February, Ruby Together was supported by 63 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). In total, we were supported by 66 individual members and 63 friends of Ruby Together. Thanks to all of our members for making everything that we do possible. <3
In other important news: [we’re hiring](https://ruby-together.breezy.hr/p/3d0aae712e8f-head-of-growth?ref=rubycentral.org)! We put out a call for a new, part-time Head of Growth. Part membership recruitment, part happiness maintainer, we are looking for someone who is excited about the Ruby community, open source, and engaging with developers and engineering management about supporting Ruby Together. Know someone who would be a fit? Send them our way!
## bundler news
In January, we awarded our [first three-month long project grant](https://rubytogether.org/projects?ref=rubycentral.org)to David Rodriguez for his work on Bundler and RubyGems. Here’s his first update:
Hello everyone!
This is my first progress report about my collaboration with Ruby Together to improve Bundler’s release process and deprecation management. I feel really proud that I’ve been given this opportunity, and I will do my best to improve the core of the Ruby ecosystem!
I have focused on several things these first two weeks:
I stabilized the builds of both Bundler and RubyGems, by fixing skipped tests and flaky failures to get both CIs consistently green. This should make subsequent improvements easier. In RubyGems, I landed several bug fixes in the install and update commands. With the release of Bundler 2 supporting only RubyGems 3.0, the basic command, “gem install rails”, started failing. We reverted the RubyGems 3.0 requirement in Bundler 2.0.1 to workaround this, but I intend to make `gem install` properly fallback to installing an older version when the `required_rubygems_version` requirement of the latest version is not satisfied. However, I decided to initially focus on some misc bug fixes in the install and update commands, to familiarize with the RubyGems code base and to be able to tackle this improvement with more confidence in the upcoming weeks. Big kudos to RubyGems contributor @MSP-Greg for providing the initial work for some of these fixes!
In Bundler, I started moving forward a new approach for deprecations, which will be enabled by default in the next release. We have a lot of improvements in Bundler’s master, but we haven’t released them for a long time, because they imply breaking changes. By starting to display deprecations for these changes, we’ll be closer to actually being able to release them. I also started addressing some issues surfaced by the Bundler 2 release, specifically about being too picky about the Bundler version a specific application should run. Currently, Bundler will raise if the version in the BUNDLED WITH section of the lock file doesn’t match the running version. We feel it’s premature to do this now, so I’m looking into downgrading this to a warning for the time being. I also coordinated with @colby-swandale the merge of Bundler 2 back into master, which hasn’t yet happened since the Bundler 2 release.
Finally, I’ve dedicated a fair amount of time to review the integration of Bundler into ruby-core since the 2.6 release, and the “gemification” of the standard library. Thanks to @hsbt, this is now a reality, but it comes with its own set of difficulties. I’ve been studying these difficulties and creating some fixes and workarounds for them. I plan to keep working on making this transition as smooth as possible for everyone.
I really hope my work is appreciated by the community and I expect to deliver better and bigger improvements in the upcoming weeks!
Best regards, David
*This is a combined update for January and February, so here is David’s second update as well:*
Hello everyone!
This is my second report about my collaboration with Rubytogether to improve bundler’s release process and deprecation management. They were a couple of exciting weeks, because I now feel I’m closer to being ready to release some of the work I’ve been doing.
The following is a non extensive list of the stuff I’ve been focusing on:
- I continued the work on bundler’s deprecations. I reviewed each deprecation and made sure the messages are actionable, they show up when they should, and they have passing specs. In particular, I made a plan for the deprecation of the changes that are most likely to be controversial and require special care. For example, I proposed to deprecate sticky options, and custom gemfile sources (such as :github, :gist, or :bitbucket), in a smoother process that should be more friendly to our users because it happens in several steps across multiple major versions. Finally, I made sure that we use non-deprecated features in our own specs, in order to set a good example :)
- In addition to deprecations, I also finished the work that I mentioned in the previous report about only reporting warnings and not hard errors when we find a mismatch between the running bundler version and the version the Gemfile was created with. I hope to release these changes in both rubygems and bundler soon.
- I also continued to improve the integration of bundler into ruby-core. I proposed to [eliminate the git dependency from bundler’s gemspec](https://github.com/bundler/bundler/pull/6985?ref=rubycentral.org) (which has caused problems with the integration), and raised [an issue](https://bugs.ruby-lang.org/issues/15610?ref=rubycentral.org) with ruby-core about where the default copies of bundler & rubygems should live, and how they should get updated. I’m in touch with hsbt and we plan to discuss the future of this integration some time in the near future.
- Finally, I’ve been working on making our specs “docker friendly”, and making bundler testable under bare docker images of ruby and rvm. My understanding is that this should make it much easier to reproduce CI failures (or user reported bugs), and to detect version manager specific regressions (or ruby-core integration bugs). Besides that, testing on top of custom docker images is something provided built-in by Azure pipelines, so it’s a good opportunity to try it.
As I mentioned in the previous report, I’m very glad to be working on bundler during these weeks. Any suggestions or feedback you may have, feel free to share them through Github, Slack or whatever means you like!
See you again soon,
David.
In January and February, Bundler gained 110 new commits, contributed by 11 authors. There were 1,401 additions and 1,503 deletions across 849 files.
## rubygems.org news
In last two months, we updated the search API to use Elasticsearch, which resolves multiple issues including [missing search results](https://github.com/rubygems/rubygems.org/issues/972?ref=rubycentral.org) and [slow performance](https://github.com/rubygems/rubygems.org/issues/1256?ref=rubycentral.org). Thanks to @lucianosousa, we are now using Rails 5.2.2\. We would also like to let you know that we sprinkled some styling to our email templates and now they are no longer being marked as spam by some email providers. We haven’t received any new help ticket for email being lost in last month—a good sign!
In mid February, we had to impose rate limit of one yank request per 10 min because we were seeing some users yank hundreds of gems at once. Our yank API endpoint was extremely slow, and hundreds of yanks at once was causing site instability. Since then we have worked hard on some optimizations and we are happy to report that we have brought down the average response time of Yank API from 4000 ms to 250 ms.
In January and February, Rubygems.org gained 67 new commits, contributed by 8 authors. There were 1,177 additions and 509 deletions across 81 files.
## rubygems news
RubyGems saw a bunch of commits cleaning up code, fixing bugs, and generally making things work better.
We also did additional work in the background, working with security researchers to fix problems that they had discovered. You can read more about [the security issues, fixes, and the latest release with fixes on the RubyGems blog](https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html?ref=rubycentral.org).
In January and February, RubyGems gained 153 new commits, contributed by 12 authors. There were 1,776 additions and 807 deletions across 176 files.
## gemstash news
Gemstash saw a few bug fixes in January and February. In total, Gemstash gained 19 commits contributed by 3 authors. There were 22 additions and 8 deletions across 5 files.
## ruby toolbox news
Hey everyone,
in February, the main topic for me was the restoration and reintegration of historical Ruby gem download data into the Ruby Toolbox, enabling two new features: [Historical Gem Download Charts](https://www.ruby-toolbox.com/blog/2019-02-25/historical-gem-download-charts?ref=rubycentral.org) and [Trending Projects](https://www.ruby-toolbox.com/blog/2019-02-28/trending-projects?ref=rubycentral.org) which both launched towards the end of the month. I documented the process of restoring the data [on a new documentation page](https://www.ruby-toolbox.com/pages/docs/features/historical%5Frubygem%5Fdownload%5Fdata?ref=rubycentral.org)
I also built and released a new [project comparison](https://www.ruby-toolbox.com/blog/2019-02-14/project-comparisons?ref=rubycentral.org) feature which allows you to view and compare a custom set of libraries just like regular categories or search results are displayed on the site.
Since I was busy getting these done until the last minute I did not find the time yet to write the review of the last 3 months of me working on the Toolbox as my main project. I will get to that soon, so keep an eye on the [Toolbox blog](https://www.ruby-toolbox.com/blog?ref=rubycentral.org) or simply wait for the next Ruby Together monthly update. :)
As always, your feedback is very welcome, if you have any suggestions or thoughts you’d like to share you can do so via [GitHub issues](https://github.com/rubytoolbox/rubytoolbox/issues?ref=rubycentral.org) or by getting in touch with me directly.
Thank you also to the PR contributors of February: alsemyonov, andyw8, havenwood, keithrbennett, kyleboe, listrophy, mbajur, pabloh, and serodriguez68
Best, Christoph
## budget & expenses
In January, we saw $13,390 in total income, and spent a total of $33,768.13.
- $1,135 for 7.6 hours worked on Bundler at $150/hour
- $2,062.50 for 13.8 hours worked on RubyGems.org at $150/hour
- $5,551.25 for 37.0 hours worked on RubyGems at $150/hour
- $3,263.75 for 21.8 hours worked on other OSS and devtools at $150/hour
- $11,837.50 for 78.9 hours worked on The Ruby Toolbox at $150/hour
- $75.93 on dedicated servers for RubyBench.org
- $452.67 on payment processing fees
- $7,898.73 on company overhead like hosting, services, software, hardware, taxes, etc
- $1,440.80 on accounting, copywriting, design, and other professional services
- $50 on marketing, evangelism, and community outreach
In February, we saw $13,883.15 and spent a total of $33,628.01.
- $993.12 for 6.6 hours worked on Bundler at $150/hour
- $2,062.50 for 13.8 hours worked on RubyGems.org at $150/hour
- $4,946.25 for 33.0 hours worked on RubyGems at $150/hour
- $2,598.12 for 17.3 hours worked on other OSS and devtools at $150/hour
- $13,587.50 for 90.6 hours worked on The Ruby Toolbox at $150/hour
- $75.97 on dedicated servers for RubyBench.org
- $465.69 on payment processing fees
- $7,048.36 on company overhead like hosting, services, software, hardware, taxes, etc
- $1,850.49 on accounting, copywriting, design, and other professional services
- $0 on marketing, evangelism, and community outreach
Until next time,
Stephanie, André and the Ruby Together team
### December Monthly and 2018 Yearly Update
URL: https://rubycentral.org/news/december-monthly-and-2018-yearly-update/
Last updated: 2022-11-28T23:39:43.000Z
Hello, and happy belated new year! Welcome to a year-end special edition of the monthly update: Ruby Together’s Yearly Update for 2018\. Throughout the year, our work was supported by [Handshake](https://www.handshake.org/?ref=rubycentral.org), [Stripe](https://stripe.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [Airbnb](https://www.airbnb.com/?ref=rubycentral.org), [Travis CI](https://travis-ci.org/?ref=rubycentral.org), [Coinbase](https://www.coinbase.com/?ref=rubycentral.org), [GitLab](https://about.gitlab.com/?ref=rubycentral.org), [reinteractive](https://reinteractive.com/?ref=rubycentral.org), [Stitch Fix](https://www.stitchfix.com/?ref=rubycentral.org), [Bleacher Report](https://bleacherreport.com/?ref=rubycentral.org), [Triplebyte](https://triplebyte.com/?ref=rubycentral.org), and many others.
## ruby together news
There are more details in the following sections, but here’s the tl;dr: during 2018, we took in $300,183.32, we spent $266,900.32, and we paid for 1,394 hours of developer work on Ruby open source.
Some highlights from the year include shipping 21 Bundler releases, shipping 11 RubyGems releases, kicking off Ruby Toolbox 2.0, Bundler almost shipping with Ruby 2.5, and announcing Project Proposals and Ruby Me.
During December, Ruby Together was supported by a total of 65 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org), as well as 69 individual members and 64 friends of Ruby Together. Thanks to all of our members for making everything that we do possible. <3
## now open: project funding proposals
Ruby Together is now accepting proposals for funded work on Ruby open source projects. Projects are expected to take between 20 and 200 hours, over three months. Proposals are now permanently open, and new projects will be selected for funding once per quarter. Selected projects and progress on those projects will be included in our regular monthly updates.
You don’t need to have prior open source development experience to propose a project, and you can live anywhere in the world. The project selection committee will choose which projects to fund based on our existing budget, and Ruby Together will fund development work on chosen projects for three months.
[Apply today](https://rubytogether.org/projects?ref=rubycentral.org)!
## bundler news
We’re funding one project application in Q1 2019: Bundler deprecation and release management, by prolific Ruby open source contributor [David Rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org). Not only is he a core team member of Bundler, he is the author of Byebug and Pry-byebug, as well as on the ActiveAdmin core team.
Here’s his message about the project:
> During the next months, I’ll be focusing on fixing some problems and surprises surfaced after the bundler 2.0 release, and bundler’s integration into ruby-core. I’ll also try to make sure we’re protected against the same kind of things happening in future releases. I’d like the bundler team to be able to ship bug fix and feature releases more confidently, with less regressions, and without any surprises whatsoever for users.
> For example,
Users should be able to early opt in to certain new features, thus providing early feedback and bug reports without affecting the majority of the users not yet trying those features.
The default availability of certain features should be toggleable in a smooth manner, by providing UI messages announcing the change, and a migration path for users who want to either migrate early, or stay in the old behavior.
Features should be deprecatable, and finally removable through a smooth process that properly informs users about how to replace them with better alternatives.
Really basic stuff, such as `gem install rails`, should be tested at the highest most realistic level, so that regressions never happen.
> All of these ideas are currently half baked in bundler’s master, but still require some work and some actual releases to wrap them up and put them into action. My project is about making this happen.
In December, Bundler reached two huge and exciting milestones. First, Ruby included Bundler for the first time ever, including Bundler 1.17.2 in Ruby 2.6\. Special thanks are due to [@hsbt](https://github.com/hsbt?ref=rubycentral.org) for years worth of work integrating Bundler into the ruby-core test suite and keeping everything working and up to date.
Second, Bundler [shipped version 2.0](https://bundler.io/blog/2019/01/03/announcing-bundler-2.html?ref=rubycentral.org)! It’s a big milestone, and the Bundler team is very excited to adopt a yearly major release cadence, to better match Ruby itself.
Bundler gained 55 new commits, contributed by 7 authors. There were 225 additions and 63 deletions across 21 files.
## rubygems.org news
In RubyGems.org news, lead RubyGems.org maintainer [@dwradcliffe](https://github.com/dwradcliffe?ref=rubycentral.org) completed porting the production RubyGems.org deployment to use Kubernetes! This didn’t cause any user-facing changes, but makes it easier for others to develop locally, and will help us with our efforts to avoid downtime.
Another major development was enabling two factor authentication, a Google Summer of Code project that can greatly improve the security of logging in and publishing new gems, for any gem authors who enable it.
In addition to those major developments, we continued to fix bugs, improve translations, and generally keep things humming along.
This month, RubyGems.org gained 57 new commits, contributed by 11 authors. There were 1,362 additions and 1,259 deletions across 111 files.
## rubygems news
December for RubyGems was also a big milestone: we shipped RubyGems 3.0.0! The biggest changes were S3 sources, multi-threaded gem downloads, support for two-factor authentication, and including Bundler 1.17.2.
In addition to those big changes, we continued to clean up unused code, improve warning and error messages, and fix bugs.
This month, RubyGems gained 149 new commits, contributed by 15 authors. There were 1,699 additions and 1,509 deletions across 270 files.
## ruby toolbox news
Hey everyone,
As mentioned in recent updates, I set aside some time and have been working on the Ruby Toolbox as my main project in December and January thanks to Ruby Together’s backing.
There’s been a flurry of activity in that time. Based on the feedback I received from November’s [community survey](https://www.ruby-toolbox.com/blog/2018-12-04/survey-results?ref=rubycentral.org) I shipped the following (among many smaller improvements ):
- [A new landing page](https://www.ruby-toolbox.com/blog/2019-01-09/new-landing-page?ref=rubycentral.org)
- [Project Health Indicators](https://www.ruby-toolbox.com/blog/2018-12-14/project-health-indicators?ref=rubycentral.org)
- [Project Sorting](https://www.ruby-toolbox.com/blog/2019-01-09/project-sorting?ref=rubycentral.org)
- [Bugfix fork filtering](https://www.ruby-toolbox.com/blog/2019-01-16/bugfix-fork-detection-and-filtering?ref=rubycentral.org) (and, through that, improved search results)
- [A new documentation and stats section](https://www.ruby-toolbox.com/blog/2019-01-24/metrics-documentation-and-statistics?ref=rubycentral.org)
- [Alternate project display modes](https://www.ruby-toolbox.com/blog/2019-01-31/alternate-project-display-modes?ref=rubycentral.org)
The feedback I received so far was very positive, and [two](https://rubyweekly.com/issues/430?ref=rubycentral.org) [mentions](https://rubyweekly.com/issues/434?ref=rubycentral.org) on the popular Ruby Weekly newsletter also brought in new intereset, contributions, and feedback.
Since I have some budgeted hours from Ruby Together remaining, I will continue working on the Toolbox through part of February. My main focus for that time will be bringing back historical data and, through that, bringing trending projects to the site (another highly requested feature from the community survey). As my focused time of working on the Toolbox comes to an end, I will also prepare a blog post looking back on the endeavour towards the end of February.
As always, your feedback is very welcome. If you have any suggestions or thoughts you’d like to share you can do so via [GitHub issues](https://github.com/rubytoolbox/rubytoolbox/issues?ref=rubycentral.org) or by getting in touch with me directly.
Thank you also to the PR contributors of December and January: FranklinYu, MrJoy, RuturajBisure, arbox, armandfardeau, bbatsell, bkuhlmann, bmedenwald, eveevans, gregors, grodowski, hsbt, janlelis, jsimpson, larskanis, mattyr, p0deje, and ttilberg
Best, Christoph
## December budget & expenses
In December, we saw $13,623.32 in total income, and spent a total of $21,674.66.
- $1,029.38 for 6.9 hours worked on Bundler at $150/hour
- $1,237.50 for 8.3 hours worked on RubyGems.org at $150/hour
- $5,292.62 for 35.3 hours worked on RubyGems at $150/hour
- $2,876.50 for 19.2 hours worked on other OSS and devtools at $150/hour
- $825 for 5.5 hours worked on The Ruby Toolbox at $150/hour
- $77.90 on dedicated servers for RubyBench.org
- $461.74 on payment processing fees
- $7,238.66 on company overhead like hosting, services, software, hardware, taxes, etc
- $2,575.64 on accounting, copywriting, design, and other professional services
- $59.72 on marketing, evangelism, and community outreach
## 2018 budget & finances
In addition to our usual monthly report, we’re including a yearly financial report. In 2018, we took in $300,183.32, we spent $266,900.32, and we paid for 1,394 hours of developer work on Ruby open source. By detail, we spent:
- $53,079.93 for 353.7 hours worked on Bundler at $150/hour
- $24,748.08 for 165.5 hours worked on RubyGems.org at $150/hour
- $52,832.59 for 352.6 hours worked on RubyGems at $150/hour
- $31,640.2 for 211 hours worked on other OSS and devtools at $150/hour
- $18,551 for 123.7 hours worked on The Ruby Toolbox at $150/hour
- $955.17 on dedicated servers for RubyBench.org
- $7,228.13 on payment processing fees
- $36,150.27 on company overhead like hosting, services, software, hardware, taxes, etc
- $28,110.64 on accounting, copywriting, design, and other professional services
- $13,517.71 on marketing, evangelism, and community outreach
On top of summing up our monthly reports, this report includes year-end compensation figures for all officers of the company and members of the board. These figures have always been available to the public in Ruby Together’s tax returns, but we’re including them here to increase visibility for everyone. Company officer and director compensation during 2018 included:
- André Arko (January-July), $0 for work as a board member, $0 for work as chief executive officer, and $22,050 for work on Ruby open source software
- André Arko (August-December), $26,458.33 for work as executive director, and $0 for work on Ruby open source software
- Adarsh Pandit, $0 for work as a board member
- Allison Sheren McMillan, $0 for work as a board member
- Courteney Ervin, $0 for work as a board member
- Coraline Ada Ehmke, $0 for work as a board member
- Joel Watson, $0 for work as a board member
- Jonan Scheffler, $0 for work as a board member
- Valerie Woolard Srinivasan, $0 for work as a board member
We’re running somewhat behind from the holidays, but we’re working to catch up—keep an eye out for the January monthly update soon.
Until next time,
Stephanie, André and the Ruby Together team
### Announcing Project Proposals
URL: https://rubycentral.org/news/announcing-project-proposals/
Last updated: 2022-11-28T23:39:43.000Z
### Announcing open project proposals
This update doesn’t fit exactly into our regular monthly news cycle, but we are excited to announce [project proposals](https://rubycentral.org/projects).
Ruby Together is now accepting proposals for funded work on Ruby open source projects. Projects are expected to take between 20 and 200 hours, over three months. Proposals are now permanently open, and new projects will be selected for funding once per quarter. Selected projects and progress on those projects will be included in our [regular monthly updates](https://rubytogether.org/news/?ref=rubycentral.org).
You don’t need to have prior open source development experience to propose a project, and you can live anywhere in the world. The project selection committee will choose which projects to fund based on our existing budget, and Ruby Together will fund development work on chosen projects for three months.
Applications are open now. [Apply today](https://rubycentral.org/projects)!
### November 2018 Monthly Update
URL: https://rubycentral.org/news/november-2018-monthly-update/
Last updated: 2022-11-28T23:39:43.000Z
Hello! Welcome to the monthly update—and the last update we’re publishing in 2018\. During November, our work was supported by [Handshake](https://handshake.org/?ref=rubycentral.org), [Stripe](https://stripe.com/?ref=rubycentral.org), [Triplebyte](https://triplebyte.com/os/rubytogether?ref=rubycentral.org), [GitLab](https://about.gitlab.com/?ref=rubycentral.org), and many others.
## ruby together news
The Ruby Together team flew out to Los Angeles for [RubyConf 2018](https://rubyconf.org/?ref=rubycentral.org), where we sponsored #RubyKaraoke (along with Engine Yard). At the conference, André, Adarsh, Jonan, and Valerie recorded a [special-edition Ruby Together episode](https://www.greaterthancode.com/2018/12/03/special-edition-ruby-together-live-from-rubyconf-2018/?ref=rubycentral.org) of [Greater Than Code](https://www.greaterthancode.com/?ref=rubycentral.org). The panel discussion covers restructuring the board, the launch of RubyMe, and our upcoming project funding applications. Give it a listen if you want to learn more!
In November, Ruby Together was supported by 67 different companies, including Ruby member [Handshake](https://handshake.org/?ref=rubycentral.org), and Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). In total, we were supported by 76 individual members and 64 friends of Ruby Together. Thanks to all of our members for making everything that we do possible.
## bundler news
This month, we [announced the upcoming Bundler 2.0 release](https://bundler.io/blog/2018/11/04/an-update-on-bundler-2.html?ref=rubycentral.org) and shipped a few prerelease versions. As mentioned in the blog post, Bundler 2 will drop support for Ruby versions that are no longer supported by the Ruby core team.
If you’re feeling adventurous, you can even try the Bundler 2 prerelease by running `gem install bundler --pre`. (You can even use the Bundler 2 prerelease on Heroku, with the [Bundler 2 buildpack](https://github.com/bundler/heroku-buildpack-bundler2?ref=rubycentral.org)!).
For the less adventurous, we’re writing documentation furiously, and we will post a full Bundler 2 upgrade guide along with the final 2.0.0 release.
This month, Bundler gained 44 new commits, contributed by 10 authors. There were 331 additions and 150 deletions across 51 files.
## rubygems.org news
In November, we updated 19 dependencies on RubyGems.org including security updates to rack and activejob. Thanks to a report that came in from HackerOne, we fixed a bug that would allow an attacker to guess an `api_key` by sending all of their guesses as an array along with the request. We also fixed some other issues reported through HackerOne, including rate limits on forgotten password requests, and profile pages being viewable after logout using the browser back button. We also removed the only use of IFrames (GitHub stars), and updated our CSP. Finally, we now have better Dutch translations thanks to [@sharkwouter](https://github.com/sharkwouter?ref=rubycentral.org), a first time contributor to RubyGems.org.
This month, RubyGems.org gained 37 commits from 6 authors, making changes to 60 files with 1,796 insertions and 1,038 deletions.
## rubygems news
RubyGems saw a lot of cleanup and bugfixes this month. We also merged [@ecnelises](https://github.com/ecnelises?ref=rubycentral.org)’s Google Summer of Code Project, which adds support for two-factor authentication to RubyGems.org. 2FA is a huge boost to account security, and once we have everything released and working, we’ll encourage everyone to turn it on. In total, RubyGems gained 125 new commits, contributed by 12 authors. There were 1,532 additions and 1,500 deletions across 268 files.
## gemstash news
In November, Gemstash version 2.0.0 shipped! It contained updated dependencies, bugfixes, and sets the stage for adding support for the new compact index format, which is our next goal. Overall, Gemstash gained 22 new commits, contributed by 2 authors. There were 450 additions and 130 deletions across 106 files.
## ruby toolbox news
Hey everyone,
In November, I ran a community survey in preparation for working on the Ruby Toolbox full time for the months of December and January.
The [results of the survey are now published](https://www.ruby-toolbox.com/blog/2018-12-04/survey-results?ref=rubycentral.org) and with the community’s opinion in mind I will work on corresponding improvements to the Toolbox in the next few weeks. I have also set up [a Ruby Toolbox community chat room on Gitter](https://gitter.im/rubytoolbox/Lobby?ref=rubycentral.org). I’ll be reliably available for chat in December and January so please stop by and say hi!
As always, your feedback is very welcome. If you have any suggestions or thoughts you’d like to share you can do so via [GitHub issues](https://github.com/rubytoolbox/rubytoolbox/issues?ref=rubycentral.org) or by getting in touch with me directly.
Thank you also to the PR contributors of November: SeyZ, geraldb, mreinsch, santhanakarthikeyan, and szTheory
Best, Christoph
## budget & expenses
In November, we saw $13,965 in total income, and spent a total of $24,409.55.
- $4,156.25 for 27.7 hours worked on Bundler at $150/hour
- $4,125 for 27.5 hours worked on RubyGems.org at $150/hour
- $5,210.62 for 34.7 hours worked on RubyGems at $150/hour
- $2,680.62 for 17.9 hours worked on other OSS and devtools at $150/hour
- $76.90 on dedicated servers for RubyBench.org
- $470.31 on payment processing fees
- $2,270.82 on company overhead like hosting, services, software, hardware, taxes, etc
- $1,682.50 on accounting, copywriting, design, and other professional services
- $3,736.52 on marketing, evangelism, and community outreach
Until 2019,
Stephanie, André and the Ruby Together team
### October 2018 Monthly Update
URL: https://rubycentral.org/news/october-2018-monthly-update/
Last updated: 2022-11-28T23:39:43.000Z
Hello! Welcome to the monthly update. During October, our work was supported by [Handshake](https://handshake.org/?ref=rubycentral.org), [Stripe](https://stripe.com/?ref=rubycentral.org), [DigitalOcean](https://www.digitalocean.com/?ref=rubycentral.org), [GitLab](https://about.gitlab.com/?ref=rubycentral.org), and many others.
## ruby together news
In October, Ruby Together was supported by 72 different companies, including Ruby member [Handshake](https://handshake.org/?ref=rubycentral.org) and Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). Three new developers signed up as members or friends of Ruby Together. In total, we were supported by 74 individual members and 68 friends of Ruby Together. Thanks to all of our members for making everything that we do possible!
On the events front, our developer evangelist PJ Hagerty spoke to audiences at [Little Rock Tech Fest](http://www.lrtechfest.com/?ref=rubycentral.org) and [GOTO:Berlin](https://gotober.com/?ref=rubycentral.org). Sam Giddins attended the [Google Summer of Code Mentor Summit](https://wiki.osgeo.org/wiki/Google%5FSummer%5Fof%5FCode%5F2018%5FMentor%5FSummit?ref=rubycentral.org), and Stephanie Morillo delivered a talk on content strategy in open source development at [All Things Open](https://allthingsopen.org/?ref=rubycentral.org).
At the [monthly board meeting](https://github.com/rubytogether/board/blob/main/meetings/2018-10-16-board-meeting.md?ref=rubycentral.org), the directors gave final approval to open applications for OSS project proposals to fund, approved a DevRel position job description, and agreed to sponsor Ruby Karaoke at RubyConf.
If you’ll be at RubyConf in LA next week, the board would love to meet with you to hear your feedback and talk about Ruby Together. Just [let us know](hello@rubytogether.org). <3
## bundler news
[We released Bundler 1.17](https://bundler.io/blog/2018/10/25/announcing-bundler-1-17-0.html?ref=rubycentral.org), which ships a new `remove` command (for removing gems from the command line), new command options, new events for Bundler plugins, and new environment variables. For a complete list of changes, check out the [v1.17 release notes](https://bundler.io/v1.17/whats%5Fnew.html?ref=rubycentral.org).
We also announced our [new plan for Bundler 2.0](https://bundler.io/blog/2018/11/04/an-update-on-bundler-2.html?ref=rubycentral.org), a new approach that we think the Bundler team and Bundler users will both be excited about. We’re planning to write more blog posts and documentation about Bundler 2, and push a prerelease preview for interested beta testers in the next week or two.
This month, Bundler gained 107 new commits, contributed by 10 authors. There were 473 additions and 156 deletions across 35 files.
## rubygems.org news
In October, we updated 23 dependencies, including the update to Rails 5.2 (thanks [@thomasdziedzic](https://github.com/thomasdziedzic?ref=rubycentral.org)) and a security update to loofah. Thanks to [@fwilkens](https://github.com/fwilkens?ref=rubycentral.org), we added a new endpoint to our API which can be used to [query for gem updates within a given time range](https://guides.rubygems.org/rubygems-org-api/?ref=rubycentral.org#get---apiv1timeframe%5Fversionsjson). We also merged improvements to the French and Chinese translations of our site.
Early in October, we had to disable the endpoint that powers the reverse dependencies list on the website, because it was interfering with the stability of the rest of the site. We sincerely apologize for any inconvenience. We’ve since done significant work to improve that endpoint’s performance, and it is back online. Unfortunately, this meant, we had to say goodbye to one of our beloved libraries, will\_paginate, which we [replaced with kaminari](https://github.com/rubygems/rubygems.org/pull/1807?ref=rubycentral.org).
We also undertook some refactoring work to improve our Code Climate score and we are happy to report that our maintainability score is an A!
This month, RubyGems.org gained 55 commits from 7 authors, making changes to 72 files with 342 insertions and 1226 deletions.
## rubygems news
RubyGems changes this month included removing insecure DNS lookups on gem servers (thanks [@arlandism](https://github.com/arlandism?ref=rubycentral.org)!), fixed an issue where RubyGems might load files from a different copy of RubyGems on disk (thanks [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org)), and did ongoing administration and maintenance. We also merged in changes from ruby-core, improving compatibility with the upcoming Ruby 2.6.
This month, RubyGems gained 49 new commits, contributed by 11 authors. There were 747 additions and 604 deletions across 73 files.
## gemstash news
Gemstash saw a few bug fixes this month, including a fix to prevent overriding a published gem. This month, Gemstash gained 9 new commits, contributed by 3 authors. There were 71 additions and 4 deletions across 7 files.
## ruby toolbox
Hey everyone,
With freelance projects winding down in November, the Ruby Toolbox will be my main focus for December and January. Over the next two months, I will work on new features and improvements on the Ruby Toolbox. You can also check out the [related announcement on the Toolbox blog](https://www.ruby-toolbox.com/blog/2018-11-05/community-survey?ref=rubycentral.org).
In order to be able to focus on what is relevant to you, the community, I have set up a survey to gather your feedback. If you have a couple minutes to spare it would be wonderful if you could leave your thoughts on what you’d like to see over at the [Ruby Toolbox 2018 Community Survey](https://survey-2018.ruby-toolbox.com/?ref=rubycentral.org). Thanks a lot for your time!
If you are interested in contributing to the Ruby Toolbox, December and January will also be a great time to get started as I’ll be available on a regular basis for replying to any questions you have or ideas you’d like to discuss. I will set up a project chat room for this; please keep an eye on the [Toolbox blog](https://www.ruby-toolbox.com/blog?ref=rubycentral.org) for announcements.
Because of this, I’m delaying planned improvements of the search I mentioned in the last update so I can spend some consecutive time on that and also incorporate any feedback that might come from the community survey. Those improvements will remain on the roadmap, with work to commence sometime next year.
As always, your feedback is very welcome, if you have any suggestions or thoughts you’d like to share you can do so via [GitHub issues](https://github.com/rubytoolbox/rubytoolbox/issues?ref=rubycentral.org) or by getting in touch with me directly.
Thank you also to the PR contributors of October: HotFusionMan, alsemyonov, cybcafe, and go2null.
Best, Christoph
## budget & expenses
In September, we saw $14,165 in total income, and spent a total of $24,891.08.
- $3,925 for 26.2 hours worked on Bundler at $150/hour
- $3,106.25 for 20.7 hours worked on RubyGems.org at $150/hour
- $5,218.12 for 34.8 hours worked on RubyGems at $150/hour
- $2,633.12 for 17.6 hours worked on other OSS and devtools at $150/hour
- $2,662.50 for 17.8 hours worked on The Ruby Toolbox at $150/hour
- $78.06 on dedicated servers for RubyBench.org
- $481.34 on payment processing fees
- $3,156.68 on company overhead like hosting, services, software, hardware, taxes, etc
- $1,945 on accounting, copywriting, design, and other professional services
- $1,685 on marketing, evangelism, and community outreach
Until next time,
Stephanie, André and the Ruby Together team
### September 2018 Monthly Update
URL: https://rubycentral.org/news/september-2018-monthly-update/
Last updated: 2022-11-28T23:39:43.000Z
Hello! Welcome to the monthly update. During September, our work was supported by [Handshake](https://handshake.org/?ref=rubycentral.org), [Stripe](https://stripe.com/?ref=rubycentral.org), [Coinbase](https://coinbase.com/?ref=rubycentral.org), [Triplebyte](https://triplebyte.com/os/rubytogether?ref=rubycentral.org), [Bleacher Report](http://www.bleacherreport.com/?ref=rubycentral.org), and many others.
## ruby together news
In September, Ruby Together was supported by 73 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). [Triplebyte](https://triplebyte.com/os/rubytogether?ref=rubycentral.org) joined as our newest Emerald member.
In addition, eight new developers signed up as members or friends of Ruby Together, including Rafael França. In total, we were supported by 77 individual members and 69 friends of Ruby Together. Thanks to all of our members for making everything that we do possible.
As mentioned last month, we solicited suggestions or applications to run in the yearly election for the Ruby Together board of directors. This year, the only candidate was our existing board member, Adarsh Pandit. Since there was only one candidate, and one board seat up for election, the remaining directors chose to skip the voting period this year. If you’re interested in nominating someone for the board of directors next year, or even running yourself, we’d love to hear from you! Reach out to us at hello@rubytogether.org and we can give you more information.
### ruby me
Earlier this month, we announced a new, paid mentorship program called [Ruby Me](http://www.rubyme.org/?ref=rubycentral.org). Designed and planned by board member Coraline Ada Ehmke, Ruby Me pairs early-career developers with seasoned Rubyists to work on open source projects for three months. Both mentees and mentors are compensated for 8 hours of work per month. The goal of Ruby Me is to help bring people from underrepresented backgrounds into open source and support them in their professional growth.
We saw an overwhelmingly positive response come from the wider community. In one week, we received over 900 applications from prospective apprentices and over 125 applications from prospective mentors. It was incredibly difficult, but we selected the participants for our first batch and sent out notification emails on October 1\. The selected teams will work together until January 2019, and we’ll be sure to report back on how things went.
We plan to open applications for Spring 2019 around the middle of December. If you’d like to get an email right away when we next open applications for Ruby Me, visit [rubyme.org](https://rubyme.org/?ref=rubycentral.org) and sign up to be notified at the bottom of the page.
### events
Coraline Ada Ehmke and Kerri Miller gave talks at CodeDaze in Buffalo, NY earlier in September, and PJ Hagerty visited Northeast PHP in Boston.
## bundler news
The Bundler team merged 29 pull requests, including fixes for nested `bundle exec`, various bugs around choosing and updating gem versions, documentation improvements, and full compatibility with TruffleRuby. We also released versions 1.16.5 and 1.17.0.pre.
We also decided how to drop backwards compatibility with old Ruby versions, allowing us to resume work to merge Bundler into Ruby 2.6\. We may or may not complete everything in time for the Ruby 2.6 release at Christmas, but we’re still working towards it!
In September, Bundler gained 73 new commits, contributed by 12 authors. There were 419 additions and 151 deletions across 40 files.
## rubygems.org news
This month, we updated seven dependencies on rubygems.org and simplified and sped up some rack-attack integration tests with the help of [@mjankowski](https://github.com/mjankowski?ref=rubycentral.org). We also discovered that it was possible to create “hidden” gems that would not show up in gem lists, and [@kerrizor](https://github.com/kerrizor?ref=rubycentral.org) implemented a fix. Overall, rubygems.org got 15 commits from 2 authors making 146 additions and 263 deletions across 8 files.
## rubygems news
This month, RubyGems merged 12 pull requests, including downloading multiple gems in parallel during `install`, setting up a new mergebot, and adding a `--resign` flag to the `cert` command. There were 26 new commits, contributed by 6 authors, with 251 additions and 163 deletions across 28 files.
## ruby toolbox
Hey everyone,
I set aside some time in September to ship the production database exports I’ve mentioned in recent updates.
You can [find the release announcement and more in this on the Ruby Toolbox blog post](https://www.ruby-toolbox.com/blog/2018-09-30/database-exports?ref=rubycentral.org). If you’d like to run some stats against the Toolbox data set, or if you’d like to get a local data set for development and contributing, this should be very helpful. You can find the exports at [data.ruby-toolbox.com](https://data.ruby-toolbox.com/?ref=rubycentral.org).
I also spent a bit of time on general maintenance, like upgrading the production database to Postgres 10 or [fixing a bug](https://github.com/rubytoolbox/rubytoolbox/pull/294?ref=rubycentral.org) that prevented gems with only pre-release versions available on rubygems.org from being indexed on the Toolbox.
Getting the database dump export process ready with all the [goals](https://github.com/rubytoolbox/backup%5Fpublisher?ref=rubycentral.org#goals) I had for it took a bit more time than I had hoped, so I didn’t get around to work on [the improvements to the search](https://github.com/rubytoolbox/rubytoolbox/issues/109?ref=rubycentral.org) I also mentioned in the last update; I will work on it in October.
As always, your feedback is very welcome! If you have any suggestions or thoughts you’d like to share you can do so via [GitHub issues](https://github.com/rubytoolbox/rubytoolbox/issues?ref=rubycentral.org) or by getting in touch with me directly.
Thank you also to the contributors who submitted PRs in September: gettalong and matkoniecz.
Best, Christoph
## budget & expenses
In September, we saw $14,630 in total income, and spent a total of $21,480.11.
- $5,539.38 for 36.9 hours worked on Bundler at $150/hour
- $687.50 for 4.6 hours worked on RubyGems.org at $150/hour
- $5,673.12 for 37.8 hours worked on RubyGems at $150/hour
- $2,975 for 19.8 hours worked on other OSS and devtools at $150/hour
- $275 for 1.8 hours worked on The Ruby Toolbox at $150/hour
- $77.80 on dedicated servers for RubyBench.org
- $492.31 on payment processing fees
- $1,853.88 on company overhead like hosting, services, software, hardware, taxes, etc
- $1,820 on accounting, copywriting, design, and other professional services
- $2,086.12 on marketing, evangelism, and community outreach
Until next time,
Stephanie, André and the Ruby Together team
### Announcing Ruby Me
URL: https://rubycentral.org/news/announcing-ruby-me/
Last updated: 2022-11-28T23:39:43.000Z
A paid mentorship program for early-career Ruby developers.
Ruby Together is extremely excited to announce a new program, designed by Coraline Ada Ehmke: [Ruby Me](https://rubyme.org/?ref=rubycentral.org).
The mission of the RubyMe program is to help early-career developers improve their skills and confidence by contributing to Ruby open source projects, by paying them to pair on open source software for 8 hours per month. Through this program we hope to give these developers the skills and experience that they need for continued growth and success in their careers.
Early-career developers (with a firm grasp of Ruby fundamentals) can apply for a spot in the three-month long program. If you’re a recent bootcamp grad, career switcher, or developer employed at the junior level, we’re looking for you.
Once selected, apprentices will be matched with an experienced Ruby developer. Together, they’ll choose an open source project to work on, and a goal to work towards during the three-month program.
Mentors and apprentices will meet and work together up to 8 hours every month, including documenting and sharing the results of their work. Each mentor and apprentice will be paid USD $75 per hour for their work.
We are accepting a limited number of applications for the pilot program that will run October through December of this year, and then open up for a new and larger cohort in January of 2019.
Learn more or apply today to participate as an apprentice or a mentor at [rubyme.org](https://rubyme.org/?ref=rubycentral.org).
### August 2018 Monthly Update
URL: https://rubycentral.org/news/august-2018-monthly-update/
Last updated: 2022-11-28T23:39:43.000Z
Hello! Welcome to the monthly update. During August, our work was supported by [Handshake](https://handshake.org/?ref=rubycentral.org), [Stripe](https://stripe.com/?ref=rubycentral.org), [Coinbase](https://coinbase.com/?ref=rubycentral.org), [reinteractive](https://reinteractive.com/?ref=rubycentral.org), [Airbnb](http://airbnb.com/?ref=rubycentral.org), and many others.
## ruby together news
In August, Ruby Together was supported by 75 different companies, including our newest Ruby-level member, [Handshake](https://www.handshake.org/?ref=rubycentral.org). Thanks so much for the incredible support! We were also supported by 77 individual members and 64 friends of Ruby Together. Thanks to all 75 companies and 141 individuals for making everything that we do possible.
### board nominations
It’s almost time for our yearly election to choose directors! Each year, one third of the seats on the board are up for election. This year, the seat currently held by Adarsh Pandit is up for election. Is there a member of Ruby Together you would want to represent you on the board of directors? Would you like to run for the board yourself? You have one week to [nominate a member or apply to run](https://goo.gl/forms/lshnSf7r0n1ruIpR2?ref=rubycentral.org).
### events
In community events, our developer evangelist PJ Hagerty spent some time at the Google Developer Group meetup in New York City, Scenic City Summit in Chattanooga, TN, and AmsterdamRB. Executive Director André Arko went to RailsCamp, experiencing the outdoors and talking with other developers about Ruby Together.
### summer of code
As scheduled, our Google Summer of Code students wrapped up their work on our various projects. Special thanks to our GSoC developers for all of their hard work these past few months! Check out the work done by those students in their final write-ups:
- Qiu Chaufan, [Adding multi-factor authentication to RubyGems](https://gist.github.com/ecnelises/9654e59877aa336977c1409ef540e2a9?ref=rubycentral.org)
- Shlok Srivastava, [Add security vulnerability notifications in rubygems](https://lifeinoss.wordpress.com/2018/08/14/gsoc-with-rubygems/?ref=rubycentral.org)
- Nicholas Yang, [Adding Type Annotations to Ruby Syntax](https://summerofcode.withgoogle.com/projects/?ref=rubycentral.org#6181205100199936)
- Yimin Zhao, [Ruby on a huge memory machine](https://github.com/Tacinight/ruby-gsoc-2018/blob/master/README.md?ref=rubycentral.org#ruby-gsoc-2018)
- Agrim Mittal, [Integrate functionality from bun](https://gist.github.com/agrim123/cfc1e1aadbe8b46f6e2b6e9b090ed2f3?ref=rubycentral.org#integrating-functionality-from-bun-into-bundler-gsoc-2018)
### reorganization for the long run
It’s hard to believe, but Ruby Together is more than three years old. In that time, we’ve grown from funding just 2 devs working 10 hours per week, to funding up to 50 hours per week when it’s needed to keep Ruby’s gem infrastructure running smoothly.
As you can probably imagine, it takes a lot more to organize ten developers than it took to organize two. Because of that, we’re making some changes to how Ruby Together is structured to make sure all of that work continues to get done.
Starting this month, we’re retiring our existing position of CEO, and replacing it with an Executive Director position. While it includes many of the previous responsibilities of the CEO, the ED position comes with a new job description, new criteria for success, and direct oversight by the board of directors.
The Executive Director will not be a member of the Board of Directors, and will not determine budgets or spending. Instead, they will be responsible for running Ruby Together on a day to day basis, implementing the strategy and plans decided on by the board.
The Executive Director will be paid for administrative and corporate work. They will not be paid for any open source work. This will allow them to focus their efforts on fundraising and collaboration with the Ruby community. Our first Executive Director will be André Arko.
Along with the new ED position, we’re resetting the size of the board of directors to 5 people. No one is being added or removed from the board to make that happen, but that size will keep our core working group in the 5-7 person range. Keeping the core working group small and focused is especially important for our scheduling, discussion, and decision-making, and the board was in unanimous agreement that the new size will improve our work.
We’re excited to enter a new phase as a “grown up” non-profit, and we’re looking forward to being able to support the Ruby open source community for years to come. 💎💝
## bundler news
With the help of [@eanlain](http://github.com/eanlain?ref=rubycentral.org), we shipped a new guide: [“How to use Bundler with Docker”](https://bundler.io/v1.16/guides/bundler%5Fdocker%5Fguide.html?ref=rubycentral.org). We also dramatically improved error messages when version requirements conflict, shipped a playbook for adding or removing core team members, and fixed some issues handling gemspecs with non-ASCII characters. We also merged a fix that could cause Bundler to [fail when trying to install a gem that has had a version yanked recently](https://github.com/bundler/bundler/pull/6675?ref=rubycentral.org).
On top of that code work, we also added two new contributors to [the Bundler team](https://bundler.io/contributors.html?ref=rubycentral.org)! Welcome to [Stephanie Morillo](https://www.twitter.com/radiomorillo?ref=rubycentral.org) and [Grey Baker](https://twitter.com/greybaker?ref=rubycentral.org).
Stephanie has helped create new Bundler docs (like the troubleshooting RubyGems and Bundler TLS/SSL issues guide), and update existing ones. She’s also responsible for updating the Bundler contributor guidelines and trying to make Bundler docs more accessible to new contributors. We’re excited to have her on board, and looking forward to working with her more in the future.
Grey is the author of [Dependabot](https://dependabot.com/?ref=rubycentral.org), and has regularly contributed to [Molinillo](https://github.com/cocoapods/molinillo?ref=rubycentral.org), the core resolver library that powers Bundler, RubyGems, and Cocoapods.
In total this month, Bundler gained 58 new commits, contributed by 10 authors. There were 334 additions and 54 deletions across 30 files.
## rubygems.org news
In August, we blacklisted several gems with names that were close to other popular gems, in response to CVE-2018-3779\. We’re starting to investigate ways to protect RubyGems.org from malicious gems—if you’re interested in helping work on that, let us know! We also reviewed and merged performance improvements to the “rubygems#show” and “version#index” pages, contributed by [@nateberkopec](https://github.com/nateberkopec?ref=rubycentral.org).
In total, RubyGems.org gained 11 commits from 5 authors, making 44 additions and 35 deletions across 8 files.
## rubygems news
In RubyGems, we fixed some bugs, including the ability to [auto re-sign expired certs](https://github.com/rubygems/rubygems/pull/2380?ref=rubycentral.org), fixed some tests, and made sure that gems with `allowed_push_host` set will be pushed to the correct host by `gem push`. In total there were 19 new commits, contributed by 5 authors, with 112 additions and 26 deletions across 13 files.
## ruby toolbox news
Hey everyone,
Despite my ambitious announcements in the last update, August turned out to be a quiet month for me. I was mostly on vacation visiting family, and while I had hoped to use the available time to also build a bunch of nice stuff for the Toolbox, the need to find some rest and to have a bunch of time with family and away from computers won in the end.
However, I’ll finally have the time to ship the public data dumps and search improvements in September I spoke about in recent updates!
In other news, towards the end of August I was in Vienna for the 2018 edition of Euruko, the European Ruby Conference. I’d like to say a big thank you to everyone involved, I think it was a great weekend and a powerful display of the health of our community. Can’t wait for next year!
As always, your feedback is very welcome, if you have any suggestions or thoughts you’d like to share you can do so via [GitHub issues](https://github.com/rubytoolbox/rubytoolbox/issues?ref=rubycentral.org) or by getting in touch with me directly.
Thank you also to the contributor of our sole pull request in August: jrochkind (it seems there were more folks on vacation).
Best, Christoph
## budget & expenses
In August, we saw $113,945 in total income, and spent a total of $20,988.71.
- $5,843.54 for 39.0 hours worked on Bundler at $150/hour
- $1,222.71 for 8.2 hours worked on RubyGems.org at $150/hour
- $5,613.12 for 37.4 hours worked on RubyGems at $150/hour
- $2,866.46 for 19.1 hours worked on other OSS and devtools at $150/hour
- $1,312.50 for 8.8 hours worked on The Ruby Toolbox at $150/hour
- $78.21 on dedicated servers for RubyBench.org
- $472.96 on payment processing fees
- $1,734.21 on company overhead like hosting, services, software, hardware, taxes, etc
- $1,795 on accounting, copywriting, design, and other professional services
- $50 on marketing, evangelism, and community outreach
Until next time,
Stephanie, André and the Ruby Together team
### July 2018 Monthly Update
URL: https://rubycentral.org/news/july-2018-monthly-update/
Last updated: 2022-11-28T23:39:41.000Z
Hello! Welcome to the monthly update. During July, our work was supported by [Coinbase](https://coinbase.com/?ref=rubycentral.org), [Cloud City Development](http://www.cloudcity.io/?ref=rubycentral.org), [reinteractive](https://reinteractive.com/?ref=rubycentral.org), and many others.
## ruby together news
In July, Ruby Together was supported by 74 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). In total, we were supported by 79 individual members and 66 friends of Ruby Together. Thanks to all of our members for making everything that we do possible!
The Ruby Together Board of Directors met, and was able to finalize and ratify a plan for a new Ruby open source mentorship program called RubyMe–stay tuned for an official announcement with more details!
In community news, Developer Evangelist [PJ Hagerty](https://twitter.com/aspleenic?ref=rubycentral.org) continued to spread the word about Ruby Together at RubyConf Kenya. Our Google Summer of Code (GSoC) students made progress on the `bundle change` feature, and they also worked on a comment that rewrites a Gemfile into a canonical form. And [Kerri Miller](https://twitter.com/kerrizor?ref=rubycentral.org) addressed outstanding issues in the RubyGems and RubyGems.org support queues.
## bundler news
We released Bundler 1.16.3 on July 17\. The new release includes support for the upcoming Ruby 2.6, and fixes several bugs including symlink handling, temporary file handling, and improving error messages around filesystem access and installation errors.
Since we announced the new RFC process last month, we’ve seen new comments and new proposals in the [Bundler RFC repo](https://github.com/bundler/rfcs/pulls?ref=rubycentral.org). If you’re interested in ideas for the future of Bundler, definitely take a look. Keep the comments and suggestions coming!
In other exciting news, we added a new contributor to the core team. Welcome [David Rodríguez](https://github.com/deivid-rodriguez?ref=rubycentral.org) to Bundler! :tada: Probably best known for his work on the `byebug` debugger gem, David was the driver behind updating gem templates to check in lockfiles, as well as work around ensuring that Bundler 2 will work on existing applications when it is released.
This month, Bundler gained 63 new commits, contributed by 8 authors. There were 1,442 additions and 72 deletions across 33 files.
## rubygems.org news
In July, we updated 15 dependencies in RubyGems.org, and we released the alpha version of [two-factor authentication](https://github.com/rubygems/rubygems.org/pull/1729?ref=rubycentral.org) for logging into the website. If you’d like to try it now, enable it by running `document.cookie='mfa_feature=true;path=/'` in your browser console. We’re working on adding support for multiple factors to the CLI as well, and you should see more updates on it next month.
We also fixed a few small bugs around the dashboard and Atom feeds for users who are logged out.
This month, RubyGems.org gained 38 commits from 4 authors, making 1,124 additions and 183 deletions across 84 files.
## rubygems news
RubyGems saw better symlink handling, some improved warning messages, and better testing on windows. We also made the flags for the `pristine` and `cleanup` commands more consistent with the existing `install` command, and did some code cleanup. Finally, we imported some fixes from ruby-core to make sure RubyGems continues to work when OpenSSL is not available in Ruby.
This month, RubyGems gained 70 new commits, contributed by 9 authors. There were 429 additions and 186 deletions across 41 files.
## ruby toolbox news
Hey everyone,
Last month I did some maintenance work by [upgrading to Rails 5.2](https://github.com/rubytoolbox/rubytoolbox/pull/214?ref=rubycentral.org) and addressing some common issues found when [syncing data from GitHub](https://github.com/rubytoolbox/rubytoolbox/pull/246?ref=rubycentral.org).
In order to reduce errors stemming from fetching old projects multiple times, I added logic to ignore old GitHub references from gems for 14 days to allow us to unblock them if they reappear. Currently, this affects approximately 11,000 projects (note that renaming owners and moved ownership should redirect properly to the new location). In the future, it might make sense to indicate this in the UI for said projects somehow since these libraries seem to be unmaintained, but we’ll see!
I also began work on the public database dumps I mentioned last month. They are not quite ready yet, but I expect to ship them in the next few weeks, allowing you to also look at the mentioned gone repo numbers yourself in more detail.
Once the database dumps are complete, I want to do some further syncing efficiency maintenance and work on the search improvements I already mentioned in the last update.
As always, your feedback is very welcome. If you have any suggestions or thoughts you’d like to share you can do so via [GitHub issues](https://github.com/rubytoolbox/rubytoolbox/issues?ref=rubycentral.org) or by getting in touch with me directly.
Thank you also to everyone who contributed pull requests in July: koflerm, paneq, spape, and splashinn.
Best, Christoph
## budget & expenses
In July, we saw $15,375 in total income, and spent a total of $17,006.02.
- $3,516.88 for 23.4 hours worked on Bundler at $150/hour
- $1,095 for 7.3 hours worked on RubyGems.org at $150/hour
- $4,543.12 for 30.3 hours worked on RubyGems at $150/hour
- $2,370 for 15.8 hours worked on other OSS and devtools at $150/hour
- $2,001 for 13.3 hours worked on The Ruby Toolbox at $150/hour
- $78.28 on dedicated servers for RubyBench.org
- $493.64 on payment processing fees
- $1,475.60 on company overhead like hosting, services, software, hardware, taxes, etc
- $1,282.50 on accounting, copywriting, design, and other professional services
- $150 on marketing, evangelism, and community outreach
Until next time,
Stephanie, André and the Ruby Together team
### June 2018 Monthly Update
URL: https://rubycentral.org/news/june-2018-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello! Welcome to the monthly update. During June, our work was supported by [Stripe](https://stripe.com/?ref=rubycentral.org), [Coinbase](https://coinbase.com/?ref=rubycentral.org), [Airbnb](http://airbnb.com/?ref=rubycentral.org), and many others.
## ruby together news
In June, Ruby Together was supported by 74 different companies. Two new developers signed up as members or friends of Ruby Together. In total, we were supported by 82 individual members and 66 friends of Ruby Together.
Developer evangelist [PJ Hagerty](http://twitter.com/aspleenic?ref=rubycentral.org) visited a number of conferences and meetups in June, including BostonRB, Texas Linux Fest, and RubyConf Kenya.
As promised, we also published the results from our [June 23 board meeting](https://github.com/rubytogether/board/blob/master/meetings/2018-06-23.md?ref=rubycentral.org). We made some great progress, and expect to be able to announce the new projects that we’re working on within the next month or two.
## bundler news
Last month, we fixed some bugs and our Google Summer of Code (GSoC) students finished work on the `bundle remove` feature. We also created a [checklist for the Bundler 2 release](https://github.com/bundler/bundler/issues/6582?ref=rubycentral.org), and finished documentation for the [Bundler release process](https://github.com/bundler/bundler/pull/5252?ref=rubycentral.org).
After that, we published a [public request for comments on the idea of Bundler release channels](https://github.com/bundler/rfcs/pull/12?ref=rubycentral.org). Just this week, we [learned a lot about how Docker and Bundler can work better together](https://github.com/bundler/bundler/pull/6524?ref=rubycentral.org).
This month, Bundler gained 63 new commits, contributed by 12 authors. There were 738 additions and 102 deletions across 48 files.
## rubygems.org news
In June, we updated over 25 dependencies, including nokogiri and the sprockets security release, and updated to Rails 5.1\. We also fixed a longstanding and frustrating issue where multiple CI builds pushing a new gem version at the same time could result in a checksum error when trying to install the new version. On June 27, we deprecated the “gem edit” page and it will be removed altogether on July 10.
Instead of editing gem metadata at rubygems.org, we recommend using the gem specification itself. Use `Gem::Specification#metadata` to setting links to a gem’s homepage, changelog, documentation, and other websites. This will help us reduce the complexity of rubygems.org by making `Gem::Specification#metadata` the single source of truth and it will also allow gem owners to set different URLs by version.
This month, rubygems.org saw 28 commits making 159 additions and 74 deletions across 29 files.
## rubygems news
RubyGems saw a lot of activity this month, with 29 merged pull requests. Changes included some support for the upcoming Ruby 2.7, test improvements, a fix for a leaking tempfile, better support for frozen string literals, and better support for case-insensitive file systems. We also added more deprecations for the upcoming 3.0 release, improved the way RubyGems interacts with Bundler 1.16.2 and the upcoming 2.0, and fixed some edge cases with stub gem specifications. We shipped most those changes by releasing RubyGems 2.7.7 on June 8.
After releasing 2.7.7, we merged several fixes for installing gems directly from an AWS S3 bucket source, improved some warning messages, and fixed issues activating gems when the same gem is installed for more than one platform at once.
In total, RubyGems gained 67 new commits, contributed by 12 authors. There were 439 additions and 62 deletions across 24 files.
## gemstash news
Gemstash saw a bug fix for health check race conditions last month. It gained 2 new commits, contributed by 2 authors. There were 11 additions and 3 deletions across 2 files.
## ruby toolbox
Hey everyone!
This month, I prepared the request-for-feedback PR for metric rankings I mentioned in the last update. If you have a minute, please [leave your suggestions in this PR](https://github.com/rubytoolbox/rubytoolbox/pull/233?ref=rubycentral.org). Additionally, there was some maintenance work, including gem updates and inbound catalog change reviews.
While the metric rankings are open for discussion in the PR, I want to set up automated database dumps available to download from the site in July. ([Refer to this issue](https://github.com/rubytoolbox/rubytoolbox/issues/73?ref=rubycentral.org) for more information.) This will serve two purposes: it makes it easier to get a reasonable local dataset for development, and it allows people interested in crunching some numbers easier access to the Toolbox dataset. I’d also [like to do some improvements to the search](https://github.com/rubytoolbox/rubytoolbox/issues/109?ref=rubycentral.org) that didn’t make it into the site for the original re-launch.
As always, your feedback is very welcome. If you have any suggestions or thoughts you’d like to share you can do so via [GitHub issues](https://github.com/rubytoolbox/rubytoolbox/issues?ref=rubycentral.org) or by getting in touch with me directly.
Thank you also to everyone who contributed pull requests in June: ch4mpignator, cvshepherd, danielwestendorf, enkessler, piotrmurach, samnissen, and splashinn
Best, Christoph
## budget & expenses
In June, we saw $15,465.00 in total income, and spent a total of $13,490.43.
- $1,722.50 for 11.5 hours worked on Bundler at $150/hour
- $1,102.50 for 7.4 hours worked on RubyGems.org at $150/hour
- $3,810 for 25.4 hours worked on RubyGems at $150/hour
- $2,177.50 for 14.5 hours worked on other OSS and devtools at $150/hour
- $78.69 on dedicated servers for RubyBench.org
- $519.78 on payment processing fees
- $1,718.96 on company overhead like hosting, services, software, hardware, taxes, etc
- $1,432.50 on accounting, copywriting, design, and other professional services
- $928 on marketing, evangelism, and community outreach
Until next time,
Stephanie, André and the Ruby Together team
### May 2018 Monthly Update
URL: https://rubycentral.org/news/may-2018-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello! Welcome to the monthly update. During May, our work was supported by [GitLab](https://about.gitlab.com/?ref=rubycentral.org), [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org), and many others.
## ruby together news
In May, Ruby Together was supported by 77 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). [Murb](https://murb.nl/?ref=rubycentral.org) and [StackPath](https://www.stackpath.com/?ref=rubycentral.org) joined as Onyx members, and developer Gregory Brown (@practicingdev) became a member.
We were supported by a total of 86 individual members and 68 friends of Ruby Together. Thanks to all of our members for making everything that we do possible.
In community events news, our developer evangelist [PJ Hagerty](http://twitter.com/aspleenic?ref=rubycentral.org) spoke at MalmoRB and Ruby Ireland, and visited CopenhagenRB among other Meetups.
Meanwhile, the Ruby Google Summer of Code projects made progress on a new `bundle remove` command, created mockups for adding two-factor authentication to RubyGems.org, and continued to implement gem security advisories.
## bundler news
In May, Bundler saw some bug fixes, a [new \--skip-install flag](https://github.com/bundler/bundler/commit/9e87a1ca4b0c3002ac2774e4837234cef7e3ce08?ref=rubycentral.org) for `bundler add`, and a [new guide on writing Bundler plugins](https://bundler.io/v1.16/guides/bundler%5Fplugins.html?ref=rubycentral.org). (Thank you [@jules2689](https://github.com/jules2689?ref=rubycentral.org) for producing this guide!)
Bundler gained 9 new commits, contributed by 3 authors. There were 66 additions and 48 deletions across 17 files.
## rubygems.org news
RubyGems.org saw 17 gem updates and performance improvements for the search page. In addition, we [revised the site footer](https://github.com/rubygems/rubygems.org/commit/8de0296d1222e9819ca3a70f678baca0484b99b1?ref=rubycentral.org) to better clarify how Ruby Central, Ruby Together, and Fastly work together on RubyGems.org.
This month, RubyGems.org gained 27 new commits, contributed by 7 authors. There were 218 additions and 215 deletions across 13 files.
## rubygems news
RubyGems saw several bug fixes, support for reproducible gem builds, a new command alias `i` for `install`, and for a pre-release of version 3\. It gained 25 new commits, contributed by 4 authors. There were 132 additions and 80 deletions across 21 files.
## gemstash news
Gemstash had a few minor fixes this month. It gained 9 new commits, contributed by 2 authors. There were 203 additions and 151 deletions across 36 files.
## ruby toolbox news
Hey everyone!
Like April, May turned out pretty busy for me so I had very limited time to spend on the Toolbox, but I did get around to doing some work on the global metrics rankings that I had written about in the previous updates. I’m currently trying to figure out how to display them best in an easy-to-understand manner—for example, gem download counts are distributed pretty unevenly, with the top 1% gems by downloads count being the reason for \~87% of all gem downloads—so it’s a bit tricky to display a fair and meaningful ranking for “all the other” projects. I expect to have a work-in-progress pull request on this available in the next week or two, so please keep an eye on [Ruby Toolbox’s PRs](https://github.com/rubytoolbox/rubytoolbox/pulls?ref=rubycentral.org) if you are interested in giving feedback on this!
As always, your feedback is very welcome, if you have any suggestions or thoughts you’d like to share you can do so via [GitHub issues](https://github.com/rubytoolbox/rubytoolbox/issues?ref=rubycentral.org) or by getting in touch with me directly.
Thank you also to everyone who contributed pull requests in May: TeamNautilus, diegobarna, oasic, plentz, skatkov, sunito, and tjwallace.
Best, Christoph
## budget & expenses
In May, we saw $15,950 in total income, and spent a total of $22,141.79.
- $3,153.75 for 21.0 hours worked on Bundler at $150/hour
- $720 for 4.8 hours worked on RubyGems.org at $150/hour
- $4,677.50 for 31.2 hours worked on RubyGems at $150/hour
- $2,456.25 for 16.4 hours worked on other OSS and devtools at $150/hour
- $79.39 on dedicated servers for RubyBench.org
- $536.51 on payment processing fees
- $3,008.58 on company overhead like hosting, services, software, hardware, taxes, etc
- $6,382.50 on accounting, copywriting, design, and other professional services
- $1,127.31 on marketing, evangelism, and community outreach
Until next time,
Stephanie, André and the Ruby Together team
### April 2018 Monthly Update
URL: https://rubycentral.org/news/april-2018-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello! Welcome to the monthly update. During April, we paid for 133.5 hours of developer work, supported by [Stripe](https://stripe.com/?ref=rubycentral.org), [Coinbase](https://coinbase.com/?ref=rubycentral.org), [reinteractive](https://reinteractive.com/?ref=rubycentral.org), [Airbnb](http://airbnb.com/?ref=rubycentral.org), and many others.
## ruby together news
It’s our birthday! 🎉🎂 As of this update, Ruby Together is officially 3 years old. Thanks for all of your help and support along the way.
In April, Ruby Together was supported by 80 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). 6 companies joined as new members, including [Piece of Code](http://www.pieceofcode.com/?ref=rubycentral.org) and [Coinbase](https://www.coinbase.com/?ref=rubycentral.org).
On top of those companies, 6 new developers signed up as members or friends of Ruby Together, including Tom Johnson, Pat Allan, Jameson Hampton, and Jeremy Flores. In total, we were supported by 92 individual members and 71 friends of Ruby Together. Thanks to all of our members for making everything that we do possible. <3
### new devs
[Luis Sagastume](https://github.com/bronzdoc?ref=rubycentral.org), a longtime contributor to RubyGems, agreed to start helping us maintain RubyGems and Gemstash. He will continue working with the existing RubyGems and Gemstash teams, fixing bugs and adding features. Welcome to Ruby Together, Luis!
[Aditya Prakash](https://github.com/sonalkr132?ref=rubycentral.org), a longtime contributor to RubyGems.org, has joined us to work on RubyGems.org. We’re excited to have him on board, and looking forward to his help keeping the servers running efficiently and securely.
### google summer of code
As we mentioned last month, Google accepted our application to bring back the Ruby umbrella organization for Summer of Code projects improving not just implementations of Ruby, but any Ruby open source project. Our efforts were more successful than we expected, and more than 50 students submitted project applications! We were able to accept six of those students. We are very excited to be hosting Shlok Srivastava, Qio Chaofan, Nicholas Yang, Yimin Zhao, Agrim Mittal, and Yogesh Kataria this summer, as they work on RubyGems, MRI, Bundler, and RDoc. Check back for progress updates next month!
### railsconf
Board members André, Coraline, Adarsh, and Valerie attended RailsConf 2018\. Coraline gave a talk on “Scaling the Software Artisan” and André gave a talk titled “Pairing: a guide to fruitful collaboration 🍓🍑🍐”. Adarsh and Valerie arranged a scheduled session for in-person community feedback, and brought that feedback back to the board.
At RailsConf we also distributed stickers and copies of our latest project, a collaboration with bubblesort.io titled [“The Evolution of Bundler”](https://twitter.com/sailorhg/status/984232596870606848?s=12&ref=rubycentral.org). Coming soon, members will be able to download a PDF of the zine for free, and anyone will be able to purchase a copy of the zine from the Ruby Together store. Stay tuned!
### community feedback
In post-RailsConf news, the board met with Ruby developer Sam Phippen to discuss his concerns about Ruby Together’s governance model. As a result of that conversation, we held a board meeting and created a new forum for communication between the community and the board. [We published the results of the meeting](https://rubytogether.org/news/2018-04-25-april-22-board-meeting-results?ref=rubycentral.org), and we expect to continue addressing community concerns in future work.
If you have feedback for the board, or concerns that you’d like to share open an issue in the Ruby Together [Board GitHub repo](https://github.com/rubytogether/board?ref=rubycentral.org) or send us an email at [feedback@rubytogether.org](mailto:feedback@rubytogether.org). (And feel free take a look at our [frequently asked questions](https://rubytogether.org/companies?ref=rubycentral.org#faq) to learn more about how we work.)
## bundler news
This month, we fixed various bugs, worked towards releasing 1.16.2 with more bug fixes, and improved the way we hide Git URL usernames and passwords for the future. Bundler gained 28 new commits, contributed by 15 authors. There were 204 additions and 35 deletions across 22 files.
## rubygems.org news
This month, RubyGems.org saw some minor site fixes, as well as ongoing server maintenance and security patches. The app gained 11 new commits, contributed by 4 authors. There were 62 additions and 54 deletions across 26 files.
## rubygems news
RubyGems saw improved error messages, fixes for several issues related to file permissions, encoding, and other minor issues. We also continued to implement the previously planned work for the long-term transision to RubyGems 3 before the end of the year. This month, RubyGems gained 17 new commits, contributed by 7 authors. There were 148 additions and 163 deletions across 28 files.
## gemstash news
We made a few minor updates to Gemstash in April, picked back up work to add support for storing private gems in AWS S3, and started work to provide the new compact index used by Bundler for faster gem installation. Gemstash gained 8 new commits, contributed by 3 authors. There were 12 additions and 9 deletions across 3 files.
## ruby toolbox news
Hey everyone!
Due to a whole bunch of other obligations, April turned out to be a rather slow month; apart from some very minor maintenance work, I sadly did not find any time to spend meaningful work on the Ruby Toolbox. That being said, May looks a bit more promising. Rolling over my plans from the last monthly update for March, I want to focus mostly on making it easier to see at a glance how a projects given metric relates to the greater ecosystem - so for example in what percentile the number of downloads is in relation to other projects.
As always, your feedback is very welcome, if you have any suggestions or thoughts you’d like to share you can do so via [GitHub issues](https://github.com/rubytoolbox/rubytoolbox/issues?ref=rubycentral.org) or by getting in touch with me directly.
Thank you also to everyone who contributed pull requests in April: bethink, danielwestendorf, khiav223577, nesaulov, skatkov, siong1987, swrobel, and vyncem.
Best, Christoph
## budget & expenses
In April, we saw $18,145.00 in total income, and spent a total of $28,511.19.
- $6,557.50 for 43.7 hours worked on Bundler at $150/hour
- $1,080 for 7.2 hours worked on RubyGems.org at $150/hour
- $6,206.25 for 41.4 hours worked on RubyGems at $150/hour
- $3,633.75 for 24.2 hours worked on other OSS and devtools at $150/hour
- $2,550 for 17.0 hours worked on The Ruby Toolbox at $150/hour
- $83.66 on dedicated servers for RubyBench.org
- $551.50 on payment processing fees
- $5,919.69 on company overhead like hosting, services, software, hardware, taxes, etc
- $1,370 on accounting, copywriting, design, and other professional services
- $558.84 on marketing, evangelism, and community outreach
Until next time,
Stephanie, André, and the Ruby Together Team
### April 22 Board Meeting Results
URL: https://rubycentral.org/news/april-22-board-meeting-results/
Last updated: 2026-06-05T16:47:51.000Z
### Attendees and agenda
The [full board](https://rubytogether.org/team?ref=rubycentral.org) was present, including André Arko, Coraline Ada Ehmke, Valerie Woolard Srinivasen, Allison Sheren McMillan, Courteney Ervin, and Adarsh Pandit. Topics included increasing communication with the community, increasing transparency about how projects are funded, and the board’s position on funded project governance.
### Decisions
To increase communication and transparency about board conversations and decisions, we have created [a GitHub repository for the Ruby Together Board of Directors](https://github.com/rubytogether/board?ref=rubycentral.org). The repo will include planned agendas for future board meetings, summaries of meetings after they happen, and instructions on how to provide feedback to the board. The same information will also be published via Slack, Twitter, email, and any other Ruby Together communication channels.
To provide clearer and more detailed information about how Ruby Together’s finances work, we will create a guide to understanding Ruby Together budget reports. As a board, we recognize that there has been confusion about how the budget is allocated and spent. To resolve this, we plan to provide additional detail about where money is spent and why it is spent on those things, supplementing the [public monthly progress and budget reports](https://rubytogether.org/news/?ref=rubycentral.org).
In a thoughtful discussion, we re-examined our existing requirements for funded project governance. Ultimately, we decided to retain the requirement that funded projects adopt and enforce a code of conduct. We also decided to actively avoid any other governance requirements. Funded projects are free to organize themselves and make decisions in any way the project contributors and maintainers work out amongst themselves.
### Future plans
We recognize that there are improvements that can be made, and we plan to continue to work on additional topics in the near future. The topics we plan to investigate in the future include (but are not limited to) finalizing our [mission and values statement](https://github.com/rubytogether/feedback/blob/main/VISION%5FMISSON%5FVALUES.md?ref=rubycentral.org), improving the project funding process, exploring additional funding options, evaluating compensation rates for paid work, and adding a mentorship component to work for Ruby Together. We also plan to spend time on contingency and succession planning, setting up Ruby Together to have a long and stable life ahead of it. We don’t yet know what the results of those investigations will be, but we plan to keep you posted about future decisions and actions.
We understand and acknowledge the concerns that people have around conflicts of interest and will use this feedback to guide the board’s future direction. As a new board, we ask for the community’s patience as we execute on these initiatives. We want the community to know what we’re planning, and what actions we plan to take to work with the Ruby community and make Ruby Together a better, strong organization.
### Feedback
Thank you everyone for your thoughts and feedback and, as always, the board is willing to have additional conversations. You can reach out to us in the Ruby Together members Slack, on GitHub at [rubytogether/board](https://github.com/rubytogether/board?ref=rubycentral.org), or by email at [feedback@rubytogether.org](mailto:feedback@rubytogether.org).
### March 2018 Monthly Update
URL: https://rubycentral.org/news/march-2018-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello! Welcome to the monthly update. During March, our work was supported by [Coinbase](https://coinbase.com/?ref=rubycentral.org), [Cloud City Development](http://www.cloudcity.io/?ref=rubycentral.org), [DigitalOcean](http://www.digitalocean.com/?ref=rubycentral.org) and many others.
This month we were able to pay for 147 hours of developer work on Ruby open source. Thank you to all of the companies and individual developers that continue to support our work.
## ruby together news
In March, Ruby Together was supported by 75 different companies. In addition, 2 developers signed up to be members of Ruby Together. We were supported by a total of 90 individual members and 68 friends of Ruby Together.
In very exciting news, the folks at [Coinbase](https://www.coinbase.com/?ref=rubycentral.org) contributed $12,750 to Ruby Together as part of their [ongoing open source funding efforts](https://engineering.coinbase.com/coinbase-open-source-fund-ruby-edition-101c04085be0?ref=rubycentral.org). They will also be contributing an additional $2,000 per month for the next five months. Thank you! 🎉
And great news for your closet—we’ve got [new Bundler T-shirts in the Ruby Together shop](https://shop.rubytogether.org/products/bundler-t-shirt?ref=rubycentral.org)! Shirts are available in a variety of sizes as well as in both fitted and unfitted styles.
## bundler news
Bundler saw a variety of bug fixes in March thanks to our contributors, including [@alyssais](https://github.com/alyssais?ref=rubycentral.org), [@koic](https://github.com/koic?ref=rubycentral.org), [@MSP-Greg](https://github.com/MSP-Greg?ref=rubycentral.org), [@nesaulov](https://github.com/nesaulov?ref=rubycentral.org), [@kunruh9](https://github.com/kunruh9?ref=rubycentral.org), [@shime](https://github.com/shime?ref=rubycentral.org), and [@greysteil](https://github.com/greysteil?ref=rubycentral.org). Fixes included [documenting the order Bundler loads config settings](https://github.com/bundler/bundler/pull/6464?ref=rubycentral.org) as well as fixing some [rescue calls that hadn’t specified error type](https://github.com/bundler/bundler/pull/6310?ref=rubycentral.org). Additionally, we published a [Bundler Policies](https://github.com/bundler/bundler/blob/2053d65c974f55fc15196b3ad82d7749750b2a3e/doc/POLICIES.md?ref=rubycentral.org) doc to supplement Bundler’s existing Code of Conduct.
Coming up next, we expect to ship bug fixes, push out a small feature release, and begin public testing on Bundler 2.0\. In total, Bundler gained 60 new commits, contributed by 13 authors. There were 353 additions and 97 deletions across 47 files.
## rubygems.org news
This month, RubyGems.org saw ongoing system updates, security patches, and general maintenance. Thank you [@dwradcliffe](https://github.com/dwradcliffe?ref=rubycentral.org) for all your hard work!
## rubygems news
RubyGems saw another 25 pull requests merged in March. We [started implementing the plan for RubyGems 3](https://github.com/rubygems/rubygems/pull/2182?ref=rubycentral.org), [improved a common and annoying warning](https://github.com/rubygems/rubygems/pull/2242?ref=rubycentral.org), and fixed many, many bugs.
In March, RubyGems gained 73 new commits, contributed by 8 authors. There were 860 additions and 1,092 deletions across 66 files.
## ruby toolbox news
Hey everyone!
Last month, my main focus was converting the GitHub stats by syncing to their [GraphQL API](https://developer.github.com/v4/?ref=rubycentral.org), which enabled the addition of a whole bunch of new project metrics while keeping the API rate limit consumption the same. I [launched them](https://twitter.com/TheDeadSerious/status/979097768177422337?ref=rubycentral.org) at the end of March and you can see an example [here](https://www.ruby-toolbox.com/projects/hanami?ref=rubycentral.org)—for instance, you can now see issue and pull request closure rates and recent commit activity.
Since I bumped into some minor issues that needed extra work while converting to the new API, I didn’t get much time to spend on the other topic I mentioned in the last update: esier understandability on what the project metrics mean in the greater context of the Ruby ecosystem. Broadly speaking, I’d like to make some clear visual indicators in what range any given metric stands in relation to the Ruby ecosystem to make it easier to “grok” at a glance the healthiness of a project. For example, for gem downloads you could see that a given project is in the 10% most-often-downloaded gems, but for example issue closure rate, release activity and many more can become much more interesting when given this kind of context.
This will be my main focus in April, and I hope to have something to show to you in this regard next month. :)
As always, your feedback is very welcome. If you have any suggestions or thoughts you’d like to share you can do so via [GitHub issues](https://github.com/rubytoolbox/rubytoolbox/issues?ref=rubycentral.org) or by getting in touch with me directly.
Thank you also to everyone who contributed pull requests in March: BurdetteLamar, apa512, boazsegev, cvoltz, franklinyu, funk-yourself, konung, nesaulov, pmackay, and skatkov.
Best,
Christoph
## budget & expenses
In March, we saw $29,620 in total income, and spent a total of $35,308.59.
- $5,188.75 for 34.6 hours worked on Bundler at $150/hour
- $2,250.62 for 15.0 hours worked on RubyGems.org at $150/hour
- $3,713.12 for 24.8 hours worked on RubyGems at $150/hour
- $1,935 for 12.9 hours worked on other OSS and devtools at $150/hour
- $8,925 for 59.5 hours worked on The Ruby Toolbox at $150/hour
- $82.80 on dedicated servers for RubyBench.org
- $1,570.52 on payment processing fees
- $3,168.47 on company overhead like hosting, services, software, hardware, taxes, etc
- $5,975 on accounting, copywriting, design, and other professional services
- $2,499.30 on marketing, evangelism, and community outreach
Until next time,
Stephanie, André and the Ruby Together team
### February 2018 Monthly Update
URL: https://rubycentral.org/news/february-2018-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello and welcome to the monthly update! During February, our work was supported by [Stripe](https://stripe.com/?ref=rubycentral.org), [GitLab](https://about.gitlab.com/?ref=rubycentral.org), [reinteractive](https://reinteractive.com/?ref=rubycentral.org), and many others.
## ruby together news
In February, Ruby Together was supported by 76 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). Four companies joined as new members, including [Nebulab](https://nebulab.it/?ref=rubycentral.org), [weLaika](https://dev.welaika.com/en/?ref=rubycentral.org), [Kickass Partners](http://kickass.partners/?ref=rubycentral.org).
In addition to those companies, 6 new developers signed up as members or friends of Ruby Together, including Stan Lo. In total, we were supported by 91 individual members and 68 friends of Ruby Together. Thanks to all of our members for making everything that we do possible. <3
As we mentioned last month, Ruby Together applied to organize a [Google Summer of Code 2018](https://summerofcode.withgoogle.com/?ref=rubycentral.org) project for work on any Ruby open source codebase. In February, Google announced projects, and our application was accepted! 🎉
Now that we’ve been accepted, we’re looking for mentors for students who want to work on Ruby open source projects this summer. For more information about what it’s like to be a mentor, Google has written a [mentor guide](https://google.github.io/gsocguides/mentor/?ref=rubycentral.org). If you are interested in mentoring a student this summer, [get in touch](mailto:hello@rubytogether.org)!
If you’re a student who’s interested in applying, student applications will open on March 12\. For help getting ready to apply, check out the [GSoC Student Guide](https://google.github.io/gsocguides/student/?ref=rubycentral.org).
Finally, we would also love contributions to the project ideas list. If you have an open source project or a feature idea that are one-student-summer sized, [add them here](https://github.com/rubygsoc/rubygsoc/wiki/Ideas-List?ref=rubycentral.org).
## bundler news
Bundler saw some fixes in February thanks to contributors [@nholden](https://github.com/nholden?ref=rubycentral.org), [@voxik](https://github.com/voxik?ref=rubycentral.org), [@cpgo](https://github.com/cpgo?ref=rubycentral.org), [@deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org), and [@alyssais](https://github.com/alyssais?ref=rubycentral.org). Fixes this month included [a fix for certain instances of the “perhaps the lockfile is corrupted?” error](https://github.com/bundler/bundler/pull/6288?ref=rubycentral.org), as well as [clear enforcement steps for the code of conduct](https://github.com/bundler/bundler/pull/6283?ref=rubycentral.org). We also received [an awesome proposal](https://github.com/bundler/rfcs/pull/10?ref=rubycentral.org) to give the `add` command superpowers, and add a `remove` command.
This month, Bundler gained 23 new commits, contributed by 8 authors. There were 291 additions and 59 deletions across 50 files.
## rubygems.org news
In February, we continued to apply security patches and other updates to the servers running RubyGems.org. We also made progress on a new project, collecting metrics from the server logs about what Ruby, RubyGems, and Bundler versions are being actively used. Hopefully we’ll have something to show everyone next month!
## rubygems news
RubyGems saw a lot of activity this month, including the release 2.7.5 and 2.7.6 with *tons* of bug fixes. The version 2.7.6 release contained some [critical security fixes](https://blog.rubygems.org/2018/02/15/2.7.6-released.html?ref=rubycentral.org), and is a strongy recommended upgrade. Get out there and run `gem update --system` today!
On top of releasing new code, we also managed to [write out the Ruby version support and release policies](https://github.com/rubygems/rubygems/pull/2202?ref=rubycentral.org), and [draft of a minimally disruptive plan for RubyGems 3 and 4](https://github.com/rubygems/rubygems/pull/2182?ref=rubycentral.org#issuecomment-364631805).
In total, RubyGems gained 130 new commits, contributed by 12 authors. There were 755 additions and 340 deletions across 50 files.
## ruby toolbox news
After bringing the Ruby Toolbox back to life at the beginning of February, the rest of the month was mostly about going through a variety of community contributions, mostly related to changes to the [catalog](https://github.com/rubytoolbox/catalog?ref=rubycentral.org), which saw 61 pull requests from 43 contributors. I also tried to improve documentation and guidelines for catalog contributions, based on common mistakes happening on that end. The Rails app itself saw a bunch of improvements to the README that now gives an overview of how to get the app running for local development, and in total saw 4 pull requests submitted by 4 contributors.
I also did some research and prototyping for charts and statistics that can be gathered from the existing project metrics, and how to make individual project metrics like gem downloads easier to put into context in relation to the rest of the ecosystem. In addition to converting the GitHub gathering to their GraphQL library, thus unlocking a whole bunch of additional project metrics (see [#94](https://github.com/rubytoolbox/rubytoolbox/pull/94?ref=rubycentral.org)), in March I’d like to make daily database dumps available for download to make it easier to get a more realistic development environment, and to bring said project metrics display improvements live for at least one metric to get community feedback on the general approach.
As always, your feedback is very welcome, if you have any suggestions or thoughts you’d like to share you can do so via [GitHub issues](https://github.com/rubytoolbox/rubytoolbox/issues?ref=rubycentral.org) or by getting in touch with me directly.
Finally, thank you to all of last month’s PR contributors: BookOfGreg, GBH, andyjeffries, brandonweiss, bricesanchez, brodock, btrd, campreb, cedlemo, cyril, dogweather, drgcms, el-feo, emilebosch, eregon, filipewl, florentferry, gzigzigzeo, iridakos, itsderek23, kddeisz, kenn, kirillshevch, konung, lulalala, mediafinger, nilbus, ohler55, olleolleolle, palkan, pat, pboling, pedrozath, philnash, phlegx, pmackay, sacrebleu, sgeorgi, strzibny, tarcieri, tiagoamaro, varyonic, victords, westonganger, zach-capalbo, zoras.
See you next month! Christoph
## budget & expenses
In February, we paid for 85 hours of developer time, saw $16,380.00 in total income, and spent a total of $16,754.02.
- $5,079 for 33.9 hours worked on Bundler at $150/hour
- $3,885 for 25.9 hours worked on RubyGems.org at $150/hour
- $1,341 for 8.9 hours worked on RubyGems at $150/hour
- $2,453 for 16.4 hours worked on other OSS and devtools at $150/hour
- $83.61 on dedicated servers for RubyBench.org
- $551.98 on payment processing fees
- $2,174.03 on company overhead like hosting, services, software, hardware, taxes, etc
- $1,050 on accounting, copywriting, design, and other professional services
- $136.9 on marketing, evangelism, and community outreach
Until next time,
Stephanie, André and the Ruby Together team
### January 2018 Monthly Update
URL: https://rubycentral.org/news/january-2018-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello, and happy New Year! Welcome to the monthly update. During January, our work was supported by [Stripe](https://stripe.com/?ref=rubycentral.org), [Cloud City Development](http://www.cloudcity.io/?ref=rubycentral.org), [Airbnb](http://airbnb.com/?ref=rubycentral.org), and many others.
We’re excited to have kicked off the new year with an announcement: the relaunch of the Ruby Toolbox! Read on for more details.
## ruby together news
In January, Ruby Together was supported by 75 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org), and 4 companies joined as new members.
On top of those companies, 4 new developers signed up as members or friends of Ruby Together, including Viacheslav Kysil, James Flowers, Stan Lo, and [Georg Gadinger (@nilsding)](https://twitter.com/nilsding?ref=rubycentral.org). In total, we were supported by 95 individual members and 67 friends of Ruby Together. Thanks to all of our members for making everything that we do possible!
We continued to fill in the remaining seats on the board of directors. During January, we were joined by [Courteney Ervin](https://twitter.com/courteneyervin?ref=rubycentral.org), and [Adarsh Pandit](https://twitter.com/adarshp?ref=rubycentral.org). Courteney works for the New York Public Library system, building open-source tools to make ebooks more accessible. Adarsh founded and runs his own software consultancy, [Cylinder Digital](http://cylinder.digital/?ref=rubycentral.org). We’re super excited to have their perspectives and input as we work to support the Ruby community.
This month also saw a new dev hire, with long-time contributor [@kerrizor](https://twitter.com/kerrizor?ref=rubycentral.org) graciously agreeing to help with RubyGems.org support and generally making things better for RubyGems users.
## google summer of code news
In some new and exciting news, we applied to Google Summer of Code! It didn’t happen in 2017, but in 2016 we were able to run a Google Summer of Code project for any Ruby codebase. With around a dozen students working on MRI, Bundler, RubyGems, and other projects, it was very exciting. Hopefully we’ll have a summer of students working on Ruby OSS in 2018 as well.
## bundler news
Bundler saw a over a dozen bugfixes in January, thanks to contributors including [@KrauseFx](https://www.github.com/KrauseFx?ref=rubycentral.org), [@akhramov](https://github.com/akhramov?ref=rubycentral.org), [@christhekeele](https://github.com/christhekeele?ref=rubycentral.org), [@joelvh](https://github.com/joelvh?ref=rubycentral.org), and [@ajwann](https://github.com/ajwann?ref=rubycentral.org). We expect to release those fixes shortly in version 1.16.2\. Altogether, Bundler gained 69 new commits, contributed by 18 authors. There were 536 additions and 146 deletions across 57 files.
## rubygems.org news
January was a quiet month for RubyGems.org, with just 1 new commit, contributed by 1 author. There was 1 addition and 1 deletion across 1 file. As always, we also continued to apply security patches and keep the servers behind RubyGems.org operating.
## rubygems news
RubyGems saw a decent amount of activity this month, including bugfixes, error message improvements, and test updates. This month, RubyGems gained 56 new commits, contributed by 11 authors. There were 502 additions and 527 deletions across 63 files.
## gemstash news
In an extremely quiet month, there were no new changes to Gemstash in January. That said, there are definitely [open issues](https://github.com/bundler/gemstash/issues?ref=rubycentral.org) that would make excellent options for anyone interested in starting to contribute to Ruby open source.
## ruby toolbox
Hello everyone,
Great news: the [Ruby Toolbox is back](https://www.ruby-toolbox.com/blog/2018-02-01/lets-push-things-forward?ref=rubycentral.org) :)
It took a bit longer than anticipated in the last monthly update (of course it did…), but I hope it was for the best. As I was chugging along on getting the site ready for launch, these tiny things that I wanted to be part of the initial relaunch kept coming up, and ultimately the site relaunched with quite a few things I had lined up for post-launch in the last update—the most notable of them being search—which is now already available.
Still, this is only a starting point. You can find the work lined up for the next few weeks on the [GitHub project](https://github.com/rubytoolbox/rubytoolbox/projects/1?ref=rubycentral.org), and as feedback from users starts pouring in, I’m sure there will be more.
On top of that, one of the main aspects I want to focus on in the next month is cleaning up the catalog; some categorizations are plain wrong, and some categories may be obsolete by now. I recently also did some [research into using GitHub’s new GraphQL API](https://github.com/rubytoolbox/rubytoolbox/pull/94?ref=rubycentral.org), and want to convert to it as it will unlock plenty of additional metrics that could be added to the site without hitting API rate limiting issues.
See you next month! Best, Christoph
## budget & expenses
In January, we paid for 105 hours of developer time, saw $18,920.00 in total income, and spent a total of $20,234.17.
- $7,335 for 48.9 hours worked on Bundler at $150/hour
- $4,286 for 28.6 hours worked on RubyGems.org at $150/hour
- $1,594 for 10.6 hours worked on RubyGems at $150/hour
- $2,583 for 17.2 hours worked on other OSS and devtools at $150/hour
- $79.87 on dedicated servers for RubyBench.org
- $625.94 on payment processing fees
- $2,430.69 on company overhead like hosting, services, software, hardware, taxes, etc
- $800.00 on accounting, copywriting, design, and other professional services
- $500.00 on marketing, evangelism, and community outreach
Until next time,
Stephanie, André and the Ruby Together team
### December Monthly and 2017 Yearly Update
URL: https://rubycentral.org/news/december-monthly-and-2017-yearly-update/
Last updated: 2022-11-28T23:39:43.000Z
Hello, and welcome to a year-end special edition of the monthly update: Ruby Together’s Yearly Update for 2017! There are more details in the following sections, but here’s the tl;dr. During 2017, we took in $284,481.28, we spent $241,973.01, and we paid for 1,169 hours of developer work on Ruby open source.
Some highlights from the year include shipping 21 Bundler releases, shipping 11 RubyGems releases, kicking off Ruby Toolbox 2.0, Bundler almost shipping with Ruby 2.5, and defending RubyGems.org against a DoS attack on Christmas Day.
### Ruby Together news
During December, our work was supported by 76 different companies, including [reinteractive](https://reinteractive.com/?ref=rubycentral.org), [Stripe](https://stripe.com/?ref=rubycentral.org), [thoughtbot](https://thoughtbot.com/?ref=rubycentral.org), [Travis CI](https://travis-ci.org/?ref=rubycentral.org), and many others. One new company joined in December, as well as one new individual member, Viacheslav Kysil. Last month, were supported by a total of 95 individual members and 67 friends of Ruby Together. Thanks to all of our members for making everything that we do possible. <3
In other news, please join us in welcoming a new director to our board: [Allison McMillan](https://twitter.com/allie%5Fp?ref=rubycentral.org)! Among her many accomplishments, Allison recently helped organize the RubyConf 2017 Scholars and Guides program, and we’re super excited to have her perspective and experience as we make plans for 2018.
Speaking of plans for 2018, there’s a big one we’ve just started working on: project applications for funding from Ruby Together. If you have opinions about how we can accept applications and start funding additional projects, we would love to hear from you! Write to us at [hello@rubytogether.org](mailto:hello@rubytogether.org) with your input. We might not reply to every email, but we’ll read and consider them all.
### Bundler news
As you may have noticed, [Bundler didn’t end up shipping with Ruby 2.5](https://www.ruby-lang.org/en/news/2017/12/25/ruby-2-5-0-released/?ref=rubycentral.org). The Ruby language core team has yet to announce why they decided to remove Bundler a few hours before Ruby 2.5 was released on Christmas Day. Hopefully, we’ll find out the story there soon.
In the meantime, Bundler 1.16.1 has been released, with fixes or workarounds for all known issues. If you were waiting to upgrade to version 1.16, give it a try now! If you’re still seeing issues on version 1.16.1, please [let us know!](https://github.com/bundler/bundler/blob/master/ISSUES.md?ref=rubycentral.org) We care a lot about fixing bugs and maintaining backwards compatibility, but we need to hear from users in order to know when bugs have crept in. <3
In December, Bundler gained 59 new commits, contributed by 8 authors. There were 419 additions and 301 deletions across 36 files.
In 2017, Bundler gained two new maintainers, [Colby Swandale](https://twitter.com/0xcolby?ref=rubycentral.org) and [hsbt](https://twitter.com/hsbt?ref=rubycentral.org). We shipped 21 releases total, which included 3 feature releases. Those releases included 1,392 commits, by 31 authors, with 21,892 additions and 5,860 deletions across 1,140 changed files.
Thanks especially to Bundler’s new contributors in 2017: Abu Nashir, Adam Wanninger, Adrian Gomez, Alessandro Dal Grande, Alex Taylor, Artyom Khramov, Ashish Sehra, Atsushi Yamamoto, Brian Christian, Daniel P. Clark, Daniel Ritz, Daniel Trierweiler, David Radcliffe, Dennis Suratna, Elia Schito, emsk, Eric Boehs, Erik Johnson, fotanus, Frederico, Frederico Bittencourt, Glenn Espinosa, Greg Werbin, Grey Baker, HippoDippo, Igor Bozato, Ivan Kuchin, Jack LaBarba, Jan Krutisch, Jared Kauppila, Jonathan Pike, Juan Barreneche, Julian Nadeau, Justin Myers, Kaycee, Keiji Yoshimi, Kerri Miller, leslie.wen, Mal Graty, Michael Deering, Michael Pitman, mpd, Noah Kantrowitz, Nobuyoshi Nakada, okkez, Olle Jonsson, Patricia Arbona, Paul Nikitochkin, Piotr Kuczynski, robcole, Robert Soly, Sebastian Nowak, Shayon Mukherjee, Stefan Sedich, Stephanie Morillo, Tejas Bubane, Tristan Hill, Urabe, Shyouhei, Wade Tandy, Will Jordan, and Zach Ahn.
### RubyGems news
RubyGems had a calmer year in 2017\. The biggest change was the start of merging Bundler and RubyGems into a single gem manager to rule them all. We plan to continue that work in the coming year, in addition to fixing bugs, staving off bitrot, and working to improve the RubyGems experience for everyone.
In 2017, we shipped 11 releases total, with one new feature release. Those releases included 463 commits, by 25 authors, with 3,655 additions and 1,144 deletions across 122 files.
We especially want to thank the new contributors to RubyGems in 2017: Alyssa Ross, anantkolvankar, Arthur Marzinkovskiy, Colby Swandale, EdOverflow, Grey Baker, HorimotoYasuhiro, Jared Beck, Jason Frey, Jonathan Claudius, Jun Aruga, Kazuaki Matsuo, Mark Sayson, Olle Jonsson, Shiva Bhusal, toru.yagi, and Tsukuru Tanimichi.
### RubyGems.org news
Through a combination of luck, hard work, and frequent security patches, RubyGems.org avoided significant downtime during 2017\. The two most exciting events were probably [discovering our years-old remote execution vulnerability was not completely fixed](http://blog.rubygems.org/2017/10/09/unsafe-object-deserialization-vulnerability.html?ref=rubycentral.org), and scrambling to truly fix it once and for all. Thanks to David Radcliffe and Aaron Patterson for their work to implement and test a new fix. On top of that, we got to defend against a denial of service attack that overwhelmed our backend servers—on Christmas Day itself. Huge props to David Radcliffe and Evan Phoenix, who saved Christmas for Ruby devs around the world while demonstrating awesome teamwork between Ruby Central and Ruby Together.
In 2017, RubyGems.org merged 336 commits by 30 authors, with 4,880 additions and 3,005 deletions across 320 files.
We especially want to thank the new contributors to RubyGems.org in 2017: Aaron Patterson, Andre Medeiros, Colby Swandale, Olle Jonsson, Shota Miyazaki, siddhantBajaj, and Yoshiyuki Hirano.
### Gemstash news
Gemstash had a pretty calm 2017, seeing some general bugfixes and enhancements but no significant activity. If you’re looking for a way to get started contributing to Ruby open source, the [Gemstash issues list](https://github.com/bundler/gemstash/issues?ref=rubycentral.org) has several bugs and feature requests that would make a good starting point.
In 2017, Gemstash merged 75 commits by 10 authors, with 610 additions and 456 deletions across 47 files. We especially want to thank the new contributors to Gemstash in 2017: Agis Anastasopoulos, and Omer Katz.
### Ruby Toolbox news
Hello everyone,
Happy new year! Holiday season was a bit involved for me, so unfortunately I didn’t find time to work on the new Toolbox in December — that obviously also meant that the planned mid-December launch that I mentioned in the last update didn’t work out — sorry for that! Sometimes you just have to cut some stuff — I actually sat down a few evenings to do some work, but quickly realized I was simply too tired to do anything meaningful.
That being said, the new year is off to a good start: Import of RubyGems and GitHub stats are ready, so after adding score calculations and a bit of UI polish, the site should finally come back in the next week or two. In contrast to the last update, this will actually already include **all** gems, not only those in categories, and the syncing already includes a good chunk of the metrics on the old site, so adding them to the site will only mean adding them to the UI, so those should become visible pretty soon as well.
After the site is launched the first thing to do will be adding good full text search. I will also prepare some “future ideas” and “easy first contribution” tickets on Github after launch, so everyone interested in contributing get a chance to do so, but first I want this website live :)
As mentioned last month, you can find the current state of the site at [beta.ruby-toolbox.com](https://beta.ruby-toolbox.com/?ref=rubycentral.org).
Thanks for your time, see you next month!
— Christoph
### December budget and finances
In December, we took in a total of $18,115.0, and spent a total of $19,475.62\. Here’s the breakdown of where the money went:
- $5,584 for 37.2 hours worked on Bundler at $150/hour
- $3,454 for 23.0 hours worked on RubyGems.org at $150/hour
- $2,441 for 16.3 hours worked on RubyGems at $150/hour
- $2,306 for 15.4 hours worked on other OSS and devtools at $150/hour
- $80.20 on dedicated servers for RubyBench.org
- $600.49 on payment processing fees
- $1,679.17 on company overhead like hosting, services, software, hardware, taxes, etc
- $1,625.0 on accounting, copywriting, design, and other professional services
- $1,705.59 on marketing, evangelism, and community outreach
### 2017 budget and finances
In addition to our usual monthly report, we’re including a yearly financial report. In 2017, we took in a total of $284,481.28, and spent a total of $241,973.01\. With that money, we paid for 1,169 hours of developer work total. By detail, we spent:
- $89,380 for 596 hours worked on Bundler at $150/hour
- $48,543 for 323.62 hours worked on RubyGems.org at $150/hour
- $16,136 for 107.57 hours worked on RubyGems at $150/hour
- $21,514 for 143.43 hours worked on other OSS and devtools at $150/hour
- $908.01 on dedicated servers for RubyBench.org
- $8,550.10 on payment processing fees
- $22,649.92 on company overhead like hosting, services, software, hardware, taxes, etc
- $18,897.50 on accounting, copywriting, design, and other professional services
- $15,399.81 on marketing, evangelism, and community outreach
On top of summing up our monthly reports, this report includes year-end compensation figures for all officers of the company and members of the board. These figures have always been available to the public in Ruby Together’s tax returns, but we’re including them here to increase visibility for everyone. Company officer and director compensation during 2017 included:
- André Arko, $53,392.50 for work on Ruby open source software, $0 for work as chief executive officer, and $0 for work as a director
- Camille Baldock, $0 for work as a director
- Coraline Ada Ehmke, $0 for work as a director
- Ines Sombra, $0 for work as a director
- Joel Watson, $0 for work as treasurer, and $0 for work as a director
- Sarah Mei, $0 for work as a director
- Steve Klabnik, $0 for work as a director
- Terence Lee, $0 for work as a director
- Valerie Woolard Srinivasan, $0 for work as a director
Thanks again to all of our members for making our work possible, and to all of you (member or not) for being part of the Ruby community. <3
Until next time, André and the Ruby Together team
### October and November 2017 Monthly Update
URL: https://rubycentral.org/news/october-and-november-2017-monthly-update/
Last updated: 2022-11-28T23:39:41.000Z
Hello! Welcome to a super-sized double monthly update for the months of October and November. During that time, our work was supported by [reinteractive](https://reinteractive.com/?ref=rubycentral.org), [Stripe](http://stripe.com/?ref=rubycentral.org), [Bleacher Report](http://www.bleacherreport.com/?ref=rubycentral.org), [thoughtbot](https://thoughtbot.com/?ref=rubycentral.org), and many others.
## ruby together news
In October and November, Ruby Together was supported by 76 different companies, including Ruby member [reinteractive](https://reinteractive.com/?ref=rubycentral.org) and Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). On top of those companies, 4 new developers signed. In total, we were supported by 96 individual members and 68 friends of Ruby Together. Thanks to all of our members for making everything that we do possible. <3
This semester, Ruby Together developer [Samuel Giddins](https://twitter.com/segiddins?ref=rubycentral.org) finished his studies and graduated from college! 🎉 He’ll be moving from Chicago to San Francisco, and continuing to work on both Bundler and RubyGems. Go tweet some congratulations at him.
At RubyConf 2017, André gave a completely new talk about the history of Bundler, called A History of Bundles: 2010 to 2017\. You can [watch the video from the conference](https://www.youtube.com/watch?v=BXFYjO8qDxk&ref=rubycentral.org), [check out the slide deck](https://speakerdeck.com/indirect/a-history-of-bundles-2010-to-2017?ref=rubycentral.org), or [read the blog post version of the talk](http://andre.arko.net/2017/11/16/a-history-of-bundles/?ref=rubycentral.org).
Finally, some board member news: founding board members Terence Lee and Sarah Mei have stepped down. We’re incredibly greatful to have had their help and support for almost three years. <3
As usual, the board will appoint successors to each vacant seat, to fill them until the next regularly scheduled board election. So far, the board has appointed one new director: [Valerie Woolard Srinivasan](https://twitter.com/valeriecodes?ref=rubycentral.org). We’re very happy to have her help, and looking forward to working with her.
## bundler news
As far as Bundler goes, we were able to release the official [version 1.16.0](http://bundler.io/blog/2017/10/31/bundler-1-16.html?ref=rubycentral.org), containing more than 20 bugfixes and some big improvements to the speed of the `install` command. It is now extremely fast to run `install` when nothing needs to be done. In addition, [Gray Baker](https://github.com/greysteil?ref=rubycentral.org) of [Dependabot](https://dependabot.com/?ref=rubycentral.org) helped us ship some nice resolver improvements, pulling off the extremely rare victory of making the resolver more correct and faster at the same time.
Since the release of 1.16 at the end of October, we’ve fixed several new bugs that have cropped up, and we expect to release version 1.16.1 sometime this week. We also expect to ship 1.16.1 in the Ruby 2.5 rc1 release shortly.
Overall, Bundler gained 215 new commits, contributed by 30 authors. There were 2,249 additions and 1,151 deletions across 113 files.
## rubygems.org news
RubyGems.org saw a small amount of work, including some security, develpoment, and production fixes, as well as the usual ongoing security updates for the servers.
Rubygems.org gained 7 new commits, contributed by 6 authors. There were 29 additions and 0 deletions across 6 files.
## rubygems news
In October and November, we released RubyGems version 2.6.14, 2.7.0, 2.7.1, 2.7.2, and 2.7.3\. Those versions included some fixes backported from ruby-trunk, work to improve compatibility with Ruby 2.5, and upgrades for the version of Bundler included inside RubyGems, as well as a smattering of other bugfixes.
On the topic of developing RubyGems, our very own [@duckinator](https://twitter.com/duckinator?ref=rubycentral.org) shipped [rgdev](https://github.com/duckinator/rgdev?ref=rubycentral.org#readme), a complete Docker-based environment for developing RubyGems. With setting up a development environment made easier, we will hopefully see more contributors over time. See Twitter for [the tl;dr on how to use it](https://twitter.com/duckinator/status/934089692601028608?ref=rubycentral.org).
Rubygems gained 114 new commits, contributed by 17 authors. There were 623 additions and 92 deletions across 35 files.
## gemstash news
Gemstash didn’t see any commits land during October or November. That said, if you’re interested in contributing to an open source project, the [Gemstash issues list](https://github.com/bundler/gemstash/issues?ref=rubycentral.org) has some promising-looking tickets. There’s definitely some openings for work on docs, the RubyGems.org mirror functionality, or the private gem hosting side of things.
## ruby toolbox news
Hey everyone,
since the last update I got started putting the Toolbox back together - I built [tooling for exporting the flat-file based catalog to a JSON structure](https://github.com/rubytoolbox/catalog/pull/6?ref=rubycentral.org) that the [backend app will be able to consume](https://github.com/rubytoolbox/rubytoolbox/pull/15?ref=rubycentral.org). This will be wired to a webhook so merged catalog PRs will immediately show up on the site.
Further, I got the actual, [new rails app started](https://github.com/rubytoolbox/rubytoolbox/pull/10?ref=rubycentral.org), which involved getting CI running on Travis and [setting up deployment and continuous delivery to Heroku](https://github.com/rubytoolbox/rubytoolbox/pull/17?ref=rubycentral.org), who will be sponsoring hosting for the Toolbox - thanks a lot Heroku! I added [basic category overview and detail UI](https://github.com/rubytoolbox/rubytoolbox/pull/16?ref=rubycentral.org), also [making it a bit prettier along the way](https://github.com/rubytoolbox/rubytoolbox/pull/20?ref=rubycentral.org).
The last missing piece needed to get the site back live is fetching the most basic stats and scoring for categorized projects from Rubygems and Github. I expect this to be done in early december. Until then, you can always see the current state of development at [beta.ruby-toolbox.com](https://beta.ruby-toolbox.com/?ref=rubycentral.org).
Once the site is back live with the bare minimum set of features, the next things to bring back will be:
- Getting all rubygems back to the site (not only the categorized ones)
- Search
- Adding more metrics to bring them on par with the old site
Please feel warmly invited to join [github.com/rubytoolbox/rubytoolbox](https://github.com/rubytoolbox/rubytoolbox?ref=rubycentral.org) and see you next month!
— [Christoph](https://twitter.com/thedeadserious?ref=rubycentral.org)
## budget & expenses
In October, we paid for 103.9 hours of developer time, saw $21,700 total income and spent a total of $19,839.25.
- $7,398.75 for 49.3 hours worked on Bundler at $150/hour
- $3,000 for 20.0 hours worked on RubyGems.org at $150/hour
- $3,426.25 for 22.8 hours worked on RubyGems at $150/hour
- $1,762.50 for 11.8 hours worked on other OSS and devtools at $150/hour
- $79.09 on dedicated servers for RubyBench.org
- $707.21 on payment processing fees
- $2,268.05 on company overhead like hosting, services, software, hardware, taxes, etc
- $570 on accounting, copywriting, design, and other professional services
- $627.40 on marketing, evangelism, and community outreach
In November, we paid for 60.7 hours of developer time, saw $21,545 in total income, and spent a total of $12,234.08.
- $4,260 for 28.4 hours worked on Bundler at $150/hour
- $352.50 for 2.4 hours worked on RubyGems.org at $150/hour
- $2,528.75 for 16.9 hours worked on RubyGems at $150/hour
- $1,946.25 for 13.0 hours worked on other OSS and devtools at $150/hour
- $78.17 on dedicated servers for RubyBench.org
- $700.91 on payment processing fees
- $1,370.24 on company overhead like hosting, services, software, hardware, taxes, etc
- $320 on accounting, copywriting, design, and other professional services
- $677.26 on marketing, evangelism, and community outreach
Keep an eye out for Ruby 2.5, which is currently scheduled to be released on Christmas Day! It will include the latest versions of RubyGems and Bundler right out of the box, with no installation needed, thanks to [@hsbt](https://twitter.com/hsbt?ref=rubycentral.org).
Until next time,
André and the Ruby Together team
### September 2017 Monthly Update
URL: https://rubycentral.org/news/september-2017-monthly-update/
Last updated: 2022-11-28T23:39:41.000Z
Hello! Welcome to the monthly update. During September, our work was supported by [reinteractive](https://reinteractive.com/?ref=rubycentral.org), [Stripe](https://stripe.com/?ref=rubycentral.org), [Bleacher Report](http://www.bleacherreport.com/?ref=rubycentral.org), [GitLab](https://about.gitlab.com/?ref=rubycentral.org), and many others.
Since the last update, we shipped a security release of RubyGems, hired a new developer to work on security, funded the new Ruby Toolbox, and patched RubyGems.org to protect it from a newly-found variant of an old security hole.
## ruby together news
In September, Ruby Together was supported by 138 different companies, including Ruby member [reinteractive](https://reinteractive.com/?ref=rubycentral.org) and Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org), and one new company. On top of those companies, 3 people signed up as members or friends of Ruby Together, including Stanislav (Stas) Katkov and Abu Nashir. In total, we were supported by 98 individual members and 70 friends of Ruby Together. Thanks to all of our members for making everything that we do possible. <3
The other Ruby Together news is pretty exciting!
To start with, we’ve brought on [@claudijd](https://twitter.com/claudijd?ref=rubycentral.org) as a new developer, focused on security improvements for RubyGems. He’ll be helping respond to security researcher reports, fix security issues, and do all of the inevitable paperwork that results.
Next, we’re extremely excited to announce that we are funding the upcoming, new, and improved [Ruby Toolbox](https://github.com/rubytoolbox/rubytoolbox?ref=rubycentral.org)! We’ll be paying [@thedeadserious](https://twitter.com/thedeadserious?ref=rubycentral.org) to rebuild the Ruby Toolbox back to its former glory, and beyond!
If you’re interested, you can also [read the announcement from the Ruby Toolbox side](https://github.com/rubytoolbox/rubytoolbox/issues/1?ref=rubycentral.org#issuecomment-333950079), or just keep reading to reach the very first Ruby Toolbox monthly update.
## bundler news
Bundler progress in September was steady. Along with @segiddins finishing off the last of his full-time summer hours, @arbonap continued to localize docs into Spanish, including automated tests for the Spanish documentation.
We released the 1.16 prerelease, discovered some bugs, fixed them, and [removed the message asking users to upgrade to prerelease versions](https://github.com/bundler/bundler/pull/6031?ref=rubycentral.org). We’re expecting a final 1.16 release sometime this month, since the latest prerelease is looking pretty stable.
After that, we’ll be starting on the path to 2.0: updating documentation, writing blog posts, testing the upgrade path, and more. Most of all, we’ll be making sure that Bundler 1.x and 2.x can coexist peacefully, so that no one is forced to upgrade or downgrade because of the projects they work on.
This month, Bundler gained 104 new commits, contributed by 14 authors. There were 1,220 additions and 417 deletions across 65 files.
## rubygems.org news
It was a quiet month for RubyGems.org… aside from the giant security issue, and the scramble to patch it, and then check every single existing gem to make sure it hadn’t been tampered with anytime in the last few years. The security issue was a big one, and potentially allowed any attacker to do anything they wanted to the RubyGems.org servers.
After adding fixes just to the RubyGems.org server, the combined RubyGems and RubyGems.org teams ultimately decided to patch RubyGems itself to ensure that this kind of issue can’t happen on other computers that use RubyGems, or other servers. For more information, check out [the RubyGems blog post about the security issue and its impact](http://blog.rubygems.org/2017/10/09/unsafe-object-deserialization-vulnerability.html?ref=rubycentral.org).
This month, Rubygems.org gained 4 new commits, contributed by 3 authors. There were 12 additions and 10 deletions across 7 files.
## rubygems news
RubyGems itself saw only a little bit of activity this month. As a result of @hsbt’s heroic work, Bundler has been merged into the version of RubyGems that ships with Ruby itself! Now we’ll need to keep changes in sync between all three of ruby-core trunk, the RubyGems master branch, and the Bundler master branch. Oh boy. 😬
On the bright side, you can already check out the fruits of all these teams’ labor in [Ruby 2.5-preview1](https://www.ruby-lang.org/en/news/2017/10/10/ruby-2-5-0-preview1-released/?ref=rubycentral.org). When you install Ruby 2.5, Bundler is included! 🎉
This month, Rubygems gained 10 new commits, contributed by 4 authors. There were 11 additions and 10 deletions across 5 files.
## gemstash news
Gemstash saw a few fixes and upgrades land this month, thanks to contributors @olleolleolle and @koic. It gained 13 new commits, contributed by 4 authors. There were 9 additions and 8 deletions across 5 files.
## ruby toolbox news
Hello everyone, great to be here :) I only just got started on bringing the Ruby Toolbox back the last week, but there’s already a place you can contribute to if you’d like: The categorization catalog is now on Github, and your help in cleaning it up, bringing it back up to date and expanding it is very welcome: [github.com/rubytoolbox/catalog](https://github.com/rubytoolbox/catalog?ref=rubycentral.org).
In the next weeks I will be working on the core app itself, trying to bring it back online as quickly as possible and expanding from there. Over at GitHub, you can read [a more detailed outlook on my planned next steps](https://github.com/rubytoolbox/rubytoolbox/issues/1?ref=rubycentral.org#issuecomment-333950079).
> — Christoph Olszowka, @thedeadserious
## budget & expenses
In September, we saw $25,145.47 in total income, and spent a total of $32,545.28.
- $16,915 for 112.8 hours worked on Bundler at $150/hour
- $1,590 for 10.6 hours worked on RubyGems.org at $150/hour
- $5,967.50 for 39.8 hours worked on RubyGems at $150/hour
- $2,902.50 for 19.4 hours worked on other OSS and devtools at $150/hour
- $80.37 on dedicated servers for RubyBench.org
- $811.53 on payment processing fees
- $2,469.72 on company overhead like hosting, services, software, hardware, taxes, etc
- $545 on accounting, copywriting, design, and other professional services
- $1,263.66 on marketing, evangelism, and community outreach
Until next time,
André and the Ruby Together team
### August 2017 Monthly Update
URL: https://rubycentral.org/news/august-2017-monthly-update/
Last updated: 2022-11-28T23:39:41.000Z
Hello! Welcome to the monthly update. During August, our work was supported by [reinteractive](http://reinteractive.com/?ref=rubycentral.org), [Stripe](http://stripe.com/?ref=rubycentral.org), [Gitlab](http://gitlab.com/?ref=rubycentral.org), [Travis CI](https://travis-ci.org/?ref=rubycentral.org), [Bleacher Report](http://www.bleacherreport.com/?ref=rubycentral.org), and many others.
## ruby together news
In August, Ruby Together was supported by 83 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). 2 companies joined as new members last month, including our first ever Ruby member, [reinteractive](http://reinteractive.com/?ref=rubycentral.org)!
On top of those companies, 2 new developers joined as friends of Ruby Together. In total, we were supported by 105 individual members and 72 friends of Ruby Together. Thanks to all of our members for making everything that we do possible. <3
In Ruby Together news, we successfully wrapped up a summer of full-time work from [@segiddins](https://github.com/segiddins?ref=rubycentral.org). His three months included a huge amount of extremely productive work, including:
- addressing several RubyGems security reports
- a RubyGems security release
- code to allow RubyGems to (optionally) release with Bundler built in
- two Bundler 1.16 preview releases
- addressing every outstanding blocker for [the Bundler 2.0 github milestone](https://github.com/bundler/bundler/issues?q=is%3Aissue+milestone%3A%222.0+%E2%80%94+Breaking+Changes%22+is%3Aclosed&ref=rubycentral.org)
On a slightly sadder note, founding board member [Steve Klabnik](https://twitter.com/steveklabnik?ref=rubycentral.org) has stepped down from the board of directors. The remaining directors will appoint an interim director to serve out the rest of Steve’s term, and we will have a board election soon. We’re incredibly grateful to Steve for his support in getting Ruby Together off the ground, and we wish him the best as he focuses on Rust! ❤️
Finally, the multiply-teased secret announcement is finally coming together, and we’ll be sharing details about it in the next update!
## bundler news
Building on the fantastic work done by Sam over the summer, RubyGems and ruby-core team member [@hsbt](https://github.com/hsbt?ref=rubycentral.org) spent countless hours to get the Bundler test suite passing inside the overall Ruby language test suite. As a result of that work, [Matz approved shipping Bundler with RubyGems, inside Ruby](https://bugs.ruby-lang.org/issues/12733?ref=rubycentral.org#note-14). Bundler was merged into the Ruby standard library in [revision 59780](https://bugs.ruby-lang.org/projects/ruby-trunk/repository/revisions/59779?ref=rubycentral.org), and is expected to ship with Ruby 2.5\. Thank you for all your help and hard work, hsbt! 🙇
Contributor [@arbonap](https://github.com/arbonap?ref=rubycentral.org) began [translating the Bundler website into Spanish](https://github.com/bundler/bundler-site/pull/328?ref=rubycentral.org), and has been enthusiastically assisted by several Spanish-speaking contributors. 💜
The work on Bundler last month was focused on changes for 2.0—we have finished adding feature flags for every change, and the difference between Bundler 1.x and Bundler 2.0 will be the default values for those settings! Bundler core team member [Colby Swandale](https://github.com/colby-swandale?ref=rubycentral.org) gave a talk at [RubyKaigi](http://rubykaigi.org/2017?ref=rubycentral.org) about Bundler 2, and the Bundler team has kicked off the process of shipping the 2.0 release.
That means we’ll be spending at least a few weeks, and possibly a few months, testing workflows, updating documentation, writing blog posts, and working with users to ensure that the transition will be as smooth as possible. If you’re interested in trying it out and helping us improve the upgrade process, we would love to hear from you in [the Bundler Slack](https://slackin.bundler.io/?ref=rubycentral.org)!
This month, Bundler gained 144 new commits, contributed by 15 authors. There were 2,395 additions and 730 deletions across 154 files.
## rubygems.org news
To help Bundler and RubyGems users connect to RubyGems.org in the future, [@indirect](https://github.com/indirect?ref=rubycentral.org) and [@rubymorillo](https://github.com/rubymorillo?ref=rubycentral.org) worked together to [expand the SSL troubleshooting guide](https://github.com/bundler/bundler-site/pull/324?ref=rubycentral.org). We’d love to get your feedback on [the work-in-progress guide](https://github.com/bundler/bundler-site/blob/067698ae7b77a2769653315799f8741d74c73d52/source/v1.15/guides/rubygems%5Ftls%5Fssl%5Ftroubleshooting%5Fguide.html.md?ref=rubycentral.org), so check it out!
RubyGems.org saw ongoing maintenance, including gem upgrades, server upgrades, and other small improvements, as well as work on the database servers. In August, the RubyGems.org repo gained 15 commits, contributed by 7 authors. There were 52 additions and 57 deletions across 11 files.
## rubygems news
RubyGems saw ongoing maintenance and bugfixes, as well as patches for several security issues, included in the [security release of version 2.6.13](http://blog.rubygems.org/2017/08/27/2.6.13-released.html?ref=rubycentral.org). If you’re unable to upgrade to the latest RubyGems, check out [the backport patches for Ruby 2.2, 2.3, and 2.4](https://www.ruby-lang.org/en/news/2017/08/29/multiple-vulnerabilities-in-rubygems/?ref=rubycentral.org). In total, Rubygems gained 57 new commits, contributed by 11 authors. There were 978 additions and 302 deletions across 38 files.
## gemstash news
On August 21, Google Cloud Platform announced [google-cloud-gemserver](https://github.com/GoogleCloudPlatform/google-cloud-gemserver?ref=rubycentral.org), a new gem from a summer intern to make running Gemstash on GCP as easy as running Gemstash on your local machine, which is super cool! You can read more about it [in the announcement blog post](https://cloudplatform.googleblog.com/2017/08/rolling-your-own-private-Ruby-gem-server-on-Google-Cloud-Platform.html?ref=rubycentral.org).
Unfortunately, when the project was announced, I (André) jumped to conclusions and [accused the project of violating Gemstash’s MIT license](https://github.com/GoogleCloudPlatform/google-cloud-gemserver/issues/36?ref=rubycentral.org). My post was unreasonably aggressive, and I shouldn’t have posted it, even if I had been right… which I wasn’t. I turned out to be completely wrong, and [apologized to the author](https://github.com/GoogleCloudPlatform/google-cloud-gemserver/issues/36?ref=rubycentral.org#issuecomment-324503159) a few hours later.
Sorry for letting you down, everyone. 💔 I’ll try to be much more careful, and more gentle, in the future.
Gemstash itself saw regular ongoing maintenance: the unyank command was removed, to mirror rubygems.org, and the tests were updated to run against the latest JRuby version. This month, Gemstash gained 19 new commits, contributed by 2 authors. There were 22 additions and 381 deletions across 20 files.
## budget & expenses
In August, we saw $19,140 in total income, and spent a total of $26,217.61.
- $13,821 for 92.1 hours worked on Bundler at $150/hour
- $4,774 for 31.8 hours worked on RubyGems.org at $150/hour
- $446 for 3.0 hours worked on RubyGems at $150/hour
- $1,871 for 12.5 hours worked on other OSS and devtools at $150/hour
- $78.97 on dedicated servers for RubyBench.org
- $638.86 on payment processing fees
- $1,986.12 on company overhead like hosting, services, software, hardware, taxes, etc
- $1,287.50 on accounting, copywriting, design, and other professional services
- $1,313.66 on marketing, evangelism, and community outreach
Until next time,
André and the Ruby Together team
### July 2017 Monthly Update
URL: https://rubycentral.org/news/july-2017-monthly-update/
Last updated: 2022-11-28T23:39:43.000Z
Hello! Welcome to the monthly update for Ruby Together, a non-profit trade association dedicated to maintaining and improving developer tools for the Ruby programming language.
During the month of July, we released two bugfix versions of Bundler, planned for the future, and made progress towards keeping RubyGems.org working for the months and years to come. Read on for more details!
Last month, our work was supported by [Stripe](http://stripe.com/?ref=rubycentral.org), [Gitlab](http://gitlab.com/?ref=rubycentral.org), [Cloud City](http://cloudcity.io/?ref=rubycentral.org), [Digital Ocean](http://digitalocean.com/?ref=rubycentral.org), [Bleacher Report](http://www.bleacherreport.com/?ref=rubycentral.org), and [viewers like you](http://rubytogether.org/join?ref=rubycentral.org).
If you’re not a member yet, you can learn more and help support our work at [rubytogether.org](https://rubytogether.org/?ref=rubycentral.org).
## ruby together news
It was pretty quiet on the Ruby Together front—no new hires, but lots of ongoing work to make using Ruby easier and more reliable.
In July, Ruby Together was supported by 79 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). On top of those companies, 1 new developer signed up a friend of Ruby Together, Josh Justice.
In total, we were supported by 109 individual members and 72 friends of Ruby Together last month. Thanks to all of our members for making everything that we do possible. <3
## bundler news
A lot happened with Bundler in July! We released two bugfix versions of Bundler, version [1.15.2](https://github.com/bundler/bundler/blob/v1.15.3/CHANGELOG.md?ref=rubycentral.org#1152-2017-07-17) and version [1.15.3](https://github.com/bundler/bundler/blob/v1.15.3/CHANGELOG.md?ref=rubycentral.org#1153-2017-07-21).
In addition to industriously fixing bugs, the indomitable [@segiddins](https://github.com/segiddins?ref=rubycentral.org) has been working full-time over the summer towards Bundler 2.0\. We made significant progress: the test suite now runs (and passes!) with all 2.0 feature flags turned on, and it is possible to build and install a development version of Bundler 2\. Our next steps will be wrapping up the expected changes, and then testing and smoothing the path to migrate from version 1.x to version 2.
Even though Bundler 2 will contain changes to default settings and command options, it’s incredibly important to us that all existing projects continue to work without breaking, and that each individual application can choose to switch from Bundler 1 to Bundler 2 at a time that’s best for them.
In addition to the work on 2.0, there were two new RFC proposals. RFCs are detailed writeups of potential changes, describing those changes in a way that can be evaluated and discussed before implementation work starts. The two new RFCs in July were:
- [Add a bundle deploy command](https://github.com/bundler/rfcs/blob/aa-deploy-command/text/0000-bundle-deploy-command.md?ref=rubycentral.org)
- [Add a bundle groups command](https://github.com/bundler/rfcs/blob/49e08ccf04579a92c394e438074ca7e277d036f5/text/0000-bundle-groups.md?ref=rubycentral.org)
If you’re interested in the way that Bundler handles deploys or gem groups, we’d love to hear your feedback on the open proposals.
Finally, a special thanks to the new contributors to Bundler in the month of July:
- [arbonap](https://github.com/arbonap?ref=rubycentral.org)
- [deivid-rodriguez](https://github.com/deivid-rodriguez?ref=rubycentral.org)
- [greysteil](https://github.com/greysteil?ref=rubycentral.org)
- [koic](https://github.com/koic?ref=rubycentral.org)
- [NickLaMuro](https://github.com/NickLaMuro?ref=rubycentral.org)
- [roberts1000](https://github.com/roberts1000?ref=rubycentral.org)
- [rubymorillo](https://github.com/rubymorillo?ref=rubycentral.org)
- [stefansedich](https://github.com/stefansedich?ref=rubycentral.org)
- [xxx](https://github.com/xxx?ref=rubycentral.org)
In total, Bundler gained 160 new commits, contributed by 14 authors. There were 7,101 additions and 1,381 deletions across 805 files.
Thanks for your hard work, everyone!
## rubygems.org news
This month was quieter for RubyGems.org, but we did regular maintenance, installed security updates, and generally kept everything running. Most of the time that we spent this month was work on an in-progress SSL troubleshooting guide.
Next year, we’ll be migrating RubyGems.org to require TLS v1.2 or newer, which is why we’re focused on writing and shipping an excellent troubleshooting and upgrade guide before that happens. When the guide is finished, it will be a fantastic resource for anyone having trouble with HTTPS connections from Ruby.
Merged features included dependency updates, copy fixes, and a security fix of throttling requests to change or delete user profiles. Overall, Rubygems.org gained 23 new commits, contributed by 4 authors. There were 84 additions and 66 deletions across 20 files.
## rubygems news
RubyGems saw some small changes and documentation updates, but stayed pretty stable. We’ve started working with ruby-core team member [@hsbt](https://github.com/hsbt?ref=rubycentral.org) on getting RubyGems and Bundler to be tested together as part of the Ruby build. Once that is done, it should be much harder for changes to Ruby to break anything inside RubyGems or Bundler, which will be a huge help.
This month, Rubygems gained 29 new commits, contributed by 7 authors. There were 348 additions and 102 deletions across 23 files.
## gemstash news
Gemstash didn’t see any new features this month, but we did finally release [version 1.1.0](https://github.com/bundler/gemstash/blob/master/CHANGELOG.md?ref=rubycentral.org#110-2017-07-31). Along with adding MySQL support, Gemstash now supports `gem install`, as well as [protected fetching](https://github.com/bundler/gemstash/blob/master/docs/gemstash-private-gems.7.md?ref=rubycentral.org#protected-fetching) for hosting completely private gems that are only available to authorized users.
## budget & expenses
In July, we saw $43,114.34 in total income, and spent a total of $25,303.55.
- $9,109 for 60.7 hours worked on Bundler at $150/hour
- $8,396 for 56 hours worked on RubyGems.org at $150/hour
- $900 for 6 hours worked on RubyGems at $150/hour
- $3,000 for 20 hours worked on other OSS and devtools at $150/hour
- $76.11 on dedicated servers for RubyBench.org
- $639.20 on payment processing fees
- $2,339.50 on company overhead like hosting, services, software, hardware, taxes, etc
- $470 on accounting, copywriting, design, and other professional services
- $373.74 on marketing, evangelism, and community outreach
Until next time,
André and the Ruby Together team
### May and June 2017 Monthly Update
URL: https://rubycentral.org/news/may-and-june-2017-monthly-update/
Last updated: 2022-11-28T23:39:41.000Z
Hello! Welcome to the monthly update. During May and June, we paid for 179.4 hours of developer work on Bundler, RubyGems, and other open source tools. Our work was supported by [Stripe](http://stripe.com/?ref=rubycentral.org), [Basecamp](https://basecamp.com/?ref=rubycentral.org), [Icelab](http://icelab.com.au/?ref=rubycentral.org), [Gitlab](http://gitlab.com/?ref=rubycentral.org), [Cloud City](http://cloudcity.io/?ref=rubycentral.org), and many others.
## ruby together news
In May and June, Ruby Together was supported by 81 different companies, including Sapphire member [Stripe](https://stripe.com/?ref=rubycentral.org). 3 companies joined as new members, including [Day of the Shirt](https://dayoftheshirt.com/?ref=rubycentral.org) and [ClickFunnels](http://www.clickfunnels.com/?ref=rubycentral.org).
On top of those companies, 6 new developers signed up as members or friends of Ruby Together, including Josh Cass, Mark Tareshawty, Anıl İyidoğan, Dian Pan, and Sangwon Yi. In total, we were supported by 113 individual members and 73 friends of Ruby Together. Thanks to all of our members for making everything that we do possible. <3
In company news, we’ve brought [@therubyrep](https://twitter.com/therubyrep?ref=rubycentral.org) onboard to help with admininstration work, including compiling these updates! We’re expecting to be more timely in the future as a result of her help.
For project work, we have three announcements: The indomitable [@segiddins](https://twitter.com/segiddins?ref=rubycentral.org) has agreed to work on Bundler and RubyGems full time over the summer, and we’ve already seen that start to pay off in the form of countless Bundler PRs working towards Bundler 2.
Next, [@radiomorillo](https://twitter.com/radiomorillo?ref=rubycentral.org) has joined us to help us craft a RubyGems.org SSL troubleshooting guide. Historically, we’ve seen many users report problems with SSL certificates, depending on their exact OS, OpenSSL installation, Ruby version, and other factors besides. In the future, we’re expecting many new issue reports when RubyGems.org deprecates versions of TLS older than 1.2\. Hopefully, we’ll come up with a guide that can help everyone get their issues sorted out and get back to installing gems.
Finally, we’ve also asked [@parbona](https://twitter.com/patricia%5Farbona?ref=rubycentral.org) to help us review and revise Bundler’s website and documentation with an eye towards helping and supporting new users and contributors. In the future, we’d love to get the documentation to a point where new developers can use the Bunlder docs to get started, rather than (usually) needing to be led through the process with explanations from more experienced developers.
The secret announcement we teased last time isn’t quite ready yet, but we think you’ll be pleased once you hear it. Keep holding on, and we’ll get there!
## bundler news
In May and June, Bundler saw the release of 1.15 final, and the 1.15.1 bugfix release. The biggest changes in Bundler were: a huge speedup to `bundle exec` on large gemfiles, a new `bundle issue` command, a new `bundle add` command, and a new `bundle pristine` command. We also (finally) shipped man pages for every Bundler command that currently exists, and plan to maintain full manpage coverage for all future releases. If you’re interested in those changes, you can read more in [the Bundler 1.15 release announcement](http://bundler.io/blog/2017/05/19/bundler-1-15-bundle-oh-so-fast.html?ref=rubycentral.org), or just upgrade right away by running `gem install bundler`.
Along with the 1.15 release, we kicked off a realistic plan towards releasing Bundler 2.0\. Rather than forking into two codebases, we are implementing all of our planned changes for 2.0 as feature flags, disabled by default. Anyone interested can try out all of the changes that we’ve finished implementing so far by setting the relevant feature flags. Once everything is complete, we’ll be able to release a 2.0 with the new default settings, and it’s shaping up to be really great so far. It’s incredibly exciting to see (literally) years of planning pay off.
In total, Bundler gained 248 new commits, contributed by 20 authors. There were 7,861 additions and 1,991 deletions across 920 files.
## rubygems.org news
RubyGems.org saw a new [advanced search page](https://github.com/rubygems/rubygems.org/pull/1603?ref=rubycentral.org), updates to Rails and many other gems, and fixes to various and sundry bugs, including validations for email length, session expiration, and visual bugs on the 404 page.
Overall, Rubygems.org gained 88 new commits, contributed by 9 authors. There were 1,375 additions and 764 deletions across 246 files.
## rubygems news
The RubyGems library also got some love, seeing new `signin` and `signout` commands for explicit authorization to RubyGems.org. There were also performance improvements and bugfixes from @segiddins. Rubygems gained 43 new commits, contributed by 11 authors. There were 365 additions and 112 deletions across 28 files.
## gemstash news
Gemstash gained a new comprehensive health check, allowing automated systems to see whether a given Gemstash server is able to respond, reach the file storage, and reach the database. Ultimately, Gemstash gained 7 new commits, contributed by 1 author. There were 181 additions and 1 deletion across 12 files.
## budget & expenses
In May, we saw $21,080.00 in total income, and spent a total of $19,089.33.
- $7275 for 48.5 hours worked on Bundler at $150/hour
- $3363 for 22.4 hours worked on RubyGems.org at $150/hour
- $3525 for 23.5 hours worked on RubyGems at $150/hour
- $1688 for 11.3 hours worked on other OSS and devtools at $150/hour
- $73.32 on dedicated servers for RubyBench.org
- $696.66 on payment processing fees
- $1588.37 on company overhead like hosting, services, software, hardware, taxes, etc
- $745.0 on accounting, copywriting, design, and other professional services
- $135.98 on marketing, evangelism, and community outreach
In June, we saw $20,880 in total income, and spent a total of $16,407.31.
- $4805 for 32.0 hours worked on Bundler at $150/hour
- $3096 for 20.6 hours worked on RubyGems.org at $150/hour
- $1098 for 7.3 hours worked on RubyGems at $150/hour
- $2167 for 14.4 hours worked on other OSS and devtools at $150/hour
- $75.34 on dedicated servers for RubyBench.org
- $696.82 on payment processing fees
- $1510.45 on company overhead like hosting, services, software, hardware, taxes, etc
- $620.0 on accounting, copywriting, design, and other professional services
- $2339.7 on marketing, evangelism, and community outreach
Until next time,
André and the Ruby Together team
### April 2017 Monthly Update
URL: https://rubycentral.org/news/april-2017-monthly-update/
Last updated: 2022-11-28T23:39:41.000Z
Hello! Welcome to the monthly update. During April, our work was supported by [Stripe](http://stripe.com/?ref=rubycentral.org), [CodeMiner42](http://www.codeminer42.com/?ref=rubycentral.org), [Cloud City](http://cloudcity.io/?ref=rubycentral.org), [Gitlab](http://gitlab.com/?ref=rubycentral.org), [Digital Ocean](http://digitalocean.com/?ref=rubycentral.org), and many others.
## ruby together news
Last month, Ruby Together was supported by 79 different companies, including Sapphire members [Stripe](https://stripe.com/?ref=rubycentral.org) and [CodeMiner42](http://www.codeminer42.com/?ref=rubycentral.org). Two companies joined as new members, including [Atomic Object](https://atomicobject.com/?ref=rubycentral.org) and [Honeybadger](https://honeybadger.io/?ref=rubycentral.org).
On top of those companies, three developers signed up to be friends of Ruby Together, and two new developers joined as members, Dominic Dagradi and Ambreen Hasan. In total, we were supported by 115 individual members and 76 friends of Ruby Together. Thanks to all of our members for making everything that we do possible. <3
April saw us continue to move forward with plans for funding additional Ruby projects. We can’t announce it just yet, but [follow us on twitter](https://twitter.com/rubytogether?ref=rubycentral.org) or read next month’s newsletter for what will hopefully be an exciting announcement.
Some other plans moved forward as well, and we launched our [public feedback forum](https://github.com/rubytogether/feedback?ref=rubycentral.org). Since the beginning, Ruby and RubyGems have been maintained and advanced by a small group of passionate volunteers. We have all of them to thank for the large, vibrant community that exists today. However, Ruby has matured to the point where its supporting infrastructure is both vital to the larger internet economy, and can no longer be maintained by a few volunteers.
We created Ruby Together to allow Ruby devs and companies to collectively pay developers for their time and effort working on central and critical projects. That said, our primary goal is to to serve and improve the entire Ruby community.
To help us do that more effectively, we’re creating this repo as a collaborative forum where anyone who is passionate about Ruby open source and infrastructure can share and discuss their ideas, opinions, and concerns with each other and with the Ruby Together team. Membership is Ruby Together is not required to participate or give feedback, and all feedback will be read and considered as we decide how to best support the Ruby community in the future. Come by and [tell us how you think we’re doing](https://github.com/rubytogether/feedback/issues?ref=rubycentral.org)!
## bundler news
Last month, we started pushing prereleases of Bundler 1.15\. As of today, we’re up to version 1.15.0.pre.4, and it’s looking increasingly likely that the next version will be the release candidate. Highlight features for 1.15 include man pages for all commands (thanks, @feministy!), a `bundle issue` command to help users report problems (thanks, @jonathanpike!), and a `bundle add` command (thanks, @denniss!).
On top of those changes, version 1.15 will also include dramatically improved performance when loading Bundler in applications with hundreds of gems, and the huge improvement to error messages when a matching version can’t be found that we mentioned in [our last monthly update](https://rubytogether.org/news/2017-04-18-march-2017-monthly-update?ref=rubycentral.org).
Many other bugs were fixed, and additional smaller features have been added. Check out [the Bundler changelog](https://github.com/bundler/bundler/blob/master/CHANGELOG.md?ref=rubycentral.org) for the full details. In total, this month 13 authors pushed 149 commits, including 1,668 additions and 306 deletions across 78 files.
## rubygems.org news
The biggest event for RubyGems.org this month was [Fastly’s planned deprecation of TLS 1.0 and 1.1](https://www.fastly.com/blog/phase-two-our-tls-10-and-11-deprecation-plan/?ref=rubycentral.org). We didn’t realize it beforehand, but many, many developers and servers are still using Ruby without support for TLS 1.2\. We were surprised because support for TLS 1.2 was added to OpenSSL [in version 1.0.1 on March 14, 2012](https://en.wikipedia.org/wiki/OpenSSL?ref=rubycentral.org#Major%5Fversion%5Freleases), over five years ago! In a group effort, we were able to work together with [Ruby Central](http://rubycentral.org/) and [Fastly](https://www.fastly.com/?ref=rubycentral.org) to quickly add back support for the older TLS 1.0 and 1.1.
Unfortunately, the PCI Security Standards Council’s requirements mean that Fastly will be disabling TLS 1.0 and 1.1 for all users, including RubyGems.org, at the end of April 2018\. This month, we started working on an early warning system that will inform Ruby developers if they need to upgrade, and we will roll it out later this year to make sure that everyone has plenty of time to adjust before the older versions of TLS are disabled again.
In total, RubyGems.org gained 21 new commits, with 4 different contributors changing 63 files. There were 851 additions and 305 deletions.
## rubygems news
For RubyGems, April saw the release of version 2.6.12\. Fixes include installing gems on MinGW systems, the `gem open` command once again opening the newest version of a gem by default, and generating binstubs (like the file named `rake`, used to run rake commands) that will work with both current and older versions of RubyGems. In total, RubyGems saw 17 new commits from 6 different contributors. They changed 16 files, with 162 additions and 61 deletions.
## gemstash news
Gemstash didn’t see any major changes during April, but it’s still a solid option if you need to host your own private gems or set up a local cache for RubyGems.org on your machine, in your office, or in your datacenter. In total, Gemstash gained 3 new commits. 2 different authors changed 5 files, with 37 additions and 6 deletions.
## budget & expenses
In April, we saw $22,252 in total income, and spent a total of $9,479.49.
- $1,950 for 13.0 hours worked on Bundler at $150/hour
- $1,538 for 10.3 hours worked on RubyGems.org at $150/hour
- $975 for 6.5 hours worked on RubyGems at $150/hour
- $1,388 for 9.3 hours worked on other OSS and devtools at $150/hour
- $71.77 on dedicated servers for RubyBench.org
- $732.52 on payment processing fees
- $1,166.63 on company overhead like hosting, services, software, hardware, taxes, etc
- $150.0 on accounting, copywriting, design, and other professional services
- $1,508.57 on marketing, evangelism, and community outreach
Until next time,
André and the Ruby Together team
### March 2017 Monthly Update
URL: https://rubycentral.org/news/march-2017-monthly-update/
Last updated: 2022-11-28T23:39:41.000Z
Hello! Welcome to the monthly update. During March, our work was supported by [Stripe](http://stripe.com/?ref=rubycentral.org), [CodeMiner42](http://www.codeminer42.com/?ref=rubycentral.org), [Basecamp](http://basecamp.com/?ref=rubycentral.org), [Icelab](http://icelab.com.au/?ref=rubycentral.org), [Bleacher Report](http://www.bleacherreport.com/?ref=rubycentral.org), and many others.
## ruby together news
On the whole, this month was pretty quiet. We filed our taxes, worked on some plans for the future, and continued to pay for developer hours to maintain Ruby’s tooling infrastructure.
In March, Ruby Together was supported by 88 different companies, including [Stripe](#) and [CodeMiner42](#). Four companies joined as new members, including [Brandeis University](https://www.brandeis.edu/?ref=rubycentral.org), [Scout RFP](http://www.scoutrfp.com/?ref=rubycentral.org), and [Modern Message](http://www.modernmsg.com/?ref=rubycentral.org).
On top of those companies, three developers signed up as friends of Ruby Together, including Byron Appelt. In total, we were supported by 183 individual members and 91 friends of Ruby Together. Thanks to all of our members for making everything that we do possible. <3
## bundler news
During March, we fixed bugs and started merging new features for Bundler 1.15\. The most exciting change is a much clearer explanation when a Gemfile cannot be resolved.
Previously, any requirement for a failed gem would be printed out. That meant the error message would include things like “Could not resolve requirement `rack ~> 10.1`, Gemfile contained `rack 10.2`”. Since Rack version 10.2 is allowed by that requirement, it was not helpful to include it in the error message. Error messages when resolution fails in the future will be much easier to understand, since they will only include the requirements that could not be met.
A host of additional small features and fixes were added as well. Check out [the Bundler changelog](https://github.com/bundler/bundler/blob/master/CHANGELOG.md?ref=rubycentral.org) to read about all of them. In total, Bundler gained 78 new commits. 16 different contributors changed 51 files, with 638 additions and 151 deletions.
## rubygems.org news
RubyGems.org saw updates to better validate incoming data, improve performance, and add a content security policy. We also merged support for self-service account deletion and about a dozen gem updates. In total, RubyGems.org gained 21 new commits. 4 different contributors changed 63 files, with 851 additions and 305 deletions.
## rubygems news
Version 2.6.11 of RubyGems was released, with improvements to resolving gem dependencies, a fix for gems compiled on MinGW, and a couple of bugfixes backported from Ruby trunk. In total, RubyGems gained 17 new commits. 6 different contributors changed 16 files, with 162 additions and 61 deletions.
## gemstash news
Gemstash gained the new feature of logging directly to stdout, making it easier to integrate with services like Heroku that expect logs to be printed. In total, Gemstash gained 3 new commits. 2 different authors changed 5 files, with 37 additions and 6 deletions.
## budget & expenses
In March, we saw $23,033 in total income, and spent a total of $16,881.76.
- $4,256 for 28.4 hours worked on Bundler at $150/hour
- $1,919 for 12.8 hours worked on RubyGems.org at $150/hour
- $2,063 for 13.8 hours worked on RubyGems at $150/hour
- $1,125 for 7.5 hours worked on other OSS and devtools at $150/hour
- $71.30 on dedicated servers for RubyBench.org
- $755.32 on payment processing fees
- $1,623.79 on company overhead like hosting, services, software, hardware, taxes, etc
- $5,000.00 on accounting, copywriting, design, and other professional services
- $68.85 on marketing, evangelism, and community outreach
Until next time,
André, Joel and the Ruby Together team
### January and February 2017 Monthly Update
URL: https://rubycentral.org/news/january-and-february-2017-monthly-update/
Last updated: 2022-11-28T23:39:41.000Z
Hello, everyone! Welcome to the monthly update—or in this particular case, two monthly updates. During the months of January and February, our work was supported by [Stripe](http://stripe.com/?ref=rubycentral.org), [CodeMiner42](http://www.codeminer42.com/?ref=rubycentral.org), [DigitalOcean](http://www.digitalocean.com/?ref=rubycentral.org), [Travis CI](https://travis-ci.org/?ref=rubycentral.org), [thoughtbot](https://thoughtbot.com/?ref=rubycentral.org), and many, many others.
## ruby together news
In some ways, January and February were boring and run-of-the-mill: we paid developers to work on open source, and Ruby OSS infrastructure was maintained and improved. We were supported by 84 companies, including [Travis](http://travis-ci.com/?ref=rubycentral.org), [Airbnb](http://www.airbnb.com/?ref=rubycentral.org), and [GitLab](http://gitlab.com/?ref=rubycentral.org) all renewing their memberships for the entire year of 2017\. 13 companies joined as new members, including [Evil Martians](https://evilmartians.com/?ref=rubycentral.org), [makandra](https://makandra.com/?ref=rubycentral.org), [Substance Lab](http://substancelab.com/?ref=rubycentral.org), [Instrumental](https://instrumentalapp.com/?ref=rubycentral.org), [Buildkite](https://buildkite.com/?ref=rubycentral.org), [DocRaptor](https://docraptor.com/?ref=rubycentral.org), [Evolving Media Network / Moonfarmer](http://www.evolvingmedia.net/?ref=rubycentral.org), [Newington College](https://newington.nsw.edu.au/?ref=rubycentral.org), [MAKEMUSIC](http://www.makemusic.com/?ref=rubycentral.org), and [Ben Lovell Ltd](https://github.com/benlovellltd?ref=rubycentral.org).
On top of those companies, 42 developers signed up as friends of Ruby Together, and 18 developers signed up as members, including Jon Atack, Eric Henderson, Nichol Alexander, Bess Sadler, Daniel Fone, Spencer Roach, Jeff Sandberg, Ivan Stana, Piotr Szmielew, Daniel Leavitt, Andrei Beliankou, Matthew Werner, Eliot Sykes, and Richard Harrah. In total, we were supported by over 180 individual members and 88 friends of Ruby Together. Thanks to all of our members for making everything that we do possible. <3
In some other ways, though, these months were surprisingly eventful: the Ruby Together board was approached in private by a group of concerned developers. The feedback those developers gave broke down into three categories. First, the Bundler post-install message was unfortunately misleading some people into thinking that Ruby Together pays for the RubyGems.org servers, when that is not the case. Second, they were concerned that Ruby Together could be seen as a way for André and the other funded maintainers to blackmail companies into paying Ruby Together for features or bugfixes. Finally, the group said they also felt upset there was no official avenue to accept their feedback to Ruby Together.
The Ruby Together board listened to their feedback, and will be addressing all three points. To start with, the Bundler team has removed the Bundler post-install message until they can come up with a clearer one. The Bundler readme has also been revised to clarify what Ruby Together pays for, and make it clear that feature requests will always be evaluated on their own merits, not based on whether the person or company proposing the feature is a member.
Towards addressing the second point, we have started work on an official project funding policy. The policy will make our criteria for funding projects public, as well as detailing the mechanisms we employ to separate recipients of funds from decisions about funding them. Keep an eye out for that policy in a separate announcement in the coming weeks.
Finally, in order to help Ruby Together accomplish its goal of serving the entire community, we will be establishing a public feedback group just for Ruby Together. We will use that forum to open discussion of policy and funding issues, and especially to get feedback on proposed plans before they are implemented. Participation will be open to anyone who uses Ruby, not just members. Our work is for the whole community, and we want to hear from all of them.
## bundler news
The exciting news for Bundler in this update is a feature release: 1.14\. Version 1.14 validates downloaded .gem files against checksums provided by RubyGems.org, it improves support for running a single bundled application on more than one OS, and shows dramatically more information if the Ruby or RubyGems version conflicts with gem requirements.
After releasing 1.14 final, we continued to fix reported bugs, including a small number of regressions. Between Dec 29 and Feb 22, we pushed 5 bugfix releaseso fixing many reported issues and repairing compatibility with the upcoming Ruby 2.5 release. In total, Bundler merged 106 pull requests that included 152 commits. 24 different contributors changed 266 files, with 3,135 additions and 1,066 deletions.
## rubygems.org news
Over on RubyGems.org, changing your email address got more reliable: we now require verification of your new email address before removing your old one. Along with the usual security updates, we also dramatically improved the performance of the inverse dependencies API. In total, RubyGems.org merged 3 pull requests including 89 commits. 12 different contributors changed 95 files, with 2,477 additions and 1,838 deletions.
## rubygems news
There were two bugfix releases of RubyGems, version 2.6.9 and 2.6.10, fixing six miscellaneous bugs and updating the dependency resolver shared with Bundler and CocoaPods. In total, RubyGems merged 33 pull requests that included 33 commits, and 9 contributors changed 40 files, with 569 additions and 158 deletions.
## gemstash news
Gemstash released version 1.0.4, adding private gem support for the `latest_gems` endpoint used by `gem install`. In total, Gemstash merged 2 pull requests that included 26 commits. 5 contributors changed 19 files, with 387 additions and 87 deletions.
## budget & expenses
In the months of January and February combined, we saw $45,031 in total income, and spent a total of $44,893.72.
- $9,994 for 66.6 hours worked on Bundler at $150/hour
- $10,134 for 67.6 hours worked on RubyGems.org at $150/hour
- $2,505 for 16.7 hours worked on RubyGems at $150/hour
- $2,543 for 17.0 hours worked on other OSS and devtools at $150/hour
- $142.09 on dedicated servers for RubyBench.org
- $1465.08 on payment processing fees
- $5337.41 on company overhead like hosting, services, software, hardware, taxes, etc
- $8025.0 on accounting, copywriting, design, and other professional services
- $4749.14 on marketing, evangelism, and community outreach
Until next time,
André and the Ruby Together team
### December 2016 Monthly Update
URL: https://rubycentral.org/news/december-2016-monthly-update/
Last updated: 2022-11-28T23:39:41.000Z
Happy new year, everyone, and welcome to the (only *slightly* delayed by the holidays 😂) Ruby Together monthly update for December! During the month of December, our work was supported by [Stripe](http://stripe.com/?ref=rubycentral.org), [CodeMiner42](http://www.codeminer42.com/?ref=rubycentral.org), [Basecamp](https://basecamp.com/?ref=rubycentral.org), [Airbnb](http://airbnb.com/?ref=rubycentral.org), [Gitlab](http://gitlab.com/?ref=rubycentral.org), and many, many others.
## ruby together news
To start things off, December was our biggest month ever since Ruby Together began. We were supported by over 100 individual developers, 60 small companies, and a dozen large companies like [Stripe](http://stripe.com/?ref=rubycentral.org), [CodeMiner42](http://www.codeminer42.com/?ref=rubycentral.org), [Basecamp](https://basecamp.com/?ref=rubycentral.org), [Airbnb](http://airbnb.com/?ref=rubycentral.org), and [Gitlab](http://gitlab.com/?ref=rubycentral.org).
This month was also a great month for new members. Six new developers signed up to support our work as Friends of Ruby Together. On top of that, ten more developers joined as members, including Nishant Modak, Thom May, Jack Bracewell, George Millo, Karlotcha Hoa, Stanislav Katkov, Chris Holmes. In addition, five completely new companies added their support: [Chef](https://www.chef.io/?ref=rubycentral.org), [Unboxed](http://www.unboxed.co/?ref=rubycentral.org), [Carbon Five](http://carbonfive.com/?ref=rubycentral.org), [Teezily](https://teezily.com/?ref=rubycentral.org), and [Intellum](http://www.intellum.com/?ref=rubycentral.org).
Thanks to all of our members for making everything that we do possible. <3
In exciting news for the upcoming year, our team gained an Empress of Documentation: [Liz Abinante](https://twitter.com/feministy?ref=rubycentral.org). We’re super excited to have a mastermind behind making Bundler and RubyGems more understandable and accessible for new users.
On the board of directors, we saw [Ines Sombra](http://twitter.com/randommood?ref=rubycentral.org) step down from her position. Ines has been a fantastic and incredibly helpful board member, and we’re super grateful to have had her input. Thanks for everything, Ines. <3
The remaining members of the board nominated [Camille Baldock](https://twitter.com/camille%5F?ref=rubycentral.org) to fill the newly empty seat, and she graciously accepted. Camille participated in this year’s board election, coming in just one or two votes behind the other candidates. We’re incredibly glad to have another chance to work with Camille, and are looking forward to getting even more done in 2017.
## bundler news
December was a good month for Bundler. We released one bugfix release, `1.13.7`, and we released a preview of the next version of Bundler, version `1.14.0.pre.1`. 13 contributors created 99 commits, and changed 63 files with 783 additions and 193 deletions.
Bundler 1.14 includes a huge number of bugfixes and small additional features, mostly focused on improving how well existing commands work. Support for different operating systems and platforms is improved, Ruby 2.5 (compiled from source control) is supported, and a notable error caused by an invalid lock file is now handled automatically. For a full list of improvements, [check out the changelog](https://github.com/bundler/bundler/blob/master/CHANGELOG.md?ref=rubycentral.org#1140pre1-2016-12-29).
## rubygems.org news
The RubyGems.org service was given the usual security updates this month, and saw a couple of useful fixes. Changing email addresses now requires confirmation before activation, so users can’t lock themselves out with a typo. 9 contributors created 47 commits, changing 59 files with 565 additions and 202 deletions.
## rubygems news
RubyGems continued to gain ground on the backlog of bugs and issues. The most notable changes were speed improvements for `require 'rubygems'`, and a fix for hash collisions when comparing objects. 4 contributors created 16 commits, changing 11 files with 88 additions and 48 deletions.
## gemstash news
Gemstash wasn’t super busy, but still gained some features: it is now possible to set arbitrary Sequel connection options, and the connection pool now defaults to the same size as the number of running Puma threads. In total, 2 contributors made 8 commits, changing 7 files with 41 additions and 6 deletions.
## budget & expenses
From November 20 to December 19, Ruby Together took in $22,620\. In total, we spent $23,552.35\. Here’s a breakdown of where the money went:
- $3,600 for 24 hours worked on Bundler at $150/hour
- $3,000 for 20 hours worked on RubyGems.org at $150/hour
- $2,850 for 19 hours worked on RubyGems at $150/hour
- $2,250 for 15 hours worked on other OSS and dev tools at $150/hour
- $71.65 on dedicated servers for RubyBench.org
- $709.74 on payment processing fees
- $1,868.6 on company overhead like hosting, services, software, hardware, taxes, etc
- $5,250.0 on accounting, copywriting, design, and other professional services
- $3,989.86 on marketing, evangelism, and community outreach
As always, if you’d like to spread the word about Ruby Together or just wear some great-looking shirts, check out the [Ruby Together shop](https://shop.rubytogether.org/?ref=rubycentral.org). It’s also the only worldwide source for Bundler packing tape! 😎
Keep an eye out for our much more timely January update, coming in about a week!
Until next time,
André, Lynn, and the Ruby Together team
### November 2016 Monthly Update
URL: https://rubycentral.org/news/november-2016-monthly-update/
Last updated: 2022-11-28T23:39:41.000Z
Welcome to the November 2016 Ruby Together monthly update! This month included maintenance work, security patches, helping users with problems, and learning several bad ways to handle gems with `required_ruby_version`.
André travelled to Cincinnati, OH to give a talk about contributing to open source, and we paid for 129.5 hours of work on Bundler, RubyGems, and RubyGems.org.
We’ll also be using this update to highlight our international contributors! They’re mentioned in each relevant news section.
## ruby together news
This month we had 13 new members! Eight new developers joined, including Minku Lee, Wolfgang Rittner, Adrien Jarthon, Fritz Grabo, Frederic Gingras, Mischa Lewis-Norelle, and Justin Burris. We also had three signups for new Friends of Ruby Together. Thank you, everyone! <3
Five companies joined as members, including [Brakeman Pro](https://brakemanpro.com/?ref=rubycentral.org), [Kundigo](http://kundigo.pro/?ref=rubycentral.org), [ChartMogul](https://chartmogul.com/?ref=rubycentral.org), [Rabid Technologies](https://www.rabid.co.nz/?ref=rubycentral.org), and [Fretless](http://www.getfretless.com/?ref=rubycentral.org).
On November 13, André gave a talk at [RubyConf](http://rubyconf.org/?ref=rubycentral.org) called [From No OSS Experience to the Core Team in 15 Minutes per Day](http://confreaks.tv/videos/rubyconf2016-from-no-oss-experience-to-the-core-team-in-15-minutes-a-day?ref=rubycentral.org). It discusses the benefits and costs of doing open source work and provides a straightforward list of activities that can be done by anyone, no matter their level of experience with programming. Watch [the video](http://confreaks.tv/videos/rubyconf2016-from-no-oss-experience-to-the-core-team-in-15-minutes-a-day?ref=rubycentral.org), check out [the slides](http://speakerdeck.com/indirect/from-no-oss-experience-to-the-core-team-in-15-minutes-a-day?ref=rubycentral.org), and/or read the talk as a blog post: [How to Contribute to OSS](http://andre.arko.net/2016/11/12/how-to-contribute-to-open-source/?ref=rubycentral.org).
At RubyConf, we gave away almost 1,000 stickers! We also gave almost 50 [Ruby Together lapel pins](https://twitter.com/rubytogether/status/795694158472048640?ref=rubycentral.org) to members. If you’re wishing for some stickers or lapel pins of your own, you’re in luck! At RubyConf, we also launched [the Ruby Together shop](https://shop.rubytogether.org/?ref=rubycentral.org)!
### We have merch!

Fulfill your [sticker](https://shop.rubytogether.org/collections/stickers?ref=rubycentral.org), [pin](https://shop.rubytogether.org/products/ruby-together-lapel-pin?ref=rubycentral.org), or [shirt](https://shop.rubytogether.org/collections/shirts?ref=rubycentral.org) dreams… we even have [Bundler packing tape](https://shop.rubytogether.org/products/bundler-packing-tape-preorder?ref=rubycentral.org). 😂 Shirts and tape are on order and will ship soon, while stickers and pins ship immediately!
We had three improvements with our meta tooling this month. The [how\_is](https://github.com/how-is/how%5Fis?ref=rubycentral.org) tool got another [release](https://github.com/how-is/how%5Fis/blob/v11.0.0/CHANGELOG.md?ref=rubycentral.org#1100), and will soon be used to actively [appraise the status](https://how-is.github.io/how-is-rubygems/2016/12/01/report.html?ref=rubycentral.org) of our various projects.
We also created a [time-card](https://github.com/rubytogether/rubytogether-lita/blob/84f6bec5d2faabbcb914132cd2880b8e7bacf33e/lib/lita/handlers/time%5Fcard.rb?ref=rubycentral.org) handler for the [lita](https://www.lita.io/?ref=rubycentral.org) bot, soon to be available for use in a chat room near you!
Finally, we shipped a new merge-bot: [@bundlerbot](https://github.com/bundlerbot?ref=rubycentral.org). We’ve been using the [homu.io](http://homu.io/?ref=rubycentral.org) service for over a year, but a long-standing bug prevented us from managing team member permissions. Now we have [our own copy of homu](https://bundlerbot-homu.herokuapp.com/?ref=rubycentral.org), and we look forward to updating team members and merging only green code for years to come.
Last in Ruby Together news, this month we partnered with [@mrb\_bk](https://twitter.com/mrb%5Fbk?ref=rubycentral.org)’s [Computer Modern](http://computermodern.io/?ref=rubycentral.org). We need more companies to join as members for Ruby Together to be sustainable in the long run, so it’s exciting to have expert help. We’ll be working with Computer Modern in the coming weeks and months to create resources for Ruby developers and Ruby Together members.
## bundler news
This month bundler and [bundler.io](https://bundler.io/?ref=rubycentral.org) got an array of documentation fixes / updates, due in large part to our new contributor [@colby-swandale](https://github.com/colby-swandale?ref=rubycentral.org).
Bundler got a [Request For Comments](https://github.com/bundler/rfcs?ref=rubycentral.org) repo, inspired by the one utilized by [Rust](https://www.rust-lang.org/en-US/?ref=rubycentral.org). We fixed [outdated not listing all outdated gems](https://github.com/bundler/bundler/pull/5176?ref=rubycentral.org). And we also [fixed an ObjectBoundsExceededError](https://github.com/bundler/bundler/pull/5213?ref=rubycentral.org) on [Rubinius](https://rubinius.com/?ref=rubycentral.org).
As mentioned last month, Bundler 1.13 shipped with [required\_ruby\_version support](http://bundler.io/blog/2016/09/08/bundler-1-13.html?ref=rubycentral.org) for Gemfiles containing a `ruby` declaration. Building on that, we hoped to release 1.14 with automatic support for the currently running Ruby version.
Over the last two months or so, the Bundler team has been discussing and experimenting with different ways to handle Gemfiles without an explicit `ruby`. The heroic @segiddins [attempted to implement](https://github.com/bundler/bundler/pull/5013?ref=rubycentral.org) our rough consensus for the feature, but we ran into a plethora of edge cases and problems with backwards compatibility. In the end, we went back to the drawing board and designed a new way to handle it that should be much better.
Downside: this work delayed Bundler 1.14, and now we’re going to ship 1.14 without automatic Ruby locking. Upside: it will be a much better feature when it’s done. Hooray.
In total, 11 authors pushed 59 commits to Bundler last month. 61 files changed and there were 1,990 additions and 1,629 deletions.
## rubygems.org news
This month in RubyGems.org, we [improved](https://github.com/rubygems/rubygems.org/pull/1423?ref=rubycentral.org) messaging for yanked and reserved namespace gems. [Reduced](https://github.com/rubygems/rubygems.org/pull/1436?ref=rubycentral.org) the database calls required for search requests. And [added](https://github.com/rubygems/rubygems.org/pull/1432?ref=rubycentral.org) email verification to new user accounts.
These changes were from RubyGems.org team member [Aditya Prakash](https://github.com/sonalkr132?ref=rubycentral.org). Overall, 8 authors pushed 40 commits to all branches, and 70 files changed. There were 1,135 additions and 360 deletions.
## rubygems news
This month in [RubyGems](https://github.com/rubygems/rubygems?ref=rubycentral.org), we [added](https://github.com/rubygems/rubygems/pull/1789?ref=rubycentral.org) displaying the current Ruby version when a version requirement is not met. We [updated](https://github.com/rubygems/rubygems/pull/1779?ref=rubycentral.org) the messaging when getting errors during cert building. And we [fixed](https://github.com/rubygems/rubygems/pull/1767?ref=rubycentral.org) a malformed version number error.
Most of this work was done by [@bronzdoc](https://github.com/bronzdoc?ref=rubycentral.org), one of our great RubyGems contributors. In total, 6 authors pushed 12 commits. 14 files changed, and there were 164 additions and 85 deletions.
## gemstash news
Meanwhile in [Gemstash](https://github.com/bundler/gemstash?ref=rubycentral.org), the documentation was completely rewritten using [Pandoc](http://pandoc.org/?ref=rubycentral.org) to pave the way for a website that shares documentation with the gem. During the month, 3 authors pushed 15 commits, 22 files changed, and there were 254 additions and 66 deletions.
## budget & expenses
From October 19 to November 18, Ruby Together took in $22,109\. In total, we spent $27,353.26\. Here’s a breakdown of where the money went:
- $8,615 for 57.4 hours worked on Bundler at $150/hour
- $6,504 for 43.4 hours worked on RubyGems.org at $150/hour
- $4,313 for 28.8 hours worked on RubyGems at $150/hour
- $73.38 on dedicated servers for RubyBench.org
- $694.5 on payment processing fees
- $2,167.27 on company overhead like hosting, services, software, hardware, taxes, etc
- $2,117.39 on accounting, copywriting, design, and other professional services
- $2,869.75 on marketing, evangelism, conferences, and community outreach
Until next time,
André, Lynn and the Ruby Together team
### October 2016 Monthly Update
URL: https://rubycentral.org/news/october-2016-monthly-update/
Last updated: 2022-11-28T23:39:41.000Z
Welcome to the October 2016 Ruby Together monthly update! This month we released Bundler `1.13.[3..6]`, weathered great internet storms, and dramatically improved response times. We did it with 70.3 hours of paid work on Bundler, RubyGems, and RubyGems.org.
## ruby together news
This month, Michael R. Bernstein (@mrb\_bk) has joined us as a consultant to help with marketing, sales, and automation. (You can see more about what he does with his company Computer Modern at [computermodern.io](http://computermodern.io/?ref=rubycentral.org)!)
There were 6 new developer members this month! Many thanks to Megan Tiu, John Akers, Rob Nichols, Olivier Lacan, Cameron Dutro, and Christoph Lupprich ^\_^ !!!
We also saw signups from two new corporate members this month: [Gleam](https://gleam.io/?ref=rubycentral.org), a business growth and marketing platform, and [Brakeman Pro](https://brakemanpro.com/?ref=rubycentral.org), a Rails security auditing system.
## bundler news
We released Bundler [1.13.3](https://github.com/bundler/bundler/blob/master/CHANGELOG.md?ref=rubycentral.org#1133-2016-10-10), [1.13.4](https://github.com/bundler/bundler/blob/master/CHANGELOG.md?ref=rubycentral.org#1134-2016-10-11), [1.13.5](https://github.com/bundler/bundler/blob/master/CHANGELOG.md?ref=rubycentral.org#1135-2016-10-15), [1.13.6](https://github.com/bundler/bundler/blob/master/CHANGELOG.md?ref=rubycentral.org#1136-2016-10-22). `1.13.3` was support for rubygems.org infrastructure changes, `1.13.[4..6]` was your regularly scheduled fixes and optimizations.
We noticed from our traffic stats that a few thousand [Bash on Windows](https://msdn.microsoft.com/en-us/commandline/wsl/about?ref=rubycentral.org) users were experiencing [bundler/bundler#4599](https://github.com/bundler/bundler/issues/4599?ref=rubycentral.org). [The cause](https://github.com/Microsoft/BashOnWindows/issues/352?ref=rubycentral.org) of this issue is home directory permissions, but we pushed out a fix for the sake of the number of effected users. [This fix](https://github.com/bundler/bundler/pull/5043?ref=rubycentral.org) was deployed in `1.13.4`.
In total, Bundler had 35 merged pull requests and 106 commits from 12 authors, and closed 59 issues.
## rubygems.org news
We finished moving Bundler server infrastructure into rubygems.org, culminating in resolving an issue with `/versions` mismatches. With this, we are now serving all of rubygems.org from [Fastly](https://www.fastly.com/?ref=rubycentral.org). This change [cut down server response times by half](https://twitter.com/dwradcliffe/status/786280193107202048?ref=rubycentral.org)!
Later in the month, we survived the survived the [Great DNS Outage of 2016](http://motherboard.vice.com/read/blame-the-internet-of-things-for-destroying-the-internet-today?ref=rubycentral.org). [rubygems.org](https://rubygems.org/?ref=rubycentral.org) was up the entire time, although most of our other tools weren’t.
In total, RubyGems.org had 18 merged pull requests and 33 commits from 8 authors.
## rubygems news
We released RubyGems [2.6.8](https://github.com/rubygems/rubygems/commit/9fb8880976f5ab998912898b091d88aa10eb1d4a?ref=rubycentral.org) this month. This release comes with [improved SSL error messaging](https://github.com/rubygems/rubygems/pull/1751?ref=rubycentral.org), which will hopefully relieve some frustration during this time of great turmoil.
In total, RubyGems had 18 merged pull requests and 29 commits from 10 authors.
## budget & expenses
From September 19 to October 18, Ruby Together took in $22,851.42\. In total, we spent $20,368.58\. Here’s a breakdown of where the money went:
- $3,960 for 26.4 hours worked on Bundler at $150/hour
- $3,390 for 22.6 hours worked on RubyGems.org at $150/hour
- $3,188 for 21.3 hours worked on RubyGems at $150/hour
- $75.53 on dedicated servers for RubyBench.org
- $716.3 on payment processing fees
- $2,450.17 on company overhead like hosting, services, software, hardware, taxes, etc
- $5,615.0 on accounting, copywriting, design, and other professional services
- $974.08 on marketing, evangelism, and community outreach
## future plans
In the coming months we plan on releasing Bundler 1.14 with better permissions error handling. We also are going to do several rounds of updates on the documentation for [bundler.io](https://bundler.io/?ref=rubycentral.org) and [rubygems.org](https://rubygems.org/?ref=rubycentral.org)
Until next time,
Lynn, André, and the Ruby Together team
### September 2016 Monthly Update
URL: https://rubycentral.org/news/september-2016-monthly-update/
Last updated: 2022-11-28T23:39:41.000Z
Welcome to the September 2016 Ruby Together monthly update! This month we added a variety of new features in Bundler 1.13, as well as bug fixes in 1.13.1 and 1.13.2\. We paid for 71.3 hours of work on Bundler, RubyGems, and RubyGems.org. Also, André gave a great talk at EuRuKo 2016 leading to 18 (!) new members.
## ruby together news
André gave a talk at [EuRuKo](http://euruko2016.org/?ref=rubycentral.org) about [the first year of of working on Ruby Together](https://speakerdeck.com/indirect/a-year-of-ruby-together?ref=rubycentral.org). The video isn’t posted yet, but you can read [our blog post based on the talk](https://rubytogether.org/news/2016-09-27-a-year-of-ruby-together?ref=rubycentral.org).
The first year of Ruby Together has been amazing! We’ve done more than we ever expected, and the community has come together in the best way possible to improve things for everyone. We’re not safe yet, though! The rapidly increasing demands of Ruby developers and companies are pushing us to the limit as we keep everything working.
This is the time for companies with profitable businesses to step up and pay it forward to the next group of devs and companies that will benefit from open, free tools. Without more support, it’s just a matter of time until we can’t keep up. You can do it, Ruby community! We believe in you. <3
Thanks so much to our many new developer members !!! Tiago Mendes-Costa, Colby M. White, Vincent Daubry, Pascal Betz, Marion Schleifer, Adam Niedzielski, Tony Drake, Cecile Veneziani, Fernando Seror, and Keycoopt !!!
Another thanks to our corporate members, the valiant organizations committed to securing their income by funding their infrastructure. New corporate members this month are: [Hexagonal Consulting](http://www.hexagonconsulting.co/?ref=rubycentral.org), [Kisko Labs](https://www.kiskolabs.com/?ref=rubycentral.org), and [Hired](http://hired.com/?utm%5Fsource=sponsor&utm%5Fmedium=rubytogether&utm%5Fcampaign=q4-16-rubytogether).
[Hired](http://hired.com/?utm%5Fsource=sponsor&utm%5Fmedium=rubytogether&utm%5Fcampaign=q4-16-rubytogether) in particular signed up as a Sapphire member, putting it up with just Stripe and CodeMiner42 in supporting our work on Ruby infrastructure. Hired is an organization for empowering developers to find job opportunities with groundbreaking companies—from household names to emerging startups, and everything in between. Developers with Hired get access to over 4,400 innovative companies, and can quickly evaluate multiple offers side-by-side to choose the right fit with confidence.
## bundler news
Early in the month, we released [Bundler 1.13](http://bundler.io/blog/2016/09/08/bundler-1-13.html?ref=rubycentral.org). This update features `required_ruby_version`, `bundle doctor`, and platform `lock` commands. Later in the month, [Bundler 1.13.1](https://github.com/bundler/bundler/milestone/32?closed=1&ref=rubycentral.org) shipped with a variety of minor bug fixes.
Chris Morris ([@chrismo](https://github.com/chrismo?ref=rubycentral.org)) was added to Bundler’s [contributor team](http://bundler.io/contributors.html?ref=rubycentral.org). His core team promotion was sponsored by the experimental [conservative update](http://bundler.io/blog/?ref=rubycentral.org#experimental-conservative-updates) that shipped with 1.13.
We fixed a [GEM\_PATH regression](https://github.com/bundler/bundler/pull/4992?ref=rubycentral.org) in release 1.13\. This bug was truly an adventure, and threw our core team for a loop for most of two weeks. Finally, we started working towards the Better Platform Support update with [the help](https://github.com/bundler/bundler/issues/4984?ref=rubycentral.org) of [@headius](https://github.com/headius?ref=rubycentral.org) and [jruby](http://jruby.org/?ref=rubycentral.org).
In total, Bundler had 37 merged pull requests and 83 commits from 11 authors, and closed 50 issues.
## rubygems.org news
We experienced the [life and death](https://github.com/rubygems/rubygems.org/issues/1429?ref=rubycentral.org) of [@rubygems](https://twitter.com/rubygems?ref=rubycentral.org) this month. Many thanks to our valiant users, always on hand to pull our Twitter accounts back from the abyss.
We also worked on both server side ([rate limiting](https://github.com/rubygems/rubygems.org/pull/1414?ref=rubycentral.org)), and end user focused ([gem yank](https://github.com/rubygems/rubygems.org/pull/1396?ref=rubycentral.org)) security issues.
In total, RubyGems.org had 13 merged pull requests and 26 commits from 5 authors.
## rubygems news
We released RubyGems 2.6.7 which features bug fixes for `--user-install`, and [other miscellaneous fixs](https://github.com/rubygems/rubygems/compare/v2.6.6...v2.6.7?ref=rubycentral.org).
We also worked on more [organization and infrastructure](https://github.com/rubygems/rubygems/issues/1681?ref=rubycentral.org) for the upcoming 3.0 merger, in addition to an array of [small integration changes](https://github.com/bundler/bundler/pulls?utf8=%E2%9C%93&q=merged%3A2016-09-01..2016-09-27%20rubygems%20&ref=rubycentral.org).
In total, RubyGems had 8 merged pull requests and 21 commits from 6 authors.
## budget & expenses
From August 19 to September 18, Ruby Together took in $19,237\. In total, we spent $13,543.78\. Here’s a breakdown of where the money went:
- $3690 for 24.6 hours worked on Bundler at $150/hour
- $3923 for 26.2 hours worked on RubyGems.org at $150/hour
- $3075 for 20.5 hours worked on RubyGems at $150/hour
- $75.16 on dedicated servers for RubyBench.org
- $604.78 on payment processing fees
- $1547.34 on company overhead like hosting, services, software, hardware, taxes, etc
- $600.0 on accounting, copywriting, design, and other professional services
- $29.0 on marketing, evangelism, and community outreach
## future plans
Next month we plan on working on a platform support release, including changes for JRuby in particular—in addition to our ongoing work on Bundler 2.0 and Bundler+RubyGems 3.0.
Until next time,
Lynn, André, and the Ruby Together team
### A Year Of Ruby Together
URL: https://rubycentral.org/news/a-year-of-ruby-together/
Last updated: 2022-11-28T23:39:41.000Z
[Ruby Together](https://rubytogether.org/?ref=rubycentral.org) has been around for over a year! It’s actually been about 18 months, but that didn’t sound as snappy. To celebrate, I’ve put together this summary of our history: why and how we exist, what we’ve done, and what the future holds.
So, what even *is* Ruby Together? Ruby Together is a non-profit that pays developers to work on RubyGems, Bundler, and more, using funds from members. Members can be any person or company who uses Ruby, and the work we pay for is free for anyone to use.
But what, exactly, does that mean? And why do we need a non-profit to do this in the first place? The explanation lies the current state of the Ruby community.
## there are some problems
Put simply, the problem is that Ruby has grown up. The Ruby community has become so large that our existing community infrastructure isn’t sustainable anymore.
### the gems! they’re multiplying!
As you’ve probably noticed, Bundler makes it easier to use gems and makes it easier to create gems. Over the 6 years that I’ve spent working on Bundler, the number of gems in existence has multiplied, and the number of gem downloads has multiplied. There are now over 100,000 gems, and those gems have over a million versions.
With those million versions comes a completely unprecedented number of downloads. In the years from 2003 to the end of 2014, we tracked roughly 2 billion gem downloads. That’s 2 billion downloads over more than ten years. Then, in 2015 alone (just one year!) we served 4 billion gem downloads.
That is an *extremely* steep increase. If we were a startup, we’d have great graphs to show VCs and convince them to give us money. But we’re not a startup. Before Ruby Together, all of RubyGems.org was maintained for free by volunteers. That’s a problem, because at the same time that usage has been increasing exponentially, volunteer help hasn’t been increasing.
### the volunteer crisis
Most people don’t realize this, but the RubyGems.org team is incredibly small. It’s never had more than four people on it, and most often has only had two. The Bundler team is even smaller—it’s never had more than two people working on it consistently, and often only one.
None of those team members were ever paid for their work. To pay their bills, every single one of them has to have a full-time job doing something else. A few volunteers giving up their nights and weekends to help the community used to be enough, but it’s not anymore.
Using open source ethically means supporting the tools and infrastructure you use, with money or time. Instead of supporting our community infrastructure, companies are taking community resources and then not giving back. These companies are making millions (and sometimes billions) of dollars. They could easily afford to support us, but choose not to. Let me give an example that really highlights this point.
### remember when rubygems.org got hacked?
About 3 years ago, RubyGems.org went down completely, for over a week. There was a security issue, and although the team knew about the security issue and planned to fix it, everyone on the team had a day job. The best we could do was plan to fix the problem that weekend. Unfortunately, a motivated hacker figured out how to break to during the week.
We had to take the servers down and create completely new servers from scratch. We also had to download and verify every single one of the hundreds of thousands of .gem files, to make sure the hacker hadn’t replaced any of them while he had access.
During this time, hundreds of Ruby developers volunteered to help. This isn’t super surprising, since almost every Ruby developer and company depends on RubyGems.org in order to be able to do their work. What is terrible is that none of those volunteers could do anything useful. None of them were already familiar with how the servers worked, and helping them get up to speed would have slowed down the recovery efforts.
The worst part, though, is that once RubyGems.org was back up… all of those volunteers disappeared. None of them were wiling to get up to speed and help out when there wasn’t an emergency. Even though the RubyGems infrastructure is vitally important to all of these companies, they can’t or won’t allow their employees to help make sure it keeps working.
### the non-solution of open source jobs
At this point, you might say “Aha! But companies sometimes hire Ruby developers specifically to work on open source. Let’s just keep doing that.” While that is a great thing, and I am very glad that companies sometimes choose to do that, it is not a solution to the crisis we are facing.
Very few companies have ever hired Ruby developers to work on open source full time. Even including all of the last 10 years, I can only think of Engine Yard, Sun, AT&T, RedHat, Heroku, Shopify, GitHub. I’m sure there are others, but there can’t be that many.
Even if there were more companies doing this, though, it would still be a problem. Engine Yard is the perfect example of a very helpful company turning out to be extremely disruptive to the community. At one point in time, Engine Yard (by itself!) employed not just the Rubinius and JRuby teams, but also everyone working full-time on Rails.
Eventually, though, they decided to stop. After Engine Yard wound down their open source positions, the JRuby team had moved to another company, but the Rubinius team and Rails team no longer had any full-time developers. If a single executive at SalesForce changes their mind, most of the full-time developers on Ruby core will be out of a job. We can do better than a community dependent on one or two companies.
Ruby Together spreads the costs across many companies and people. Everyone shares the costs of paying developers, and everyone shares the benefits. Even better, that sharing means we’re not dependent on any single company to be able to do our work. A single company changing their mind or cutting costs is no longer enough to disrupt the community.
## how it came about
Working on Bundler and RubyGems over the last six years had made these problems clear to me, but most of the people I talked to didn’t think they were important problems. Bundler and RubyGems had always gotten along with work from volunteers! Companies were able to build huge and wildly profitable companies on top of Ruby open source, so everything seemed fine.
I spent years experimenting with different ideas for how Bundler and RubyGems could make enough money to support paying developers. I tested out support contracts, feature bounties, enterprise-only features, and more. None of them were enough of an improvement for companies to want to pay for them. Even worse, every option was a huge time-sink away from the actual goal of working on the open source projects.
One company was willing to support Bundler directly, without any conditions or requirements: [Stripe](https://stripe.com/?ref=rubycentral.org). Using funds from Stripe, I was able to do research, hire a lawyer, and found Ruby Together.
Ruby Together incorporated as a particular kind of non-profit company—what the U.S. government calls a “trade association”. Other trade associations you may have heard of include the Linux Foundation, the Jquery Foundation, and the Sqlite Foundation, but the best-known example is the American Dairy Farmers’ Association.
The American Dairy Farmers’ Association pays for the “Got Milk?” ad campaigns. Those ad campaigns cost more than a single dairy farmer could afford, but they benefit all dairy farmers by promoting milk. Each trade association uses membership dues to fund community projects that benefit all members of that trade, whether they belong to the association or not.
## what we’ve done
Speaking of benefiting everyone, let’s talk about some of the things that Ruby Together has done in it’s first year and a half. The big, underlying thing that we did is pay for 1,100 hours of developer time. Using that developer time, we’ve gotten a lot of stuff done. I can’t possibly cover everything in detail, but even an overview will give you a taste of what goes into keeping `bundle install` working month after month, and year after year.
### bundler accomplishments
Working on Bundler, have completed and 5 feature releases. In [Bundler 1.9](http://bundler.io/blog/2015/03/21/hello-bundler-19.html?ref=rubycentral.org), we started using Molinillo, a new dependency manager. It was funded by a Stripe grant and shared between Bundler, RubyGems, and CocoaPods. In [Bundler 1.10](http://bundler.io/blog/2015/06/24/version-1-10-released.html?ref=rubycentral.org), we added the `lock` command, optional groups, conditional groups, and the ability to mute post-install messages per gem. (Finally, it’s possible to never be told “You must HTTParty hard” again!) In [Bundler 1.11](http://bundler.io/blog/2015/12/12/version-1-11-released.html?ref=rubycentral.org), we dramatically improved error messages both in general and when the Gemfile cannot be resolved. In [Bundler 1.12](http://bundler.io/blog/2016/04/28/the-new-index-format-fastly-and-bundler-1-12.html?ref=rubycentral.org), we finished a 3-year-long project and started using a new gem metadata file format that allows us to finally stop sending every user information about every gem every time they install. We also increased the speed of `bundle exec` and added support for locking and updating the Ruby version. In [Bundler 1.13](http://bundler.io/blog/2016/09/08/bundler-1-13.html?ref=rubycentral.org), we added support for gems with `required_ruby_version` for Gemfiles that declare their `ruby` version, added the `doctor` command to fix broken compiled gems, and added the ability to add and remove platforms you want Bundler to resolve for. And that was just a summary of the big features!
We also released [38 bugfix releases](https://rubygems.org/gems/bundler/versions?ref=rubycentral.org), completely [redesigned the Bundler website](http://bundler.io/blog/2016/07/10/bundler-1-13-and-redesigned-bundler-io.html?ref=rubycentral.org), and mentored nine [Google Summer of Code](http://summerofcode.withgoogle.com/?ref=rubycentral.org) students and four [RailsGirls Summer of Code](http://railsgirlssummerofcode.org/?ref=rubycentral.org) students across two summers.
### now rubygems, too
As part of keeping Bundler working, Ruby Together has taken over maintenance of the [RubyGems project](https://github.com/rubygems/rubygems?ref=rubycentral.org) as of 2016\. Bundler already uses parts of RubyGems to install gems, and so it was a good fit. Even worse, ever since AT&T Interactive shut down their Ruby open source department, RubyGems hasn’t had any dedicated development. For almost two years, the only significant change to RubyGems was a critical security fix.
It was an awful situation. For that entire two years, installing compiled gems was broken on Windows for any Ruby version older than the latest. I’m very pleased to reveal that since the start of this year, we have fixed many bugs, including that one. Developers on Windows can install gems again. In total, we’ve released one minor and eight bugfix versions of RubyGems so far. We also have some great plans for RubyGems that I’ll cover in the section about the future, so keep reading!
### oh and the servers
On the server side, we’ve done a huge amount of work on RubyGems.org and on the [Bundler dependency API](https://github.com/bundler/bundler-api?ref=rubycentral.org). I’ve previously given [a talk about setting up the Bundler API ](http://andre.arko.net/2013/12/09/extreme-makeover-rubygems-edition/?ref=rubycentral.org) as a separate thing from RubyGems.org. It’s not in my talk, but the biggest reason we had to do that was that at that time RubyGems.org didn’t have enough volunteers to stay functional if it ran the Bundler API as well.
Because of that shortage, the Bundler dependency API is a completely separate application from RubyGems.org. Even though we now have one team cooperating to run everything, we have had to keep paying the cost of two separate systems: one for the gem metadata, and one for the gems themselves.
For the last year and a half, we’ve applied countless security patches and implemented the server-side part of the [new index format](http://andre.arko.net/2014/03/28/the-new-rubygems-index-format/?ref=rubycentral.org) used by Bundler 1.12\. We’ve even ported the entire Bundler API Sinatra app into the RubyGems.org Rails app. Someday very soon, we’ll only have one platform to keep operational. That’s a big win, giving us more reliability while requiring us to do less work. We also switched to using the [Fastly CDN](http://fastly.com/?ref=rubycentral.org) for gem downloads, and we have ever so slowly reworked the entire architecture of RubyGems.org so that every page can be served from Fastly’s closest data center instead of from Amazon’s US-West region.
On top of all of that proactive maintenance, we have paid developers to take on incident response. It’s much easier to prioritize keeping all of these systems operational when it’s paid work. Our team has handled around a dozen outages over the last 18 months, and every one of them has been shorter than it would have been without Ruby Together.
### gemstash, also pretty neat
One more thing that we did: we built a new tool to help everyone manage the gems that they need. It’s called [Gemstash](https://github.com/bundler/gemstash?ref=rubycentral.org), and it’s a server you can run that will cache every gem you download from RubyGems.org. You can run one on your local laptop to avoid downloading gems multiple times. You can run one in your office to speed up installing the gems your application needs. Or you can run one in your datacenter, and install gems across all your server from a local source. It can even act as a server for private gems, so you can keep your company’s internal gems on it, too.
### bundler 2.0 is coming
Later this fall, we’re going to release [Bundler 1.14](https://github.com/bundler/bundler/issues/4853?ref=rubycentral.org), and then [Bundler 2.0](https://github.com/bundler/bundler/issues/4856?ref=rubycentral.org) after that. When we were designing Bundler 1.0, we made tradeoffs based on a world that didn’t use Bundler. Today, not only Ruby developers but developers in most languages have a dependency manager—the old tradeoffs are a problem now, instead of a benefit.
Plus, it’s a huge drain on our time to keep supporting Ruby 1.8.7 and all the other ancient versions of Ruby and RubyGems that were new at the time Bundler was originally released. The functionality provided by Bundler won’t change, and everyone will be able to use Bundler 1 in some projects and Bundler 2 in others on the same machine. I’m really excited about the improvements that are possible with backwards-breaking changes, and I’m looking forward to sharing those with you later this year or early next year.
### plus we’re going to merge bundler and rubygems
Oh, and one more thing. For the last six years of working on Bundler, one of the most frustrating things about working on it has been the separation between Bundler and RubyGems. Sometimes making a change in one would break something in the other. The rest of the time it has just been a huge pain to make sure that they work to install gems the same way even when they aren’t working together.
By talking to developers, companies, and the teams working on Bundler, RubyGems, and RubyGems.org, we’ve come up with a plan to combine the Bundler and RubyGems projects. They’ll still have separate commands, `gem` and `bundle`, but they’ll have a single codebase behind them. This summer, we mapped out everything that needed to be done for that merger, and started working on it.
After Bundler 2 is released, the main focus of the Bundler and RubyGems teams will be merging the codebases together into [RubyGems+Bundler 3.0](https://github.com/rubygems/rubygems/issues/1681?ref=rubycentral.org).
## somehow, it’s working!
In many ways, the last year and a half has been more successful than I could have dreamed. Ruby Together is paying developers for work every week. We’ve fixed more bugs and made more progress on Bundler and RubyGems in the last year than we managed in the three years before that. We started out especially strong, and we saw new companies and developers signing up every single month for an entire year.
### but it’s not all good
But for the last six months, even as we’ve set new records for paid hours, while we managed the [Google Summer of Code](https://summerofcode.withgoogle.com/?ref=rubycentral.org) project for all of Ruby, and while we made these exciting plans to finally bring RubyGems and Bundler together… membership has been flat. We’ve seen a few new members, but a few members have left. Overall, we’re in the same place after 18 months as we were after 12 months: able to pay consistently for several hours a week, but not yet able to pay even two people part-time.
### companies are short-sighted
Businesses are ultimately answerable to shareholders who want profit, and right now businesses think that they can get the benefits of Ruby community infrastructure and tools without needing to contribute back themselves. It’s always worked before, right?
Just because it’s worked in the past doesn’t mean it will keep working in the future. As I showed earlier, the demands of the community keep growing. The situation we have now is unsustainable. RubyGems was broken on Windows for two years! Everyone in the Ruby community needs to know about the crisis that we’re heading towards. Every company in the community needs to understand that we can’t keep giving them a free ride even if we wanted to.
Some companies (like [Stripe](https://stripe.com/?ref=rubycentral.org), [CodeMiner42](http://codeminer42.com/?ref=rubycentral.org), [Basecamp](http://basecamp.com/?ref=rubycentral.org), [Travis](http://travis-ci.com/?ref=rubycentral.org), and others) have stepped up to support us with actual money. Other companies tell us it’s a great initiative, and they’re really glad we exist, but they’re not willing to pitch in. We haven’t seen any new companies join for almost six months. If that keeps up, we won’t even be able to keep up paying for a few hours of work per week. If companies keep taking community benefits without giving back, it takes us straight back to unsustainable volunteers burning themselves out.
### cooperating is good for everyone
We don’t want that! There’s a better way. It’s not even hard, or expensive. At Ruby Together, we’re already prepared to keep everything working—we just need support from Ruby developers and companies to make that possible.
We offer the entire community a great deal: free tools and free hosting for Ruby code they want to share with the world. We offer a fantastic deal for companies, too: the benefits of full-time infrastructure developers at a tiny fraction of the cost.
So for now, we’re asking: help us work on [Bundler](https://bundler.io/?ref=rubycentral.org), [RubyGems](https://rubygems.org/?ref=rubycentral.org), and everything else by [signing up](https://rubytogether.org/join?ref=rubycentral.org). Everything we build with money from the community is shared back to the community, and that’s what Ruby Together is all about.
### August 2016 Monthly Update
URL: https://rubycentral.org/news/august-2016-monthly-update/
Last updated: 2022-11-28T23:39:41.000Z
Welcome to the Ruby Together update for August 2016\. This month, we paid for 65.5 hours of work, had 2 new members join. We released Bundler 1.13 RC2, and created roadmaps for Bundler 1.13, 1.14, 2.0, and RubyGems + Bundler 3.0.
## ruby together news
This August at Ruby Together was marked by personnel shifts. The Google Summer of Code students finished their term, with 12 students successfully completing their projects. The Rails Girls Summer of Code students shifted up their work, submitting their first PR. Our ops engineer’s wife had a child (congrats, David + family!) and our project manager had a major surgery.
We had two new developer members join, but no companies. If your company needs Bundler and RubyGems to function, talk to your team about Ruby Together! We need support from companies to keep everything working smoothly.
Voting for the board of directors wrapped up this month. After an incredibly close election, board members [Ines Sombra](http://twitter.com/randommood?ref=rubycentral.org) and [Coraline Ada Ehmke](http://twitter.com/coralineada?ref=rubycentral.org) were re-elected to a three year term. Thanks to every member who participated! <3
Ruby Together employees also worked on a variety of smaller tools in the Ruby development ecosystem, including [how-is](https://github.com/how-is/how%5Fis?ref=rubycentral.org), [vcr](https://github.com/vcr/vcr?ref=rubycentral.org), and [lita](https://github.com/indirect/lita-tweet?ref=rubycentral.org).
## bundler news
We ironed out more bugs with Bundler 1.13, and arrived at [1.13.rc2](https://github.com/bundler/bundler/blob/master/CHANGELOG.md?ref=rubycentral.org#1130rc2-2016-08-21). Andre created checklists for upcoming versions of Bundler, including [1.13](https://github.com/bundler/bundler/issues/4852?ref=rubycentral.org), [1.14](https://github.com/bundler/bundler/issues/4853?ref=rubycentral.org), and [2.0](https://github.com/bundler/bundler/issues/4856?ref=rubycentral.org). [Bundler.io](https://bundler.io/?ref=rubycentral.org) got its last set of changes courtesy of Google Summer of Code, and will be returning to its mountain lair where it lies in wait for more motivated contributors.
In total, Bundler had 53 merged pull requests and 184 commits from 18 authors, and closed 44 issues.
## rubygems.org news
RubyGems.org got its regular maintenance work, and updates to address security vulnerabilities in the `gem yank` command. With those changes, RubyGems.org had 18 merged pull requests and 26 commits from 7 authors.
## rubygems news
RubyGems got a lot of planning work done towards the 3.0 merge, and now has [an issue](https://github.com/rubygems/rubygems/issues/1681?ref=rubycentral.org) to track merger considerations. Including that work, RubyGems had 10 merged pull requests and 10 commits from 5 authors.
## budget & expenses
From July 19 to August 18, Ruby Together took in $18577\. In total, we spent $22637.63\. Here’s a breakdown of where the money went:
- $3930 for 26.2 hours worked on Bundler at $150/hour
- $3795 for 25.3 hours worked on RubyGems.org at $150/hour
- $2100 for 14.0 hours worked on RubyGems at $150/hour
- $74.2 on dedicated servers for RubyBench.org
- $582.04 on payment processing fees
- $3668.53 on company overhead like hosting, services, software, hardware, taxes, etc
- $6315.0 on accounting, copywriting, design, and other professional services
- $2172.86 on marketing, evangelism, and community outreach
## next month
Look forward next month to us capitalizing on the release planning work, and the efforts of our Rails Girls Summer of Code students!
Until next time,
Lynn, André, and the Ruby Together team
### July 2016 Monthly Update
URL: https://rubycentral.org/news/july-2016-monthly-update/
Last updated: 2022-11-28T23:39:41.000Z
Welcome to the Ruby Together update for July 2016\. This month, we paid for 64.4 hours of work, had 5 new members join, and had another solid month from our summer coding students. Work done this month includes a new design for bundler.io, and a lot of progress towards Bundler 1.13, 1.14, 2.0, and the combined Bundler+RubyGems 3.0.
## ruby together news
The focus at RubyTogether this month was on coordinating work across our largest team ever, thanks to all of our summer coding students. The biggest event was [@kruczjak](https://github.com/kruczjak?ref=rubycentral.org) and [@sailorhg](https://twitter.com/sailorhg?ref=rubycentral.org)’s work on the [bundler.io](http://bundler.io/?ref=rubycentral.org) redesign, which dramatically updated the style and added an array of new functionality. The highlights of that work are detailed in [@kruczjak’s post announcing the new design](http://bundler.io/blog/2016/07/10/bundler-1-13-and-redesigned-bundler-io.html?ref=rubycentral.org).
Along with that we had other [Google Summer of Code](https://developers.google.com/open-source/gsoc/?ref=rubycentral.org) students working on a variety of small Bundler features, and the [Rails Girls Summer of Code](http://railsgirlssummerofcode.org/?ref=rubycentral.org) students gearing up to working on Bundler’s analytics system. Finally we had [@segiddins](https://github.com/segiddins?ref=rubycentral.org) working on future Bundler / RubyGems updates, [@duckinator](https://github.com/duckinator/?ref=rubycentral.org) on [how-is](https://github.com/how-is?ref=rubycentral.org), and [@lynnco](https://github.com/LynnCo?ref=rubycentral.org) on administrative automation.
We had two 5 new members join this month, including 3 new developers and 2 new companies. We appreciate everyone getting the word out, and encouraging people to support the Ruby community!
## bundler news
This was a very busy month for Bundler, with 15 authors getting 35 merged PRs with 251 commits. Features include: [RubyGems / Bundler Integration](https://github.com/bundler/bundler/pull/4770?ref=rubycentral.org), [respecting the required Ruby version](https://github.com/bundler/bundler/pull/4650?ref=rubycentral.org), [a warning message / upgrade guide](https://github.com/bundler/bundler/pull/4741?ref=rubycentral.org) for Bundler 2.0, [trampolining fixes](https://github.com/bundler/bundler/issues/4753?ref=rubycentral.org) which will allow Bundler 2.0 to stay compatible with apps that use Bundler 1.x, and [bundler-patch](https://github.com/bundler/bundler/pull/4676?ref=rubycentral.org). Most of that work will be shipping with Bundler release 1.13 (any day now), and 1.14 (coming soon after, likely next month).
## rubygems.org news
RubyGems.org this month was mostly [content updates](https://github.com/rubygems/rubygems.org/pull/1359?ref=rubycentral.org) and [minor security changes](https://github.com/rubygems/rubygems.org/pull/1342?ref=rubycentral.org). Notably, though, we got a first time open source contributor! [They added](https://github.com/rubygems/rubygems.org/pull/1361?ref=rubycentral.org) a Twitter field to RubyGems.org user profiles. In total we had 9 authors working on 27 merges with 67 commits.
## rubygems news
RubyGems this month was mostly [minor](https://github.com/rubygems/rubygems/pull/1666?ref=rubycentral.org) [fixes](https://github.com/rubygems/rubygems/pull/1659?ref=rubycentral.org), across 1 author (our own [Samuel Giddins](https://github.com/segiddins?ref=rubycentral.org)), 3 merges, and 10 commits. Near the end of this month, the [first](https://github.com/rubygems/rubygems/pull/1639?ref=rubycentral.org) of what will likely be many Bundler / RubyGems PRs was resolved, moving us closer to Bundler / RubyGems 3.0.
## budget & expenses
From June 21 to July 19, Ruby Together took in $19,161\. In total, we spent $18,563.86\. Here’s a breakdown of where the money went:
- $2,452 for 16.3 hours worked on Bundler at $150/hour
- $3,613 for 24.1 hours worked on RubyGems.org at $150/hour
- $3,600 for 24.0 hours worked on RubyGems at $150/hour
- $74.35 on dedicated servers for RubyBench.org
- $596.57 on payment processing fees
- $1544.71 on company overhead like hosting, services, software, hardware, taxes, etc
- $7275.0 on accounting, copywriting, design, and other professional services
- $29.0 on marketing, evangelism, and community outreach
Check back next month for our last month of work from Google Summer of Code, more work towards major releases, and our regular diligent security updates and minor fixes.
Until next time,
Lynn and the Ruby Together team
### June 2016 Monthly Update
URL: https://rubycentral.org/news/june-2016-monthly-update/
Last updated: 2022-11-28T23:39:41.000Z
Welcome to the June 2016 monthly update for Ruby Together! In the last month, we paid for 119.6 hours of work, and had 6 new members join. Our work this month includes RubyGems 2.6.6, Bundler 1.13 pre-release, and an array of minor improvements thanks to our Google Summer of Code students.
## ruby together news
### tools for our tools
We worked on two meta tools: [How Is](https://github.com/duckinator/how%5Fis?ref=rubycentral.org) for checking the status of issues and pull requests, and [Patronus](https://github.com/patronus-io/patronus?ref=rubycentral.org) for testing and merging pull requests. Their broad goal is to take some of the legwork out of maintaining Bundler and RubyGems.
### summer of coders
Our Google Summer of Code ([GSoC](https://developers.google.com/open-source/gsoc/?ref=rubycentral.org)) students have done an array of work including an initial release of the plugin system, Bundler’s site redesign, and resolving many [other issues](https://github.com/bundler/bundler/issues?utf8=%E2%9C%93&q=label%3AGSoC%20&ref=rubycentral.org). They are going pretty strong as we head into GSoC’s midterms. We also got approval for a second set of summer assistance, and so next month we will be working with a team from [Rails Girls Summer of Code](http://railsgirlssummerofcode.org/blog/2016-06-24-more-teams-aye?ref=rubycentral.org).
### new members
We had a total of 7 new members this month, including 5 developers: Joseph Method, Daisuke Goto, George Claghorn, Joseph D. Marhee, and Aditya Sanghi. The 2 companies that joined this month are: [Powershop](http://www.powershop.co.nz/?ref=rubycentral.org) and [Envato](https://envato.com/?ref=rubycentral.org)
## bundler news
Bundler [1.13](https://github.com/bundler/bundler/blob/master/CHANGELOG.md?ref=rubycentral.org#1130pre1-2016-06-20) got a pre-release this month, featuring a set of [significant speed improvements](https://github.com/bundler/bundler/pull/4580?ref=rubycentral.org) ported from [CocoaPods](https://github.com/CocoaPods/Molinillo/pull/40?ref=rubycentral.org). 1.13 also includes an alpha version of the [plugin system](https://github.com/bundler/bundler/pull/4608?ref=rubycentral.org), which will likely see a full release in 1.14.
Recently [Bundler-api](https://github.com/bundler/bundler-api?ref=rubycentral.org) (the server side code for Bundler) has started [being moved](https://github.com/rubygems/rubygems-infrastructure/issues/42?ref=rubycentral.org) into RubyGems.org infrastructure. This change was made to reduce duplication of effort and resources, but also fits into the general goal of an eventual Bundler and RubyGems merge.
Finally this month saw [a lot of work](https://github.com/bundler/bundler-site/pull/218?ref=rubycentral.org) towards the new design for [bundler.io](https://bundler.io/?ref=rubycentral.org).
In total, Bundler had 40 merged pull requests and 226 commits from 15 authors, and we closed 49 issues.
## rubygems.org news
In addition to the standard Fastly optimizations, the RubyGems.org team started working towards better policies and more security. The policies work, which will be released in the coming months, is on terms of use in general and name disputes (see: [left pad and npm](http://blog.npmjs.org/post/141577284765/kik-left-pad-and-npm?ref=rubycentral.org)) in particular. The security updates are also related to name issues, and inspired by a blog post about [typosquatting package managers](http://incolumitas.com/2016/06/08/typosquatting-package-managers/?ref=rubycentral.org). If you have advice / want to contribute to this particular solving this particular problem, here is [the relevant issue](https://github.com/rubygems/rubygems.org/issues/1334?ref=rubycentral.org).
In total, RubyGems.org had 40 merged pull requests and 103 commits from 11 authors.
## rubygems news
RubyGems [2.6.5](http://blog.rubygems.org/2016/06/21/2.6.5-released.html?ref=rubycentral.org) and [2.6.6](http://blog.rubygems.org/2016/06/22/2.6.6-released.html?ref=rubycentral.org) released this month, featuring a variety of bug fixes and minor enhancements that had accumulated since the last release. We also started working towards RubyGems 3.0, the Bundler and RubyGems merge. So far we have merged the [testing](https://github.com/rubygems/rubygems/pull/1650?ref=rubycentral.org) and [issue semantics](https://github.com/rubygems/rubygems/issues/1442?ref=rubycentral.org). Pending a blog post detailing what the 3.0 release will entail, here is André describing [Bundler / RubyGems 3.0](https://github.com/rubygems/rubygems/pull/1639?ref=rubycentral.org#issuecomment-227287369) informally.
In total, RubyGems had 12 merged pull requests and 19 commits from 6 authors.
## budget & expenses
From May 20 to June 20, Ruby Together took in $21162\. In total, we spent $26813.03\. Here’s a breakdown of where the money went:
- $7879.60 for 52.5 hours worked on Bundler at $150/hour
- $5419.90 for 36.1 hours worked on RubyGems.org at $150/hour
- $4650 for 31.0 hours worked on RubyGems at $150/hour
- $75.11 on dedicated servers for RubyBench.org
- $657.6 on payment processing fees
- $2159.42 on company overhead like hosting, services, software, hardware, taxes, etc
- $6600 on accounting, copywriting, design, and other professional services
- $29 on marketing, evangelism, and community outreach
Look forward in the next month to the completed [Bundler.io](https://bundler.io/?ref=rubycentral.org) redesign, the efforts of our many summer coding assistants, and the full Bundler 1.13 release.
Until next time,
Lynn, André, and the Ruby Together team
### May 2016 Monthly Update
URL: https://rubycentral.org/news/may-2016-monthly-update/
Last updated: 2022-11-28T23:39:41.000Z
Welcome to the May 2016 monthly update for Ruby Together. In the last month, we paid for 232.3 hours of developer, designer, and project management time (twice as high as the previous record!). With that time we released several patches for Bundler 1.12, optimized and improved fallback for the Bundler API and RubyGems.org, and introduced over a dozen new people to working on Bundler / RubyGems. We also saw six new members join, including three companies.
## ruby together news
This month at Ruby Together was all about people. We went to [RailsConf](http://railsconf.com/?ref=rubycentral.org), kicked off [Google Summer of Code](https://developers.google.com/open-source/gsoc/?ref=rubycentral.org) student projects, and started reorganizing Bundler and RubyGems issues. At RailsConf, both [Gemstash](https://github.com/bundler/gemstash?ref=rubycentral.org) and the [RubyGems Adoption Center](https://github.com/rubygems/adoption-center?ref=rubycentral.org)) got shoutouts and work from attendees. Andre and Samuel also started working with the Google Summer of Code students on a variety of Bundler and RubyGems issues.
We paid for 118.4 hours of time spent on Bundler. That time was primarily focused on bugfixes for Bundler’s 1.12 release, and also laid the groundwork for Google Summer of Code students to start working on several different projects. Lynn reorganized Bundler’s issues and Trello boards so that more information is public and accessible. Finally, we received nomination(s) for board members this month and will be holding an election to decide the state of the new Ruby Together board.
We had three new developers join as members: James Wen, Adam Becker, and Asad Akbar. Three companies joined: [Thoughtbot](https://thoughtbot.com/?ref=rubycentral.org), [Geckoboard](https://www.geckoboard.com/?ref=rubycentral.org), and [Sabre Corp](https://www.sabre.com/?ref=rubycentral.org).
[Thoughtbot](https://thoughtbot.com/?ref=rubycentral.org) is a consulting company with small teams of designers and developers in 10 cities around the world, making software for clients, and contributing to open source software.
Although [Icelab](http://icelab.com.au/?ref=rubycentral.org) joined us last month, we forgot to mention them in last month’s newsletter, so here they are: [Icelab](http://icelab.com.au/?ref=rubycentral.org) is a studio in Australia with a team of problem solvers who want to work with you to build a better world. They work with Ruby every day, and do their best to push Ruby forward through our support of the [dry-rb](http://dry-rb.org/?ref=rubycentral.org) project.
## bundler news
This month we released [Bundler 1.12.1 - 1.12.5](https://github.com/bundler/bundler/blob/master/CHANGELOG.md?ref=rubycentral.org). These changes were mainly bug fixes for the new index format, but we also fixed several issues running Bundler on continuous integration servers. We also worked on upcoming releases this month, specifically breaking changes for Bundler 2.0 and the plugin system that’s been in progress for some time now. On the [Bundler-api](https://github.com/bundler/bundler-api?ref=rubycentral.org) side, we set up a new follower database and then promoted it to primary status. The new primary database means we’ll be able to avoid downtime when AWS services the old primary database later this month.
In total, [Bundler](https://github.com/bundler/bundler?ref=rubycentral.org) and [Bundler-api](https://github.com/bundler/bundler-api?ref=rubycentral.org) had 25 merged pull requests and 119 commits from 10 authors, and we closed 53 closed issues.
## rubygems.org news
RubyGems.org had 24 merged pull requests and 59 commits from 13 authors. We implemented [a variety of infrastructure changes](http://blog.rubygems.org/2016/05/19/simplifying-our-stack.html?ref=rubycentral.org) this month, including serving our millions of gem requests directly from Fastly, reducing our reliance on Nginx and completely eliminating Redis from our stack. Next up is porting the Bundler API’s new index format, working towards our goal of a single unified application to serve the entire site.
This month the team also [blogged about ways to improve RubyGems.org for 2016](http://blog.rubygems.org/2016/05/20/rubygems-org-2016-push.html?ref=rubycentral.org) by increasing contributors, updating policies, and decreasing response times on support issues. Many of the issues described there are due to RubyGems support having been run by volunteers, which Ruby Together is working on addressing! The financial support of Ruby community members like you is making all of this possible. <3
## rubygems news
In the last month, RubyGems merged 13 pull requests, containing 15 commits by 8 authors. We’re continuing to work our way through outstanding issues, planning the future merger of Bundler with RubyGems, and evaluating what we can do to make RubyGems more useful to everyone who depends on it.
## budget & expenses
From April 19 to May 19, Ruby Together took in $17,956\. In total, we spent $58,330.67\. Here’s a breakdown of where the money went:
- $17,752.50 for 118.4 hours worked on Bundler at $150/hour
- $6,900.00 for 46 hours worked on RubyGems.org at $150/hour
- $10,187.50 for 67.9 hours worked on RubyGems at $150/hour
- $76.19 on dedicated servers for RubyBench.org
- $563.08 on payment processing fees
- $5,729.31 on company overhead like hosting, services, software, hardware, taxes, etc
- $1,920.00 on accounting, copywriting, design, and other professional services
- $15,145.53 on marketing, evangelism, and community outreach
We spent more than usual this month thanks to a combination of onboarding new volunteers and Google Summer of Code students, our newest employees ramping up, filing tax returns, attending RailsConf, doing more direct outreach to companies, and working on the Ruby Together store (coming soon!). Look forward to seeing the efforts of our hardworking Google Summer of Code students next month, as well as results from our focused outreach efforts!
Until next time,
Lynn, André, and the Ruby Together team
### April 2016 Monthly Update
URL: https://rubycentral.org/news/april-2016-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello there, and welcome to the Ruby Together monthly update for April 2016! In the last month, we paid for 106 hours of developer time (another new record!). With that time, we handled [a big security issue on RubyGems.org](http://blog.rubygems.org/2016/04/06/gem-replacement-vulnerability-and-mitigation.html?ref=rubycentral.org) and released new versions of Bundler and RubyGems. We also had six new members join, including five companies.
## ruby together news
### meet us, get swag (RailsConf edition)
In May, André will be speaking at [RailsConf 2016](https://www.railsconf.com/?ref=rubycentral.org) in Kansas City, MO. He’ll be giving a talk titled Don’t Forget The Network: Your App Is Slower Than You Think. If you’ll be there, say hello! He’ll have Bundler stickers and Ruby Together shirts and stickers.
### new members
This month six new members joined. One individual member, Ryan Buckley, and five companies: [Icelab](http://www.icelab.com/?ref=rubycentral.org), [Metabahn](https://metabahn.com/?ref=rubycentral.org), [Tommy John](https://www.tommyjohn.com/?ref=rubycentral.org), and [SuperBorrowNet](https://www.superborrownet.com/?ref=rubycentral.org), and [Abletech](https://abletech.nz/?ref=rubycentral.org). Thanks for helping spread the word about Ruby Together to our new members!
### new hires
This month, we hired a project manager and a developer evangelist! [Lynn Cyrin](https://twitter.com/lynncyrin?ref=rubycentral.org) will be working on making sure code releases and update posts happen in a timeline fashion, generating roadmaps, and generally bring order to chaos. [Phil Arndt](https://twitter.com/parndt?ref=rubycentral.org) will be representing Ruby Together to companies (mainly in Australia and New Zealand), handing out stickers and helping companies become members.
### one year anniversary (and board elections)
It’s our birthday! Ruby Together has been around for an entire year. It’s been a really busy year, but we’ve gotten a lot of great stuff done. In our first year, we’ve handled security issues and outages on RubyGems.org and released new versions of Bundler and RubyGems as well as implementing the new index format. We also created and released [Gemstash](https://github.com/bundler/gemstash?ref=rubycentral.org), a server anyone can run to host private gem, or caching public ones. We’re extremely proud of what we’ve managed to accomplish in our first year, and we’re planning to get even more done in year two!
As part of being one year old, it’s time for the yearly board elections. The first step in those elections is nominations. If you’re a member and you want to nominate someone for election to the Ruby Together board, you can! Fill out the [board member nomination form](http://goo.gl/forms/iYgnMVGswj?ref=rubycentral.org) and give us all of your suggestions. Next month, members will vote to decide who will represent them for the next year.
## bundler news
This month we released [Bundler 1.12](http://bundler.io/blog/2016/04/28/the-new-index-format-fastly-and-bundler-1-12.html?ref=rubycentral.org)! Excitingly, this is the first release to use the [new index format](http://andre.arko.net/2014/03/28/the-new-rubygems-index-format/?ref=rubycentral.org). Designing the new index, implementing a server and a client, and rolling it out has taken over two years, but it’s finally done. The new index format means that `bundle install` will be noticeably faster (especially when no new gems versions have been released since the last time you installed). The server-side is also hugely improved, since all the gem data is served by the Fastly CDN from a data center near you, all around the world.
We also saw 29 merged pull requests and 67 commits from 8 authors for the Bundler client and server. Finally, we created a set of [milestones](https://github.com/bundler/bundler/milestones?ref=rubycentral.org) for how Bundler will progress for 1.13, 1.14, and on to 3.0.
## rubygems.org news
RubyGems.org got 13 merge requests and 85 commits from 8 authors. This month involved a lot of cleanup work, and a little bit of infrastructure changes to support the Bundler index format.
## rubygems news
[RubyGems](https://github.com/rubygems/rubygems?ref=rubycentral.org) has 15 merged pull requests and 24 commits from 10 authors. RubyGems released [version 2.6.4](http://blog.rubygems.org/2016/04/26/2.6.4-released.html?ref=rubycentral.org) featuring symlinks on Windows, and using less hard coded strings. RubyGems releases have been fairly consistent since 2.5.2 at the beginning of this year, and we intent to keep them that way!
## budget & expenses
From March 20 to April 18, Ruby Together took in $16,645\. In total, we spent $26,881.32\. Here’s a breakdown of where the money went:
- $4,050 for 27 hours of developer time on Bundler at $150/hour
- $5,850 for 39 hours of developer time on RubyGems.org at $150/hour
- $5,970 for 39.8 hours of developer time on RubyGems at $150/hour
- $75.81 on dedicated servers for RubyBench.org
- $523.51 on payment processing fees
- $1927.29 on company overhead like hosting, services, software, hardware, taxes, etc.
- $0 on accounting, copywriting, design, and other professional services
- $9,003.22 on marketing, evangelism, and community outreach
Some evangelism and outreach work over the past six months had gone unbilled, and we were able to settle all accounts this month. Next month, we expect to continue spending more than usual on outreach, because of our new hire and attending RailsConf to spread the word about Ruby Together.
Check back next month to hear about board member elections, as well as the results of our new hires this month. By that time we will also have rolled out a set of plans for how we intend on updating Bundler, RubyGems, and Ruby Together in general. Towards the future!
Until next time,
André, Lynn, and the Ruby Together team
### March 2016 Monthly Update
URL: https://rubycentral.org/news/march-2016-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello, everyone! Welcome to the March 2016 monthly update for Ruby Together. This month, we paid for 68.25 developer hours, and had 6 new members join. We continued to make forward progress in every project, and quickly restored service after an outage in the RubyGems Dependency API. Keep an eye out for release announcements from Bundler, RubyGems, and RubyGems.org, since we plan to keep them coming. If you’re not a member yet, help us do even more work for the community by [joining today](https://rubytogether.org/?ref=rubycentral.org).
## Meet us, get stickers
This week, André will be attending Ruby on Ales in Bend, OR. He’ll also be giving a talk on the first day of the conference about ways to avoid driving contributors away from your open source project (or company’s engineering team). If you’ll be there, say hello! He’ll have lots of Ruby Together stickers to give away.
## Ruby Together News
In the last month, we’ve been working hard—Ruby Together paid for 68.25 developer hours. We spent that time on Bundler, RubyGems, RubyGems.org, and Google Summer of Code for Ruby. We had six new members join: Tom Johnson, Francis Luong (Franco), Patrick McSweeny, Dan Sherson, Andrew Nesbitt, and Jeffrey Baird.
The bad news is that no new companies joined last month, for the first time since Ruby Together was started. If your company hasn’t joined yet, this would be a good time to encourage them! On the other hand, the good news is that even with no new corporate members, we can afford to pay for 25 hours of development work every week. That’s 100 hours of maintenance and improvements every month on Ruby community infrastructure that was previously being done without compensation, or more likely not being done at all.
In other news, the GSoC student application deadline was this Friday, and we’ve spent much of the month communicating with students about potential projects and their proposals. In all, we received 41 applications, including projects in Bundler, RubyGems.org, Rails, JRuby, and MRI itself.
Over the next month, we’ll be reviewing proposals and requesting slots from Google for the students we want to accept. Last year, we were able to work with every student whose proposal we decided to accept. Hopefully we’ll be able to do that again this year, too.
## Bundler News
Bundler got a fair amount of ongoing maintenance this month, with 45 new commits and 24 merged pull requests from 12 different authors. We also finished the prerelease cycle for Bundler 1.12, and pushed the release candidate to RubyGems.org. If we don’t find any bugs, it will be the final version! Give it a try by running `gem install bundler --pre` and \[let us know\] if you run into any problems.
On the Bundler API side of things, we saw 24 new commits and 13 merged pull requests from 7 authors. When the API started \[returning 503 responses last week\], we were able to investigate, mitigate the issue by adding capacity, continue monitoring, and completely resolve the problem the next day. We also added a graph of API responses to \[the RubyGems.org status page\] so that future issues will be easier to see. Everything is back to working smoothly, and no one had to take unpaid time off of work to do it, thanks to your support for Ruby Together! Good work, everyone.
## RubyGems.org News
The RubyGems.org repo saw 15 pull requests merged, including 99 commits from 10 authors. We added a new application server, fixed a bevy of small issues, and shipped the new download counting setup that works with Fastly from staging to production! If everything goes according to plan, all of RubyGems.org will be served directly from Fastly within the next month.
## RubyGems News
RubyGems saw some nice progress as well, with 20 pull requests merged, containing 33 commits from 9 authors. Fixes included finding the right gem on different platforms, finding the right gem executable stub, and always running the newest installed version of a gem. We released RubyGems version 2.6.2 with some of those fixes, and we’ll be releasing 2.6.3 shortly with the rest of them.
## Budget & Expenses
From Feburary 20 to March 19, Ruby Together took in $18,140\. In total, we spent $13,437.96\. Here’s a breakdown of where the money went:
- $4,275 for 28.5 hours of developer time on Bundler at $150/hour
- $3,112.50 for 20.75 hours of developer time on RubyGems.org at $150/hour
- $2,850 for 19 hours of developer time on RubyGems at $150/hour
- $73.52 on dedicated servers for RubyBench.org
- $566.86 on payment processing fees
- $1,561.81 on company overhead like hosting, services, software, hardware, taxes, etc.
- $210 on accounting, copywriting, design, and other professional services
- $788.27 on community outreach, including stickers, shirts, and speaking at conferences
Over the next month, we plan to ship two big, long-term projects! Work on Bundler 1.12 and the new index format started three years ago, and work on serving RubyGems.org entirely through Fastly started over a year ago. It’s amazing that we’ve managed to accomplish changes requiring years of work—and it’s because of your help.
Until next time,
André and the Ruby Together team
### February 2016 Monthly Update
URL: https://rubycentral.org/news/february-2016-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello, and welcome to the monthly update for February 2016\. This month, we paid for 86.4 hours of developer time (a new record!), and had 7 new members join, including BoochTek and Minnesota Public Radio. We also had our Ruby Google Summer of Code team accepted for 2016!
If you’re not a member yet, help us do even more next month by [joining today](https://rubytogether.org/join?ref=rubycentral.org).
## Ruby Together news
February saw us set a new record for developer hours, with 86.4 paid hours worked on Bundler, the RubyGems.org servers, and RubyGems itself.
Ruby Together also applied to [Google Summer of Code](http://summerofcode.withgoogle.com/?ref=rubycentral.org) for Ruby as a whole (including MRI, Bundler, RubyGems, and other gems). Acceptances were just announced today, and Ruby was accepted! If you’re interested in participating in GSoC, either as a student or a mentor, [join the Bundler Slack](https://bundler-slackin.herokuapp.com/?ref=rubycentral.org) and let us know. We’d love to work with you this summer.
In February, we had four developers join as members, including Lamont Granquist, Nic Boie, Tara Scherner de la Fuente, and Jon Daniel. Two new companies joined, [BoochTek](http://boochtek.com/?ref=rubycentral.org) and [Minnesota Public Radio](http://www.mpr.org/?ref=rubycentral.org). With these new members, our projected monthly income is now $17,120.
## Bundler news
Across the Bundler and Bundler API projects, 50 pull requests were merged, including 123 commits from 13 authors. Work on the next release of Bundler continued as planned: we released not one but two prereleases of Bundler 1.12\. As a result, anyone can start using the new index today by running `gem install bundler --pre`. Try it out and let us know how it works for you!
As long as no new issues come to light, we’ll be releasing Bundler 1.12 final in about two weeks. It’s honestly kind of astonishing to contemplate the idea that it will finally be released, almost three years after starting to work on it.
## RubyGems.org news
In the [rubygems.org repo](https://github.com/rubygems/rubygems.org/?ref=rubycentral.org), 15 pull requests were merged, including 80 commits from 9 authors. We applied security patches, upgraded gems, fixed bugs, and removed a dependency on Flash.
We also shipped the first version of the Fastly log processor to the staging environment. Once it’s live in production, we’ll be able to move all gem downloads to point directly at a CDN endpoint, rather than serving redirects to the CDN from our servers on EC2.
## RubyGems news
RubyGems continued to make significant progress, catching up on the backlog of outstanding issues. We closed 51 issues, leaving only 108 remaining. We also merged 35 pull requests, including 69 commits from 15 authors.
Some highlights from those changes include support for Ruby 2.3’s frozen string literals, better support for pushing to gem hosts other than rubygems.org, and many miscellaneous fixes released as RubyGems [version 2.6](https://github.com/rubygems/rubygems/blob/master/History.txt?ref=rubycentral.org#L3).
## Budget & Expenses
From January 19 to February 19, including Travis CI paying up front for an entire year, Ruby Together took in $18,556.94\. In total, we spent $21,355.40\. Here’s a breakdown of where the money went:
- $4,500 for 30 hours of developer time on Bundler at $150/hour
- $2,887.50 for 19.25 hours of developer time on RubyGems.org at $150/hour
- $7,075 for 41.67 hours of developer time on RubyGems at $150/hour
- $73.20 on dedicated servers for RubyBench.org
- $493.63 on payment processing fees
- $274.58 on company overhead like hosting, services, software, hardware, taxes, etc.
- $70 on accounting, copywriting, design, and other professional services
- $5,530.02 on community outreach, including stickers, shirts, and speaking at conferences
As mentioned in last month’s newsletter, this month’s community outreach spending actually covers multiple months, due to reimbursement delays.
Next month, keep an eye out for more progress on RubyGems and the Bundler 1.12 release, bringing the new index format to Rubyists around the world!
Until next time,
André and the Ruby Together team
### January 2016 Monthly Update
URL: https://rubycentral.org/news/january-2016-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Welcome to the Ruby Together monthly update for January 2016! This month we paid for 55.65 hours of developer time, 7 new developers joined as members, and 2 new companies joined: Simplificator AG and Travis CI.
If you’re not a member yet, help us do even more next month by [joining today](https://rubytogether.org/join?ref=rubycentral.org).
## Ruby Together news
The end of December and January were a pretty quiet time, as usual for most businesses around the world. While it was quiet, we were still working away, and we have hired two more developers to work on Ruby gem infrastructure! Bundler maintainer [Samuel E. Giddins](https://twitter.com/segiddins?ref=rubycentral.org) will be working on both Bundler and RubyGems when his studies permit. Also stepping in to give a hand with RubyGems work is [Ellen Marie Dash](http://twitter.com/duckinator?ref=rubycentral.org). See below for the results on RubyGems—we’re making good progress.
We had seven new developers join as members, including Sean Moubry, Simon Starr, Veronica Ray, Terry Finn, Barrett Clark, and Chris Thorn. Two companies joined, [Simplificator AG](http://www.simplificator.com/en?ref=rubycentral.org) and [Travis CI](https://travis-ci.com/?ref=rubycentral.org). Travis CI has been a long-time supporter of Ruby open source, and provides free infrastructure to run the tests for Bundler, RubyGems, RubyGems.org, and countless other open source projects. With these new members, our projected monthly income is now $16,830.
## Bundler news
Between finals and holiday vacations, work on Bundler was sporadic, but we made significant progress. Across the Bundler and Bundler API projects, 49 pull requests were merged, including 239 commits from 10 authors.
The Bundler API servers are now serving the new RubyGems index format, and the Bundler master branch has merged the new index client code. With only a few known issues left, we expect to ship a prerelease of Bundler 1.12 within the next week or two!
## RubyGems.org news
In the [rubygems.org repo](https://github.com/rubygems/rubygems.org/?ref=rubycentral.org), 13 pull requests were merged, including 82 commits from 10 authors. We applied security patches, upgraded gems, fixed bugs, and improved translations on the site. We also built and deployed a completely new status page at http://status.rubygems.org. It is more accurate, and should also be more reliable.
In addition to improving the codebase, we improved exception reporting, dealt with sporadic CDN outages, blocked abusive traffic that threatened to take down the site, and generally worked to keep things running smoothly.
## RubyGems news
RubyGems is the most exciting project to me in this update, since it is getting seriously worked on for the first time in several months. We closed 50 issues, leaving only 131 remaining. We also merged 17 pull requests, including 31 commits from 9 authors.
Some highlights from those changes include fixing [a longstanding bug with native gems](https://github.com/rubygems/rubygems/issues/977?ref=rubycentral.org), adding Windows CI for the RubyGems, and many miscellaneous fixes released as RubyGems [version 2.5.2](https://github.com/rubygems/rubygems/blob/master/History.txt?ref=rubycentral.org#L3).
## Budget & Expenses
From December 19 to January 18, including Travis CI paying up front for an entire year, Ruby Together took in $25,766\. In total, we spent $10,346.25\. Here’s a breakdown of where the money went:
- $3,000 for 20 hours of developer time on Bundler at $150/hour
- $3,000 for 20 hours of developer time on RubyGems.org at $150/hour
- $2,347.50 for 15.65 hours of developer time on RubyGems at $150/hour
- $73.72 on dedicated servers for RubyBench.org
- $507.31 on payment processing fees
- $1,211.44 on company overhead like hosting, services, software, hardware, taxes, etc.
- $280 on accounting, copywriting, design, and other professional services
We spent around $2,500 on community outreach costs, including stickers, shirts, conferences, and etc., but reimbursements went out too late to be included here. We’ll include them in next month’s budget summary.
Next month, we expect an increase in community outreach as we ramp up operations in the new year. We also expect to pay for between 60 and 100 developer hours, an all-time high.
In the next update: Bundler 1.12, the new RubyGems index format, and further results from reviewing the years-long backlog of RubyGems issues!
Until next time,
André and the Ruby Together team
### December 2015 Monthly Update
URL: https://rubycentral.org/news/december-2015-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Happy new year, everyone! Just in time to wrap up 2015, this is the monthly update for December 2015\. In the last month, we paid for 40 hours of work on Bundler and RubyGems.org, 2 developers joined, and 4 companies joined. The end of the year is always a quiet time, but we were still able to make some great progress.
## Ruby Together news
The biggest news is that we’ve started to pay for work on [RubyGems](https://github.com/rubygems/rubygems?ref=rubycentral.org)! The `gem` command and associated libraries, which ship as part of Ruby itself, will get some love from [Jeremy Hinegardner](https://github.com/copiousfreetime/?ref=rubycentral.org) and [Kurtis Rainbolt-Greene](https://github.com/krainboltgreene?ref=rubycentral.org). Hooray! 🎉
We were also joined by two new developer members, including Brian Buchalter, and 4 new companies, including [Appcanary](https://appcanary.com/?ref=rubycentral.org) and [bitcrowd](http://bitcrowd.net/?ref=rubycentral.org). With these new members, our total monthly income is now projected to be $16,620 per month. As this amount increases, we plan to increase developer hours spent on Bundler, RubyGems and RubyGems.org, moving from 15 hours per week towards full-time work on Ruby infrastructure. If you’re not a member yet, help us reach that goal by [joining today](https://rubytogether.org/join?ref=rubycentral.org).
## Bundler news
The last month was very productive for Bundler. We released [Bundler 1.11](http://bundler.io/blog/2015/12/12/version-1-11-released.html?ref=rubycentral.org). The biggest new features are the error messages: our goal is to never show an exception and backtrace while running the `bundle` command, and instead print a message that explains what the problem is and suggests solutions if any are available. This release was a huge step in that direction. We now catch many, many errors that were previously uncaught, especially ones around filesystem permissions and access problems.
The other big error message improvement was in the resolver. When your Gemfile contains gems that can’t all be installed together, the error message will now show every gem’s current version, the version you asked for, and the versions that ultimately conflicted. It doesn’t happen a lot, but when it does, the new messages make it much, much easier to resolve the problem.
The third big feature of 1.11 wasn’t actually a feature: we fixed bugs. Lots of bugs. We fixed over 50 bugs, making this version of Bundler the most stable one we have ever released. To start using Bundler 1.11 today, just run `gem install bundler`, and you’re good to go! All told, in the last months 9 different authors pushed 199 new commits, working on Bundler version 1.11 and upcoming versions 1.12 and 2.0.
Next month, we’ll be working hard on Bundler 1.12, with support for [new RubyGems index format](http://andre.arko.net/2014/03/28/the-new-rubygems-index-format/?ref=rubycentral.org)! It’s really exciting to see more than two years of work finally paying off with increased speed and reliability.
## RubyGems.org news
In the last month, 10 authors pushed 54 commits to the RubyGems.org and RubyGems infrastructure repositories. We improved search, added a new API endpoint with information about single versions of gems, improved the copywriting on the site itself, and dramatically improved the Spanish translation.
We also settled on the final plan for processing download counts with Fastly, and started working on the implementation. Once that stats system is set up, we’ll be ready to switch the entire RubyGems.org site over to be served by Fastly.
## Budget & Expenses
From November 19 to December 18, including Airbnb paying up front for an entire year, Ruby Together took in $28,775\. In total, we spent $12,366.34\. Here’s a breakdown of where the money went:
- $3,000 for 20 hours of developer time on Bundler at $150/hour
- $3,000 for 20 hours of developer time on RubyGems.org at $150/hour
- $71.34 on dedicated servers for RubyBench.org
- $506.90 on payment processing fees
- $1,399.68 on company overhead like hosting, services, software, hardware, taxes, etc.
- $1,077.50 on accounting, copywriting, design, and other professional services
- $3,310.92 on community outreach including stickers, conferences, etc.
We made great progress on Bundler and RubyGems.org this month. Check back next month to hear about Bundler 1.12, the RubyGems.org Fastly migration, and the results of Ruby Together starting to pay for work on RubyGems and the `gem` command!
Until next time,
André and the Ruby Together team
### November 2015 Monthly Update
URL: https://rubycentral.org/news/november-2015-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello, and welcome to the Ruby Together update for the month of November! This was an extremely eventful month: we paid for 40 hours of development work on Bundler and RubyGems.org, and we were joined by a record 17 (!) new members. We also added a new Ruby Together team member, spoke at RubyConf 2015 in San Antonio, Texas, and lots more.
Keep reading to hear about everything we managed to do this month, and if you’re not a member yet, [sign up today!](https://rubytogether.org/?ref=rubycentral.org#join) to help us get even more done.
### Ruby Together news
This month, the biggest news is that we have a new Ruby Together team member! [Carina Zona](https://twitter.com/cczona?ref=rubycentral.org), noted developer evangelist and public speaker, will be helping us spread the word about Ruby Together.
Carina gave the opening keynote at RubyConf 2015, and helmed the Ruby Together exhibitor table. André also spoke at RubyConf, and occasionally manned the table as well. At our RubyConf table, we distributed shirts, stickers, and information to anyone who was interested.
The Ruby Together shirts were extremely popular, with all 250 gone in less than an hour! They were so popular, in fact, that we’re going to be launching a new site where everyone can get their hands on one in a design and size that makes them happy.
There were eight new developers who joined us since last update, including Leo Liang, Abdullah Esmail, and Kazuho Yamaguchi, Ryan Bigg, Ravil Bayramgalin, Teng Siong Ong, Jason Charnes, and Nikki Murray.
Nine new companies signed up, including [CodeMiner 42](http://www.codeminer42.com/?ref=rubycentral.org), [GitLab](https://about.gitlab.com/?ref=rubycentral.org), [AppFolio](http://www.appfolioinc.com/?ref=rubycentral.org), [Kindly Ops](https://www.kindlyops.com/?ref=rubycentral.org), [Binary Noggin](http://binarynoggin.com/?ref=rubycentral.org), and [Appcanary](https://appcanary.com/?ref=rubycentral.org). CodeMiner 42 deserves a special shout-out for being the second company ever at the Sapphire level, along with Stripe.
Thank you to everyone who signed up! With the new memberships, our projected monthly income has now reached $16,550 per month.

### Bundler news
This was a great month for Bundler, as well. A prerelease of version 1.11 has been pushed to RubyGems.org, and anyone can use it with `gem install bundler --pre`. In a week or so, once we’ve seen it working in the wild, we’ll update the website at [bundler.io](http://bundler.io/?ref=rubycentral.org) and announce the changes with a full blog post there. In the meantime, here’s a brief summary of what’s new:
- Dramatically improved messages on permission errors
- Resolver conflict messages now show the conflicting version numbers
- Git repos using HTTP can have credentials set via `bundle config`
- Update gems without installing them using `bundle lock --update`
This release also lays the groundwork for version 1.12, which will include the (nearly complete!) new index changes, and is on its way to you as fast as is humanly possible.
The Bundler team also released [Gemstash](https://github.com/bundler/gemstash?ref=rubycentral.org) a completely new project that’s been in the works for a while. Gemstash is mainly the work of [@smellsblue](https://github.com/smellsblue?ref=rubycentral.org), [@pcarranza](https://github.com/pcarranza?ref=rubycentral.org), and [@indirect](https://github.com/indirect?ref=rubycentral.org).
Gemstash can act as a gem caching server, storing copies of the gems you need from RubyGems.org. This can be particularly useful if you have an office full of pairing machines, a data center full of app servers, or any other time when you need to install the same gems onto many machines. By running Gemstash locally, you can download that gem from far-off RubyGems.org just once, and then install it from Gemstash after that. Much faster.
The other big thing Gemstash offers is private gem hosting. If your company has been using private git repos in order to avoid an internal gem server, or if you have an internal gem server that never seems to work correctly, start using Gemstash! Git gems require copying the entire history of every gem, which includes a lot of data that is never used, so releasing private gems can speed things up.
### RubyGems news
The Bundler news was really long, so I’ll try to keep the RubyGems.org news brief: we applied security updates, merged pull requests, upgraded gems, migrated to a new version of Chef, worked on the Fastly migration, handled an (accidental-looking) DoS attack, and generally kept everything running smoothly. If progress with the Fastly transition continues at this rate, we should be completely moved over within the next two or three months.
Eagle eyes may have noticed that this section used to be called “RubyGems.org news”, but is now called “RubyGems news”. That’s because Ruby Together is also going to be able fund work on the `gem` command and the RubyGems client! Exactly as we’ve hoped since the beginning, more members means we have the budget for more developer time. The RubyGems library ships inside Ruby itself, and is used extensively by Bundler, and could really use some maintenance. Check back here next month for an update on our progress finding someone to tackle RubyGems.
## Budget & Expenses
From September 19 to October 18, Ruby Together took in $16,315\. In total, we spent $15,830\. Here’s a breakdown of where that money went:
- $3,000 for 20 hours of developer time on Bundler at $150/hour
- $3,000 for 20 hours of developer time on RubyGems.org at $150/hour
- $73.56 in dedicated servers for RubyBench.org
- $499.09 on payment processing fees
- $877.69 on company overhead like hosting, services, software, hardware, taxes, etc.
- $400 on accounting, copywriting, design, and other professional services
- $4,735.43 on community outreach including stickers, conferences, etc.
As you may have noticed, we’ve started spending a bit more on community outreach. It seems to be working! The Ruby community has been very encouraging and enthusiastic, and so we’re going to keep doing everything we can to let everyone know that we exist.
In the upcoming month, both André and Carina will be working on outreach and evangelism projects. If we can find the right developers, we’ll also start paying for work on the RubyGems client library and gem command, following our roadmap.
Thanks for the support, everyone!
We couldn’t do it without you. <3
Until next time,
André and the Ruby Together team
### October 2015 Monthly Update
URL: https://rubycentral.org/news/october-2015-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Just in time for Halloween, it’s the Ruby Together monthly update for October 2015! This month we paid for 40 hours of developer time to maintain and improve Bundler and RubyGems.org. We gained four new individual members, and three new company members. Every new member means we’re able to do more for the Ruby community, so if you’re not a member yet, [sign up today!](https://rubytogether.org/?ref=rubycentral.org#join).
## Ruby Together news
In the last month, André spoke at ROSSConf, the [Ruby Open Source Software Conference](http://rossconf.io/?ref=rubycentral.org), in Berlin, where he spoke about the history of Bundler and led a hackday of work on Bundler by new contributors. André also attended EuRuKo, the European Ruby Conference, and gave a lightning talk about Ruby Together.
Attendees at both conferences were very positive and excited about the idea of Ruby Together, but most of them were hearing about Ruby Together for the first time. Since it seems like most Ruby developers and companies haven’t heard about Ruby Together yet, we’re going to work on doing more conferences and outreach in the coming months.
Since the last update, we’ve had three new companies join: [Contributed Systems](http://contribsys.com/?ref=rubycentral.org) (makers of the popular [Sidekiq](http://sidekiq.org/?ref=rubycentral.org) gem), [Estately](http://estately.com/?ref=rubycentral.org), and [DevMynd](http://devmynd.com/?ref=rubycentral.org). We’ve had four new individual members join: Dave H, Sudodoki, Rebecca Skinner, and Raphael Campardou. Thanks for your support, everyone!
With those new members, our projected monthly income is now $13,100 per month. With that income, we’ll be able to not only pay for maintenance work on Bundler and RubyGems.org, but also pay for outreach and evangelism work to let more companies know about what we’re doing. With more companies, we’ll be able to support more Ruby open source projects and get things done even faster. Hooray!
## Bundler news
Excluding merge commits, this month the Bundler repository saw 136 commits by 17 authors. 28 pull requests were merged, and a good amount of progress was made on bug fixes, new features, and future plans.
The most significant progress was on the new [gemstash](https://github.com/bundler/gemstash?ref=rubycentral.org) project, an open source server for hosting gems. Gemstash is able to act as a caching proxy for RubyGems.org, providing local copies of gems for a data center or office. It is also able to host private or internal gems, and offers an easy way for teams to migrate away from using gems directly out of git repositories. We’re not quite at 1.0, but everything is already working! We’ll have a release candidate out shortly once we’ve polished up the documentation and done a bit more QA testing.
## RubyGems.org news
On RubyGems.org and associated repositories, 23 pull requests were merged, and in total 20 authors pushed 114 commits.
The SSL certificate for status.rubygems.org was renewed and updated, and the [gem adoption center project](https://github.com/rubygems/adoption-center?ref=rubycentral.org) continues to make progress after the end of the RailsGirls Summer of Code.
We also applied many security updates, continued work on the integration with Fastly, and shipped a beta version of the completely rewritten new-and-improved search. Once we’re sure that it works, we’ll enable it for everyone, and searching for gems will finally include all of their information rather than just their names.
## Budget & Expenses
From September 19 to October 18, Ruby Together took in $12,680\. In total, we spent $11.245.53\. Here’s a breakdown of where that money went:
- $3,000 for 20 hours of developer time on Bundler at $150/hour
- $3,000 for 20 hours of developer time on RubyGems.org at $150/hour
- $75.43 in dedicated servers for RubyBench.org
- $403.72 on payment processing fees
- $1804.79 on company overhead like hosting, services, software, hardware, taxes, etc.
- $1072.50 on accounting, copywriting, design, and other professional services
- $3,396.61 on community outreach including stickers, conferences, etc.
Feedback from the community about Ruby Together indicates that it is relatively unknown. As a result, we’re planing to do more outreach and evangelism work in the coming months, including hiring professional help. In the meantime, if you have friends, coworkers, or managers who don’t know about Ruby Together yet, let them know!
Until next time,
André and the Ruby Together team
### September 2015 Monthly Update
URL: https://rubycentral.org/news/september-2015-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello, and welcome to the Ruby Together monthly update for September! This month we were joined by 4 developers and 4 companies. We continued to maintain and develop Bundler and RubyGems.org, paying for 58 hours of developer time. Keep reading for the rest of the details on our new members, our work, and our finances this month.
## Ruby Together News
On September 9, André went on the [Ruby Rogues podcast](https://devchat.tv/ruby-rogues/?ref=rubycentral.org) for [an episode about Ruby Together](https://devchat.tv/ruby-rogues/224-rr-ruby-together-with-andr-arko?ref=rubycentral.org) with rogues Charles Max Wood and Coraline Ada Ehkme. They discussed why Ruby Together was founded, what its goals are, and why being a non-profit is so important, as well as answering a bunch of common questions about Ruby Together. There’s both an audio recording of the episode and a text transcript, so if you’re interested in what exactly Ruby Together does and how it all works, check it out.
This week, André will be in Berlin, attending the RailsGirls Summer of Code wrap-up party and speaking at [ROSSConf](http://www.rossconf.io/event/berlin/?ref=rubycentral.org) about how Bundler works. He will also be in Salzburg, Austria for [EuRuKo](http://www.euruko2015.org/?ref=rubycentral.org) on October 17 & 18, with lots of stickers. Come say hello and get some stickers if you’ll be around!
Our four new members this month include Rene Sanchez, Ivar Vong, and Kieth Pitty. We were also joined by four new companies: Emerald members [Stitch Fix](http://multithreaded.stitchfix.com/?ref=rubycentral.org) and [New Relic](http://newrelic.com/?ref=rubycentral.org), and Topaz members [Square](https://squareup.com/?ref=rubycentral.org), and [Intercom](http://intercom.io/?ref=rubycentral.org). With these new members, our projected monthly income is now $12,190.00.
This infographic, taken from our roadmap, shows where we’re at right now and what we’ll be able to do as more members join.

Thanks for supporting our work, everyone!
## Bundler News
This month, the Bundler team merged 23 pull requests, including 218 new commits from 14 different authors. We fixed bugs, improved error messages, and added features to the in-progress 1.11 and 2.0 releases.
Integration work on the new index format is almost complete: it works! We just have to handle yanked gems, and it will be time to start beta-testing. It’s very exciting to see the culmination of two years of planning and work pay off.
## RubyGems.org News
The RubyGems.org team kept things moving smoothly this month, merging 16 pull requests, including 95 commits from 14 authors. We fixed bugs, added tests, applied security updates, and handled unexpected traffic spikes.
We also kept working on the new logging system, merged a Chinese (Simplified) translation for the RubyGems.org interface, moved even more of the site to be served by Fastly, and renewed our SSL certificate for another year.
The RailsGirls Summer of Code ends this week, and so we are working with the RGSoC team to deploy their work in a Gem Adoption Center that will allow unmaintaned gems to be adopted by new owners.
## Budget & Expenses
This month one company pre-paid for an entire year, and Ruby Together took in $22,043.83 over the last month.
In total, we spent $16,120.54\. Here’s a breakdown of our spending by category:
- $5,700 for 38 hours of developer time on Bundler at $150/hour
- $3,000 for 20 hours of developer time on RubyGems.org at $150/hour
- $76.20 in dedicated servers for RubyBench.org
- $444.51 in payment processing fees
- $1,957.97 on company overhead like hosting, services, software, hardware, taxes, etc.
- $1,600 on accounting, copywriting, design, and other professional services
- $3,341.86 on community outreach including stickers, conferences, etc.
Like we predicted last month, professional services have dropped dramatically, while we’ve started spending more on conferences and other community outreach. Help us get the word out!
Until next time,
André and the Ruby Together team
### August 2015 Monthly Update
URL: https://rubycentral.org/news/august-2015-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello, and welcome to the Ruby Together update for August! This month 5 developers and 3 companies joined, including [David Heinemier Hansson](https://twitter.com/dhh?ref=rubycentral.org) (creator of Rails) and his company [Basecamp](https://basecamp.com/?ref=rubycentral.org). We also continued to maintain and develop Bundler and RubyGems.org, paying for 40 hours of developer time. Keep reading for more details on projects, members, and finances.
## Ruby Together news
Since the last update, five people joined as new members, including Jacob Helwig, James Turnbull, and Matt Mills. [Kickstarter](https://kickstarter.com/?ref=rubycentral.org) joined as a Topaz member, and two companies joined as Emerald members: [Yammer](https://yammer.com/?ref=rubycentral.org) and [Basecamp](https://basecamp.com/?ref=rubycentral.org).
I’m excited to announce that thanks to our new members this month, we’ve hit our first major fundraising goal! With an projected monthly income of $10,780.00, Ruby Together is now able sustainably pay for ongoing work on both Bundler and RubyGems.org every week.
This infographic, taken from [our roadmap](https://rubytogether.org/roadmap?ref=rubycentral.org) shows where we’re at right now, and what we’ll be able to do as more members join.

Today, [RubyGems](http://github.com/rubygems?ref=rubycentral.org) doesn’t have any consistently active maintainers, but it has outstanding issues that we would really like to start working on. As more companies and developers join, we plan to fund work on RubyGems as quickly as possible.
## Bundler news
On the Bundler team, we’re just now wrapping up the Google Summer of Code and the four (!) students who had projects working on Bundler. [@suhastech](http://github.com/suhastech?ref=rubycentral.org) researched plugin systems and wrote a prototype that we will use to inform future plugins work. [@rgb-one](http://github.com/rgb-one?ref=rubycentral.org) fielded tickets and refactored and improved the Bundler website. [@smlance](http://github.com/smlance?ref=rubycentral.org) worked on changes for Bundler 2.0, which we hope to release as an alpha within a few weeks. [@fotanus](http://github.com/fotanus?ref=rubycentral.org)’ worked on the new index server, which should be live soon.
Complementing @fotanus’ work on the new index server, core team member [@segiddins](http://github.com/segiddins?ref=rubycentral.org) is finishing up the new index client, and we plan to release the fruit of their labor as Bundler 1.11 very soon.
## RubyGems.org news
On the RubyGems.org side, we made steady progress on the switchover to using [Fastly](https://fastly.com/?ref=rubycentral.org) as our CDN. Last month, about 45% of our total data transfer was served by Fastly while this month it should be closer to 90%. The RubyGems.org servers were upgraded to use Ruby 2.2.2, for the latest performance and security improvements.
We also added publicly accessible backups of our Redis server, hardened the site against failing services, applied security patches, upgraded gems, updated packages, reviewed pull requests, and answered support tickets. It was a busy month!
## Budget & Expenses
Thanks to one company pre-paying for over 9 months, Ruby Together took in $19,239.00 over the last month.
Thanks to that extra money, we were able to repay a loan that covered our initial startup costs. We also bought some software and hardware that will help us do our jobs more easily.
In total, we spent $16,033.77\. Here’s a breakdown of our spending by category:
- $3,000 for 20 hours of developer time on Bundler at $150/hour
- $3,000 for 20 hours of developer time on RubyGems.org at $150/hour
- $74.63 in dedicated servers for RubyBench.org
- $611.98 in payment processing fees
- $4,438.16 on company overhead like hosting, services, software, hardware, taxes, etc.
- $2,185 on accounting, copywriting, design, and other professional services
- $2,205 to finish repaying company-founding expenses, including legal counsel and government fees
- $549 on community outreach including stickers, conferences, etc.
As predicted, our spending on professional services has gone down now that we’re a bit more established as a company. In the coming months, we expect to start spending more on community outreach and conferences.
Right now, the most common response when we approach developers and companies is simply “what’s Ruby Together? I haven’t heard about it”. That needs to change. :)
Until next time,
André and the Ruby Together team
### July 2015 Monthly Update
URL: https://rubycentral.org/news/july-2015-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello, and welcome to the Ruby Together update for July! This double update includes both June and July, so it’s longer than usual. We’ve also started including details about Ruby Together’s budget and development spending in our monthly updates, so be sure to take a look.
## tl;dr
In June & July, we launched a new website, a significant new version of Bundler, shipped new ops tools for RubyGems.org, gained 15 new members, and paid for 80.33 hours of maintenance and development work on Ruby infrastructure. If you’re interested in the details, keep going!
## Ruby Together news
The [Ruby Together website](https://rubytogether.org/?ref=rubycentral.org) relaunched just this week. The new design is a direct result of feedback from the community, and focuses on keeping the community informed about what we’re doing and what our plans are. The [Ruby Together roadmap](https://rubytogether.org/roadmap?ref=rubycentral.org) showcases those plans, while the new [faq](https://rubytogether.org/companies?ref=rubycentral.org#faq) answers your questions.
Founding board member [Aaron Patterson](http://twitter.com/tenderlove?ref=rubycentral.org) informed us that while he is still “on board” with Ruby Together, he needed to retire from our board of directors. Instead of leaving his seat empty, the board conducted a search, and we have appointed [Coraline Ada Ehmke](http://twitter.com/coralineada?ref=rubycentral.org) as an interim board member. Best wishes to Aaron, who will now have more time to spend with his cats, and welcome to Coraline!
Finally, as the culmination of weeks of planning, we were able to announce that Ruby Together will only fund development work on open source projects that adhere to a code of conduct for maintainers and contributors. Anyone interested can check our blog for the [more detailed announcement](https://rubytogether.org/news/2015-07-15-project-codes-of-conduct?ref=rubycentral.org).
## Bundler news
Bundler 1.10 includes several long-awaited features: a `lock` command, inline Gemfiles inside of scripts, the ability to disable post-install messages, optional gem groups, and conditional gem groups. For much more detail, including a discussion of the BUNDLED WITH section in the lock file, check out [the 1.10 release announcement](http://bundler.io/blog/2015/06/24/version-1-10-released.html?ref=rubycentral.org).
A combination of unexpected factors made some users very unhappy with the 1.10 release. As a result, we spent dozens of hours talking with users, coming up with workarounds, and trying to help everyone upgrade to the newest version of Bundler as smoothly as possible. An overview of the problems and the results of that work are also discussed in the release announcement, so reading it is probably worth your time.
Since the last update, [Google Summer of Code](https://www.google-melange.com/?ref=rubycentral.org) kicked off, bringing four student contributors to Bundler! For three months, [@smlance](https://github.com/smlance?ref=rubycentral.org) will be working on Bundler 2.0, [@fotanus](https://github.com/fotanus?ref=rubycentral.org) will be working on the new index format, [@rgb-one](https://github.com/rgb-one?ref=rubycentral.org) will be working on project maintenance and the website, and [@suhastech](https://github.com/suhastech?ref=rubycentral.org) be working on a plugin system for Bundler. We’re very excited to have them!
## RubyGems.org news
The RubyGems.org team, led by David Radcliffe, made some great progress this month. Deploying the site is now handled by [Shipit](https://github.com/Shopify/shipit-engine?ref=rubycentral.org). The logging system that’s been in progress got some attention, and we’ll be migrating to a new service in July that should need much less maintenance in the future. We switched to using a new chatbot, improved our Fastly config to reduce client errors and position us for the full Fastly migration, and started work on improved search. Finally, two new ops members joined the volunteer team, bringing the ops team up to 4 members.
[RailsGirls Summer of Code](http://railsgirlssummerofcode.org/?ref=rubycentral.org) also started, with a team working on RubyGems.org. RailsGirls Team Binary will be working on a RubyGems adoption center, to match up gems that need maintainers with developers who have time to work on them.
## New members
In June & July, 9 new developer members joined, including Phil Cohen, Brian Lauber, Camille Baldock, Joshua Bell, Rohit Paul Kurukilla, and Nick & Amanda Quaranto.
Four new companies joined: Ecstatic Labs, Optoro, CustomInk, and Koombea.
Today, Ruby Together has 75 developer members, 4 Topaz company members, 3 Emerald company members, and 1 Sapphire company member.
## Funding status
Our combined memberships currently amount to a projected monthly income of $8,350 per month. This infographic, taken from [our roadmap](https://rubytogether.org/roadmap?ref=rubycentral.org) shows where we’re at right now, and what we’ll be able to do as more members join.

## Budget & Expenses
During the months of June and July, Ruby Together took in $20,811.92 and spent $20,031.92\. Here’s a breakdown of the categories that we spent money in:
- $4,550 for 30.33 hours of developer time on Bundler at $150/hour
- $7,500 for 50 hours of developer time on RubyGems.org at $150/hour
- $148.92 on dedicated servers for RubyBench.org
- $613.58 in payment processing fees
- $3,121.92 on company overhead like hosting, services, software, taxes, etc.
- $4,877.50 on accounting, copywriting, design, and other professional services
Spending on professional services is high right now, because the company is still getting off the ground in our third and fourth months of existence. As our revenue grows, we expect to spend more on developer time and servers, and the same amount or less on professional services and overhead.
Until next time,
André and the Ruby Together team
### Project Codes Of Conduct
URL: https://rubycentral.org/news/project-codes-of-conduct/
Last updated: 2026-03-04T17:51:34.000Z
At Ruby Together, we are very proud of the culture that has emerged around the Ruby programming language. However, we also acknowledge that our community still has progress to make with regard to being welcoming and accepting of different kinds of contributors, be they women, people of color, people on the LGBT spectrum, or other underrepresented populations.
One of the ways to signal that an open source community is welcoming is to adopt a formal code of conduct. Codes of conduct, which started primarily as a means of improving conferences and other events, have gained traction over the past year with open source projects as well. The [Contributor Covenant](http://contributor-covenant.org/?ref=rubycentral.org) is one of the most popular of these codes of conduct, and has been adopted by dozens of open source projects including Bundler, GitLab, AngularJS, rubygems.org, and RubyBench.
Being overt in our openness is a first step toward making the Ruby community a better place. It is in this spirit that Ruby Together is announcing a new policy regarding open source Ruby projects that we will support: to be eligible, a project must have a clear and enforceable code of conduct that applies to all contributors and maintainers, and project owners must make a commitment to ensuring that the policies laid out by that code of conduct are enforced.
We as a community have created something special, and it’s our responsibility to ensure that our core values are clearly communicated and shared by everyone. We hope that only supporting projects with a code of conduct is a positive step toward this goal.
— André, Coraline Ada, and the Ruby Together team
### June 2015 Monthly Update
URL: https://rubycentral.org/news/june-2015-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Wow. June was really busy. Right as it was time for us to write the June update, the Bundler 1.10 release turned into a Bundler 1.10 fiasco. We spent dozens of hours talking with users, coming up with workarounds, and trying to help everyone upgrade to the newest version of Bundler as smoothly as possible.
The discussions and workarounds are summarized in the epic [Bundler 1.10 release announcement and retrospective](http://bundler.io/blog/2015/06/24/version-1-10-released.html?ref=rubycentral.org). We weren’t able to complete the regular Ruby Together update due to that emergency work, but we’ll have a complete update ready on schedule for July, and it will include details about June as well. See you then!
Until next time,
André and the Ruby Together team
### May 2015 Monthly Update
URL: https://rubycentral.org/news/may-2015-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello! Welcome to the second Ruby Together monthly update, for May 2015.
## Projects
This month, Ruby Together was able to fund 20 hours of maintenance and development work on Bundler, and 20 hours of maintenance and development work on RubyGems.org, as well as the hosting costs for RubyBench.org.
As more members join Ruby Together, we’ll be able to fund more development work and complete more useful and exciting plans. In the next few weeks, we’ll be revealing more details about those plans and how members can help us get them done.
## Bundler work log
Since last month, Bundler released a lot of new versions: 1.7.15, 1.9.5, 1.9.6, 1.9.7, 1.9.8, 1.9.9, 1.10.0.pre.1, 1.10.0.pre.2, 1.10.0.pre.2, and 1.10.0.rc.
The 1.9.5-1.9.9 releases fixed various bugs in the 1.9 series as they were found. Happily, none of those minor bugs were the result of the new resolver, making Molinillo a resounding success.
The big news this month is that version 1.10 has reached Release Candidate! This version includes a boatload of new features: optional groups, conditional gem installation, inline gemspecs for scripts, the lock command, dramatically improved outdated output, a 10x speedup while resolving slow Gemfiles, and more.
Read more about the exact changes in [the changelog](https://github.com/bundler/bundler/blob/1-10-stable/CHANGELOG.md?ref=rubycentral.org), install the RC by running `gem install bundler --pre`, and try it out!
We also worked on changes that will become part of version 1.11, writing code that allows Bundler to understand the long-planned new index format. Once it’s done, running `bundle install` will be way faster, no matter where you are in the world.
## RubyGems.org work log
RubyGems.org maintenance this month included security upgrades, gem upgrades, ongoing work on the logging system, and starting an upgrade of the deploy system.
Development work included several small fixes and upgrades, and the large change of deleting yanked gems immediately when they are yanked. All previously-yanked gems have now been deleted, and all of the RubyGems.org help tickets about deleting yanked gems have been resolved.
## Meet the team!
In the next month, André will be speaking at [RedDotRubyConf](http://www.reddotrubyconf.com/?ref=rubycentral.org) in Singapore, [RubyNation](http://www.rubynation.org/?ref=rubycentral.org) in Washington DC, and [MagmaConf](http://magmaconf.com/?ref=rubycentral.org) in Manzanillo, Mexico. If you see him, be sure to say hello and ask for a Ruby Together sticker!
## Coming up…
During the month of June, the RubyGems.org team will be working on upgrading the deploy system and the centralized logging service.
The Bundler team will be squashing bugs and writing documentation to finish the 1.10 release, as well as continuing work on version 1.11\. Faster `bundle install`, here we come!
## New members
In the last month, 11 individual members joined Ruby Together, including Yang Bo, Paul Campbell, Serene Careaga, and Janis Miezitis.
Thanks for the support, everyone!
If your company hasn’t joined Ruby Together yet, let them know about it! Ruby Together is both [good and good for companies](https://rubytogether.org/companies?ref=rubycentral.org), and we’ll be able to do more for the community as more companies join us.
Until next time,
André & the Ruby Together team
### April 2015 Monthly Update
URL: https://rubycentral.org/news/april-2015-monthly-update/
Last updated: 2022-11-28T23:39:42.000Z
Hello, everyone! This is the Ruby Together monthly update for April, 2015\. This was our first month in operation, and we were able to make a huge amount of progress this month.
## New hires
This month, Ruby Together hired André Arko (that’s me!) to work on Bundler, which led to the release of several significant new features, detailed in the “New releases” section below.
We also hired David Radcliffe, starting to pay him for his work on the RubyGems.org servers and infrastructure. David has worked tirelessly for years to ensure that RubyGems.org stays up to serve gems to the world. As a volunteer, David has spent countless nights and weekends donating his time and expertise to the Ruby community, and he richly deserves to be paid a fair rate for his work that benefits every person and company using Ruby.
## New projects
As planned, Ruby Together hired André Arko to continue ongoing maintenance and feature work on Bundler.
Next, shortly after our public launch, we were able to form [The RubyGems Partnership](https://rubytogether.org/rubygems?ref=rubycentral.org) together with [Ruby Central](http://rubycentral.org/). As part of that partnership, we have hired [David Radcliffe](http://github.com/dwradcliffe?ref=rubycentral.org) to support his ongoing maintenance and development work on RubyGems.org.
In addition to Bundler and RubyGems, we were able to start supporting the RubyBench.org project by funding the dedicated server that the benchmark suite runs on. Since RubyBench is a benchmarking project, it is vital that the test suite run on its own hardware, and that the hardware always be exactly the same. In the future, we plan to support active development of RubyBench as a valuable community resource.
## Bundler work log
The last month included a record number of Bundler releases: we released versions 1.7.14, 1.8.6, 1.8.7, 1.9.0, 1.9.1, 1.9.2, 1.9.3, and 1.9.4.
The 1.7.14 fix addressed a couple of small bugs and one regression, and we have since wound down ongoing support work for the 1.7.x release branch.
The 1.8.6 and 1.8.7 releases fixed edge cases when installing multiple compiled gems in parallel, updating only the requested gem when multiple gems came from a specific gem server, and fixed a regression that could suppress errors that occurred while Bundler required a gem.
The big news, though, was the 1.9 release! Bundler 1.9 is the first version to feature the shiny new dependency resolver Molinillo, written by CocoaPods team member Samuel Giddins. For three months, Ruby Together member Stripe sponsored Samuel to develop a dependency resolver from scratch in Ruby.
That project was a rousing success, and the resulting resolver has now shipped in both CocoaPods and Bundler. It’s even been [submitted to RubyGems as a pull request](https://github.com/rubygems/rubygems/pull/1189?ref=rubycentral.org). As a result of this cooperation between all three Ruby projects that manage dependencies, any improvements or bugfixes to the dependency resolver in one of the projects can be shared among all of them. You can [read more about the 1.9 release](http://bundler.io/blog/2015/03/21/hello-bundler-19.html?ref=rubycentral.org) on the Bundler blog.
## RubyGems.org work log
RubyGems.org maintenance this month included several security upgrades, including an upgrade to Ruby version 2.1.6\. We also started work on a centralized logging service for all the systems that keep RubyGems.org running, which will be a big help when work needs to be done in the future.
Development work included several small fixes and upgrades, while the primary focus was on designing and implementing an upcoming policy change: soon, yanked gems will be deleted rather than simply removed from the main gem index. This change should significantly reduce the number of support tickets that the RubyGems.org team has to answer, and make the entire yanking process act the way that users expect it to.
## Meet the team!
This upcoming week, André, David, and several Ruby Together board members will all be attending RailsConf 2015 in Atlanta, GA. As well as attending, André will be giving a talk titled “How Does Bundler Work, Anyway?” on Tuesday, April 21 at 11am in room 204 CDE.
If you’ll be at the conference, say hello to us—we’ll have Ruby Together stickers for you!
## Coming up…
During May, the Bundler team will be working on finishing the 1.10 and 1.11 releases, which will include several useful new features and a major optimization to how long it takes to run `bundle install`. Keep an eye out for more about those changes in next month’s newsletter.
The RubyGems.org team will be working to finish the consolidated logging changes that were started in April, and starting work on revamping the worldwide gem mirrors to use the same automation infrastructure that was just finished for the main site. They’ll also be working on implementing the server-side changes that are required for Bundler 1.10 and 1.11.
## New members
In the last month, Stripe and Engine Yard joined Ruby Together as founding corporate members. Cloud City Development and Bleacher Report also joined as corporate members.
| 66 individual members also joined Ruby Together, including Tony Pitale, Mark Turner, Pat Allan, Becker, Sean Linsley, Carol (Nichols | | Goulding), Youssef Chaker, Todd Eichel, John Wulff, Fred Jean, Zee Spencer, Luis Lavena, George Sheppard, David Hill, Josh Kaufman, Chris McGrath, Christopher Eckhardt, Derik Olsson, Henrik Hodne, Corey Csuhta, Jeremy Hinegardner, Philip Arndt, Andy Croll, Piotr Solnica, Andrew Broman, Justin Etheredge, Piotr Szotkowski, Tiago Amaro, Andrew White, Ezekiel Templin, Matt Jones, Garrett Dimon, Alexey Mogilnikov, Joe James, Mykola Kyryk, Mariusz Droździel, Dan Wagner, David Elliott, Ender Ahmet Yurt, Dan Fockler, Jason Waldrip, Ryan Clark, Joel Watson, Ching-Yen Ricky Pai, Badri Janakiraman, Matt Pruitt, and Jeremy Green. |
| ------------------------------------------------------------------------------------------------------------------------------------ | | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
Thanks for the support, everyone!
If your company hasn’t joined Ruby Together yet, let them know about it! Ruby Together is both [good and good for companies](https://rubytogether.org/companies?ref=rubycentral.org), and we’ll be able to do more for the community as more companies join us.
Until next time,
André & the Ruby Together team
### Cloud City and Ruby Together
URL: https://rubycentral.org/news/cloud-city-and-ruby-together/
Last updated: 2022-11-28T23:39:43.000Z
Ruby Together is immensely pleased to announce that [Cloud City Development](http://cloudcity.io/?ref=rubycentral.org) has become our newest corporate member. Cloud City has employed [André Arko](https://twitter.com/indirect?ref=rubycentral.org) for years, providing him with time and opportunities to work on open source, speak at conferences, and work on Ruby infrastructure.
Cloud City continues to support work on the open source powering Ruby’s infrastructure both indirectly, by providing André with consulting work to ensure his bills are paid, and directly, as a member of Ruby Together.
Join Cloud City in supporting and improving the infrastructure that all Rubyists depend on by [becoming a member](https://rubycentral.org/#join) of Ruby Together.
### David Radcliffe Joins The Team
URL: https://rubycentral.org/news/david-radcliffe-joins-the-team/
Last updated: 2022-11-28T23:39:43.000Z
Today we are excited to announce that Ruby Together has begun paying [David Radcliffe](https://dwradcliffe.com/?ref=rubycentral.org), the lead developer of the [RubyGems infrastructure project](https://github.com/rubygems/rubygems-infra?ref=rubycentral.org).
David has worked tirelessly for years to ensure that RubyGems.org stays up to serve gems to the world. As a volunteer, David has spent countless nights and weekends donating his time and expertise to the Ruby community, and he richly deserves to be paid a fair rate for his work that benefits every person and company using Ruby.
As part of the ongoing [RubyGems Partnership](https://rubycentral.org/rubygems) with Ruby Central, Ruby Together funds maintenance and development work on RubyGems.org, ensuring that the servers and software behind the public infrastructure continue to operate smoothly and efficiently. Support our work and [join today](https://rubycentral.org/#join)!
### Engine Yard and Ruby Together
URL: https://rubycentral.org/news/engine-yard-and-ruby-together/
Last updated: 2022-11-28T23:39:43.000Z
Today, we are pleased to be able to inform everyone that [Engine Yard](https://www.engineyard.com/?ref=rubycentral.org), the original Ruby platform as a service, is a founding corporate member of Ruby Together. As a [sponsor of Bundler](https://blog.engineyard.com/2015/engine-yard-sponsors-bundler?ref=rubycentral.org) even before Ruby Together existed, as well as a previous sponsor of Rails, Rubinius, and JRuby, Engine Yard has a long history of support for both open source work and public Ruby infrastructure.
Now, Engine Yard supports Bundler, RubyGems.org, and other Ruby infrastructure as a member of Ruby Together. [Become a member](https://rubycentral.org/#join) alongside Engine Yard, improving things for everyone who uses Ruby.
### Stripe and Ruby Together
URL: https://rubycentral.org/news/stripe-and-ruby-together/
Last updated: 2022-11-28T23:39:43.000Z
Today we’re pleased to officially announce [Stripe](https://stripe.com/?ref=rubycentral.org), the payments platform for the internet, as a founding corporate member of Ruby Together. Stripe has been a a part of Ruby Together since before it even began, when their CTO Greg Brockman came forward to sponsor development and maintenance work on Bundler. That sponsorship proved that the concept of community-funded infrastructure was feasible, and ultimately led André Arko to found Ruby Together.
Stripe continues to [support Ruby’s public infrastructure](https://rubycentral.org/#join) both now and in the future as a member of Ruby Together, and we’re very happy about that.
### Sponsoring Rubybench
URL: https://rubycentral.org/news/sponsoring-rubybench/
Last updated: 2022-11-28T23:39:43.000Z
Since before Ruby Together even launched, supporting and improving [public Ruby infrastructure](https://rubycentral.org/roadmap) has been our goal. Although we decided to focus on Bundler and Rubygems.org as our first two projects, we already had our eye on [RubyBench](http://rubybench.org/?ref=rubycentral.org) as a project to support.
RubyBench provides public benchmarks, running a large suite of performance tests against every commit of Ruby. It also benchmarks every commit to Rails against the performance benchmark suite of the Discourse project. These two benchmarks combined provide massive utility to Ruby developers around the world.
With historical and current performance information, it is possible to find performance regressions quickly, as well as release new versions with confidence that performance has stayed the same or gotten even better. This assurance allows developers to upgrade their projects to newer versions of Ruby and Rails more frequently, more easily, and with greater confidence.
Today, I’m happy to announce that Ruby Together has agreed to fund the server hardware that runs the RubyBench benchmark suite, taking over for RubyBench founding sponsor [Rubytune](http://rubytune.com/?ref=rubycentral.org). In addition to funding the server hardware, Ruby Together plans to fund work maintaining and expanding RubyBench in the future.
To support our work with RubyBench and other projects, [join Ruby Together](https://rubycentral.org/#join) today.
### Friends Of Ruby Together
URL: https://rubycentral.org/news/friends-of-ruby-together/
Last updated: 2022-11-28T23:39:43.000Z
Since we launched earlier this week, several people have let us know that while they think Ruby Together is a wonderful idea, the current membership dues are more than they can afford. We want everyone to be able to support Ruby Together and the public infrastructure, so we’ve created another option: [Friends of Ruby Together](https://rubycentral.org/friends).
Friends of Ruby Together includes everyone who contributes to help support our work. While we aren’t able to provide member benefits to friends of Ruby Together, every dollar will go directly to support our ongoing work on the public infrastructure of Ruby. Contributions can be as small as just $1\. [Become a Friend](https://rubycentral.org/friends) today!
### Announcing The Rubygems Partnership
URL: https://rubycentral.org/news/announcing-the-rubygems-partnership/
Last updated: 2022-11-28T23:39:43.000Z
We are pleased to announce that Ruby Together has joined with [Ruby Central](https://rubycentral.org/) to create [The Rubygems Partnership](https://rubycentral.org/rubygems), an ongoing project to improve the stability and performance of [RubyGems.org](https://rubygems.org/?ref=rubycentral.org).
As part of this partnership, Ruby Central will continue to underwrite hosting and operational costs for RubyGems.org, while Ruby Together will fund ongoing maintenance and development work.
In this way, the partnership accomplishes the goals of both Ruby Central and Ruby Together, ensuring that RubyGems.org is funded and stable for the long term, while also providing a way for it to grow and improve without relying on unpaid labor from volunteers.
To support Ruby Together in its work maintaining and developing Ruby’s [public infrastructure](https://rubycentral.org/roadmap), [become a member](https://rubycentral.org/#join) today!
### Announcing Ruby Together
URL: https://rubycentral.org/news/announcing-ruby-together/
Last updated: 2022-11-28T23:39:44.000Z
All of the infrastructure used by Ruby developers today, including Bundler, RubyGems, and [RubyGems.org](https://rubygems.org/?ref=rubycentral.org) is maintained and developed by volunteers. While it’s good that no one company controls resources shared by the community, it’s terrible that the only people who work on our shared infrastructure are doing so for free and in their spare time.
Ruby Together was founded so the community can cooperate to solve that problem. It will fund on-call rotations, maintenance work, and improvements to the [shared, public infrastructure](https://rubycentral.org/roadmap) used by the entire community.
We’ll also provide [benefits just for members](https://rubycentral.org/companies). To begin with, opportunities to connect and exchange knowledge, turning [RubyBench.org](https://rubybench.org/?ref=rubycentral.org) into a fully-fledged community performance benchmarking resource, and tracking and reporting on important deprecations and security issues for members.
The community that has grown up around Ruby is amazing, and provides many fantastic (and fantastically useful) tools that any developer can use. Let’s work together to make sure those tools (and the community) are the best that they can be, for everyone.
If you or your company has benefited from the free and open-source tools available in Ruby, support those tools by becoming a member of Ruby Together. Membership dues directly fund work that benefits everyone using Ruby, and are usually tax-deductible. Both individual and corporate memberships are available. [Join us today](https://rubycentral.org/)!