There will be bleeps (Friends)

17 Oct 2025 · 1 h 42 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Podcast Episode Notes: The Changelog - "There Will Be Bleeps (Friends)"

Episode Summary In this episode of The Changelog, Jerod Santo is joined by Mike McQuaid and Justin Searls to discuss the recent RubyGems debacle, the implications of money in open source, the concept of sustainability in the community, and the challenges of making a career out of open source contributions. The conversation is rich with insights on governance, transparency, and the evolving landscape of software development.

---

Key Themes and Discussions

  1. RubyGems Incident Overview
  2. Background: The RubyGems community faced significant turmoil due to governance and access issues, leading to the removal of key maintainer Andre Arco from the on-call rotation and GitHub access.
  3. Conflict: There is ongoing tension between Ruby Central and RubyGems maintainers, culminating in a new initiative called "gem.coop" by Andre and other maintainers.
  1. Impact of Money in Open Source
  2. Sustainability vs. Exploitation: The discussion touches on how financial models affect contributors and the culture around open source, with concerns about how maintainers are compensated and the motivations behind contributions.
  3. Changing Dynamics: The conversation considers whether increased funding leads to improved governance and whether it risks making the community exclusive or exploitative.
  1. Career Aspirations in Open Source
  2. Not a Career Path: Mike McQuaid emphasizes that open source is not a traditional career path. Many successful contributors engage in open source as a hobby or side project rather than as their main source of income.
  3. Advice for Contributors: Contributors are encouraged to focus on their passion for coding and problem-solving, rather than viewing open source solely as a means to a lucrative career.
  1. The Role of AI and Automation
  2. Code Generation Tools: The impact of AI tools like GitHub Copilot on development practices is discussed, particularly how they can change the role of human contributors and the value of traditional coding skills.
  3. Zero Dependency Software: Justin points out a trend toward minimal dependencies in software projects, with companies opting for internal development over reliance on open source libraries.
  1. Governance and Transparency in Open Source
  2. Need for Better Governance: The lack of transparent governance in organizations like Ruby Central is highlighted, emphasizing the need for clear communication and better management practices.
  3. Future of RubyGems and Bundler: The episode hints at a potential shift in oversight for RubyGems and Bundler to ensure better alignment with the Ruby community’s needs.

---

Key Takeaways

  • Enjoyment in Open Source: Contributors should engage with open source out of interest and enjoyment, not solely for monetary gain.
  • Transparency is Crucial: Organizations need to improve governance to build trust within the community and ensure long-term sustainability.
  • Adaptation to Change: The landscape of software development is evolving with AI, and contributors must adapt their skills and approaches accordingly.
  • Community Health: The well-being of maintainers is essential for a thriving open source community; burnout and dissatisfaction must be addressed.

---

Conclusion The episode provides a thought-provoking look at the complexities of open source software development amid changing technologies, community dynamics, and financial considerations. It encourages listeners to reflect on their own motivations and the broader implications of their contributions to the open source ecosystem.

---

*For more insights and discussions, tune in to The Changelog and explore the evolving world of software development and open source.*

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:14Welcome to changelog and friends, a weekly talk show about Gen Z career aspirations. Thanks as always to our partners at Fly.io, the public cloud built for developers who ship. We love Fly. You might too. Learn all about it at Fly.io. Okay, let's talk.

0:37Well, friends, the news is out. Our friends over at CodeRabbit, CodeRabbit.ai, they've raised a massive Series B and they've launched their CLI reviews tool. It is now out there. I've been playing with it. It's cool. The bottleneck is not code. The bottleneck is code review. With so much code happening, so many people coding now, so much code being generated, and so many things competing for developers' time and attention to maximize, code review still remains a bottleneck. But not anymore. CodeRabbit, CLI code reviews, code reviews in your pull requests, code reviews in your VS Code, and more.

1:20teams now have a true answer to what it means to code review at scale code review at the speed of ai and code rabbit is right there for you you'll learn more at coderabbit.ai we'll link up their latest blog announcing their series b and their announcement of their cli review tool again coderabbit.ai

1:44well we are here with a breaking change log justin asked me to do that pun a crossover episode. We are publishing shows to both Changelog and Friends and to Justin's Breaking Change hot fix, merge conflict. I don't know what this is on his pod, but it'll be there. The explicit version will be over on Justin's side. On our side, there will be bleeps because we also have not just Justin, but also Mike McQuaid with us. What's up, Mike? Thanks for having me. I hope to make heavy use of your bleep counter today, as is my Scottish self-employed tradition. Well, Mike's only requirement was that there would become a non-bleeped version of his voice out there on the internet talking about this, and so Justin will happily oblige.

2:32Yes, and I'm not going to make it a contest or anything, but I've got a feeling I'm not going to go bleep-free for what we're about to talk about. And the reason for the bleeps is because we've got trouble right here at Ruby Central. Yes, that's an old music man. What is that? I don't know. Trouble! Right here in River City! Right here in River City! With a capital T and that rhymes with P and that stands for POO! For a new problem, maybe not a new problem, an old problem, an issue that's been going on with Ruby Gems, with Ruby Central, with Ruby Together, with Ruby. the community more so than the programming language language is doing just fine isn't it mike seems to be i'm i wrote some today it still works yeah did you install any gems i did they installed okay it seems to be fine yeah i was actually doing an ios project when all this stuff broke but then i was worried that like you know ruby would stop working so i i dropped that switched gears and now i've been working on my posse party project and earnest to try to get it done before the servers turn off.

3:34Just in case, just in case. Well, there's a lot of ins, a lot of outs, a lot of what have yous, as the dude would say to this particular story more probably than I can summarize, which is why I've mostly ignored this in changelog news because there's just so much going on. And every once in a while, I just link over to Justin who's been commentating and color commentating, but we're going to let Mike try to set the table for us. just some of the events that's going on for those who are uninitiated with some of the Ruby drama that's been percolating and coming to a head recently with an actual root access event published on rubygems.org.

4:12So Mike, help everybody understand exactly what's been going down. Yeah. So I guess things kicked off probably what we are. We're October 15th at the time of recording. So this time a month ago, things seemed to all be fairly normal and stable and whatever. No one seemed to really know much. Like, I guess my first personal involvement was there was like a governance PR on Ruby Gems that was based on the homebrew one. I was pulled in and asked to kind of give my thoughts on that. And then a few people started messaging me and whatever. But essentially what went down is Ruby Central, for the main parties involved here, is the nonprofit organization that controls rubygems.org.

4:57And they had, as employees and contractors at various points, various maintainers of Ruby Gems, the open source projects. And those people were involved with rubygems.org kind of on-call rotations and whatever. so essentially kind of i guess last month you know we're talking i think september the 18th or whatever from then onwards over the kind of following few weeks ruby central notified ruby gems maintainers uh including i guess andre arco like i guess if you want to read the two differences of accounts i guess the the starkest extremes here are andre's written a few things on his blog rubygems have written a few things on their blog and basically from september the 18th onwards andre and some other rubygems maintainers were removed from the uncall rotation they were removed from their github access and various bits and pieces went down there's kind of back and forward and arguments and disputes about what was communicated exactly by who and when and what happened and what didn't happen and whatever but essentially we're at the point today where almost no one who is involved with ruby gems open source project has access to be involved with it today and andre and a bunch of the other ruby gems maintainers have created their own thing called gem.coop which right now is essentially like a modified version fork whatever you want to call of rubygems.org it's run as like separate infrastructure and andre has personally been involved with kind of some competitors to like bundler and rubygems and whatever i think there's a tool called rv and as what seems to be now public knowledge is that both parties are writing various blog posts targeting the other and it sounds like there's some kind of lawsuits in action between various parties as well does that provide the overview you're looking for, Jared?

7:00Or do you want a bit more color on particular bits? I think that's a good overview. I think that brings us to what seems to be the biggest milestone or moment, which was published just last week by Shan Curitan, executive director at Ruby Central of this AWS root access event that happened in September. Justin, you want to hop in here on that or do you want Mike to continue? Yeah. So if you're if you if you had been following along the thing that everybody had been clamoring for kind of regardless, like people are taking sides. There's a lot of even though we're not public figures, we're not famous people.

7:44It's like Ruby's been a smallish pond for a long time. A lot of these people have been there for 20 years, 20 plus years. and everybody kind of knows everybody. If you go to the conferences and we've all seen each other and people talk and there's different cliques and there's different groups. And so like, regardless of like kind of like where your allegiances fall in terms of who, what friend group is sort of thinking this way or that way. And, and, and, and where things line up in general, that's like, I'm talking about a universe of like 200 people, Matt's and like way more people in the world use Ruby and, and also read the internet.

8:21And so they've been operating under this complete lack of complete just information of like, what's the whole story? Like something isn't adding up here. You know, some people have been happy to fill the void with like sort of conspiratorial thinking throughout. Like this is all a takeover from Shopify because they're trying to get after this one guy. And it's like, OK, so why? And then no one's got an answer for that. Right. Like and other people are just very honestly and earnestly being like Ruby Central saying that they just removed everyone for supply chain reasons. Like, why? And Ruby Central is not talking, right?

8:54And all you get is kind of hand-wavy. Oh, well, because the lawyer is telling us we can't or something like that, if you ask people. This blog post, which, what was it? Was it the 30th? No, it was more recently. It was published. It was published October 9th. October 9th, thanks. The event might have been the 30th. Yes, the event. No, on the 30th was the blog post that raised concerns. That's right. Right. So part of why this is confusing is the post is a timeline, but the timeline is like three timelines in reverse order to to first talk about like the last thing that happened and in what order things happened when the last thing happened.

9:34And then the next section explains like the why that the why behind that. And then the next last section is the why behind that. and if you were to like and this is why as soon as I read it I put up my own blog post I kind of tried to unspool it to explain like what are the stakes what this reads like to me when you go through it so I'll first try to like summarize it's characterized as a post mortem of security incident response where on September 30th a person named Joel Draper or Draper posts a blog post that says yo Andre Arco still has all these systems accesses like the only person who he's the only owner of a particular github organization uh he's still got these aws accesses and i think that the if not expressly stated implication of the post is this is how incompetent ruby central is that like here we are weeks after supposedly having these accesses removed he actually still has this access and And so look at how insecure this is.

10:38Like, you know, this is this is Ruby Central not having their act together. Right. Because they had taken access away from Andre as well as other Ruby Gems dot org maintainers prior. However, Andre still had access, according to Joel Draper's Draper Draper. It's two Ps. It's two Ps, but Joel Draper just sounds more natural. So I don't know. And my wife and I are rewatching Mad Men, coincidentally. Don Draper. Yes. And so it's just like it's really hard to separate. I agree. I haven't seen it for years, but I'm still saying Draper. Anywho, this post that he says on September 30th is that they're so, I mean, the implication is that the incompetence of Ruby Central, who is the, is it a foundation?

11:20Is it a nonprofit? Help us understand some of the entities here. Ruby Central, is it a for-profit? My understanding is it's a 501c3, which I, frankly, I really wish I didn't know about US non-profit organizations, considering I don't live there and I never will. But yet I've been involved with like open source non-profit stuff long enough that I'm sadly intimately aware. So a 501c3, they're somewhat hard to establish nowadays, because various government agencies have decided that like open source software is a bit too easy to look businessy right so basically it's an organization that exists to own the assets of Ruby Gems um it merged previously with Ruby Together which was started by Andre I don't know who started Ruby Central personally um but basically it exists as an entity to provide legal ownership of the service, to provide the ability to receive tax-free donations from individuals and companies, and then redistribute those to whatever non-profit appropriate areas that they do, which has been RubyGems maintenance, RubyGems on call, some conferences, et cetera.

12:42And there's a lot of moving parts which makes us hard to track. there's like the repos on github there's the uh servers that are actually running said code there's the access of the servers there's databases there's other things that make this just really hard to track but back to so that's ruby central the entity back to where justin was they published this post about joel drapper's post saying that andre still had access or implying that there was right yeah so so so before the post post don't worry like like they actually were notified of of this permissions uh uh exposure so it wasn't a zero day announcement no yeah they had it looks like seven minutes where andre emailed them that he still had these accesses and that this was the only disclosure gotcha joel post goes up uh you know at 5 30 utc uh you know and now this is justin the guy just reading a blog post or forgive me if my characterizations are at all inaccurate.

13:39You know, at that point, Ruby Central has to treat it like a security incident. So they go into emergency mode, try to lock down all these systems, initiate password reset, and then begin a relatively long, you know, investigation of all these other knock-on systems first over the next few hours and then the next few days. When, let's see, the, when they backtrack, right? So that's September 30th. Then there's an analysis of events that goes back and says, hey, look, on September 18th, Ruby Central notified Mr. Arco via email that he was going to have his access removed or that it had been removed.

14:15And while they removed his particular IAM, I assume, like AWS account that presumably would be tied to his email address, they did not rotate the password on the AWS root account. So, you know, like if you're familiar with AWS, there's typically an email address and a root password or an email address that is effectively the root account and it's bad practice to use that thing right and log in as it because you don't have any of the sort of like you know policies and procedures available to you but because andre was like kind of the core one of one of if not the core operator of rubygems.org for so long it appears that even though that he was removed from whatever their password vault system was presumably like a one password.

15:03He had a separate copy of that password or that login item somewhere, because even though his, you know, email was his individual AWS account was apparently, according to Ruby Central, disabled. Looks like roughly eight hours after that notice sent, they state that an unauthorized actor from San Francisco logged into that AWS account, into the root AWS account and then proceeded to change the password. And as far as they know, didn't do anything else. I don't, I'm not an expert in, you know, cloud forensics. So I have no idea if that's a thing that like Ruby sent. It's like the absence of evidence is what's leading them to say that or whether they have any sort of like, you know, dispositive proof that nothing bad happened.

15:48I think I read somewhere that they did have some, like there's like some sort of immutable time-based log and they confirmed from the log, like what had happened, what hadn't happened. Yeah, I read both sides of that. And I think Mike's what Mike just stated seemed like it was more informed than the ulterior, which is once you have root access, you can change everything. I don't know AWS well enough to confirm or deny a side, but I that does that did at the time of my reading seem to be the most reasonable stance that they could confirm it. That being said, I also don't know for sure. Yeah, I pride myself in my ignorance when it comes to DevOps stuff.

16:24So I'll take your word for it. the AWS stuff. I think the thing that jumps out at me with a lot of this stuff is you can plausibly see why both sides thought they were doing the right thing a lot of times in this, right? So like from, I guess, Andre's perspective, what's been published is he says like, well, I thought this was, I didn't have enough information to go on that this wasn't, was a legitimate event and it wasn't like someone at Ruby Central's email or GitHub account or whatever had been hacked. So I was trying to do what I could to preserve the integrity of the service. But I think like what is hard for me with the communication of both sides, right, is I think particularly unsurprisingly now that maybe some lawyers are involved is that I would love to maybe it's just because I'm British.

17:12I would love like a bit more from both sides and saying like, hey, turns out in hindsight, I didn't do the best thing here. right and going forward if you find yourself in the situation i was in my advice to you is to do x instead of y and i did y right and i i think that's the hard thing with all this is that it we're now at a point where there seems to be like some degree of stability and it doesn't seem like ruby central is going to be inviting the folks who have left including andre back into the fold anytime soon it doesn't seem that like you know andrea and co are gonna take control over ruby gems github org or whatever anytime soon like but i feel like the main parties who have suffered through this are people in the ruby community who of which i include myself who are just have a lot of uncertainty of like what's going on right and i can't remember i said this publicly or privately but like essentially the person I feel the most for is anyone in the last month who is trying to pitch a new Ruby project at work with right to a management or leadership team who looks at hacker news even once a week right like good luck right because a whole lot of fear uncertainty and doubt has come into this and and also like I think both sides I see you know I'm I'm a strong proponent of you know i wrote a post a few years ago which some people hate uh some people love it's called open source maintainers are you nothing which points out from like a legal liability perspective essentially every open source license says like if you don't like the terms of that i'm providing you here you can go yourself and just take what you're given and like it you know and from that perspective like i am sympathetic and i i tend towards my sympathy being towards the maintainers but at the same time we have like a critical part of the ruby ecosystem which essentially had no governance process no public governance process whatsoever right that had and still has to some degree very little beyond the legal required levels of financial transparency of required of like a 5.1c3 and a lot of figures making decisions and making statements where most people like i don't know who this person is right i don't know who this person is how they got access who's right who's wrong are my ruby gems safe or unsafe or whatever right and i think that's the part about this all i find really frustrating is that like a whole lot of people are still in the ruby because we're still being disrupted by this and it doesn't seem like it's going to get solved anytime soon maybe ever right because right now both parties are now just in damage control and both again like both sides on i had someone i can't remember it was blue sky or whatever who was basically oh blah blah you seem to have switched sides on this and i'm like well i don't think i mean rarely in life is there a situation where what side a is 100 right side b is 100 wrong but like this is definitely a situation where that's not the case both sides to make mistakes, you may well be inclined more towards one side than the other, but like both sides have to do things to repair trust and fix things and improve things moving forward.

20:34Right. I'm going to just jump in real quick. Sorry, sorry, Mike, because I want to do point out like two of the things from this timeline, then we can move on to the bigger conversation. Yeah. Like open source maintainers who have an MIT license indeed owe you nothing. However, part of the complexity here is like what's under dispute. And this is like a natural, like and i wrote about this in my first post on the topic like the fact that ruby ruby itself is 30 years old mostly maintained by a committer group that's mostly based in japan the ruby gems as a tool was created in america by americans initially and then hosted in america has a separate lineage and there's a three-legged stool between like custody of the code for for ruby gems and then later bundler and then later they merge custody of and management of ruby the language And then like Ruby gems.org, which is like a going concern and operational, you know, system that is running in the cloud.

21:29And so from a from a just accesses perspective, like we're not talking about like who's got commit bit necessarily. So when they say that he logged in with the root email eight hours after getting noticed that his his personal access had been revoked and then he changes the password. And that's on September 18th. You know, you scroll down and it also says on the 28th, he logged in again while he was in Tokyo at Kaigi on Rails, another conference event. And then it's only on September 30th, seven minutes before our blog post, that there's any disclosure whatsoever. Right. So like if he was concerned about the secure their implication in this post is if he was supposedly concerned about the security, Had there been a, you know, had this exposure been leaked out to other maintainers or if it was out in the wild or something like 12 days is an awful long time to sit on that information and not disclose it.

22:24Additionally, when you go back and ask, like, so why did we get to that point? Like what actually happened? You scroll down and the precipitating event to why are we getting serious about supply chain security was apparently and this is an event that, you know, predates August 3rd. So presumably, you know, when and I haven't met her, Shan, the new executive director at Ruby Central, doesn't have a lot of technical technology experience, but does have nonprofit experience. I imagine, you know, Mike, if it's as dire as you're saying in terms of like lack of governance, lack of policies and procedures, my understanding is they didn't even have like terms of service and privacy policy up at the website until earlier this year.

23:08I suspect she probably came in and she's like, we got to like get serious, right? We got to run this thing better. We got to introduce the, you know, standard operating procedure, you know, make sure that we're buttoned up from a regulatory perspective. And then we got to, you know, understanding Ruby Central has been extremely budget constrained since since RailsConf and RailsWorld turned into the schism. Also get the budget under control. And so I knew and I talked to Marty about this, I think, like maybe late last year, early this year when he was taking on the role at Ruby Central, that they were trying to get more, you know, serious about controlling the finances and getting the budget managed well.

23:49And so like when you when you go through the timeline, apparently they cut the budget for secondary on call rotation for Ruby gems dot org, which had previously apparently been fifty thousand dollars annually. And that all of that had or that that amount anyway had gone to Andre Arco's, you know, consultancy to provide that service, even though it was rarely invoked when he was informed that they were removing that budget. He sent an email to Marty that was, you know, kind of spitballing an idea, it looks like, to say, well, in lieu of getting paid in dollars, if I could be permitted to have access to the HTTP logs that could then be used for presumably by a company to do some sort of analysis for some sort of marketable purpose.

24:34And you can debate whether there's any sort of like PII implication or if that could be discerned from the logs. And Mike, my understanding is you probably have, being the homebrew guy, probably been approached by similar companies in the past. Regardless of the actual mechanics and what that would look like, it was pretty clearly not something in the privacy policy currently or the terms of service. And so that email is received on August 3rd. And then it looks like the board and leadership team, and I'm imagining now, and this is just speculation on my part, Shan as executive director, who's not still trying to get her bearings and trying to button this stuff up, probably sees that as like, and this is the person who has all of the access to all these systems and could just take it anyway and is upset that, you know, we're cutting the budget.

25:17Like that's probably the precipitating event. And that's how they characterize it in this email of the thing that leads to, we got to tighten up the security and these accesses and get to, we don't have an operator agreement signed for all these people who have the, you know, operational access. And we don't have committer license agreements for all the people who are committing to this code base and could cause, you know, disputes later. And so we got to get those in place. So like first cut everyone's access, get the agreements in place, and then we can start to rebuild on a, you know, firmer footing is my understanding of the timeline.

25:49Now, like that's that that's what I read reading this, right? It's like it sure it boils up to unauthorized access, ultimately acute alleged against Andre and changing the password and not disclosing it. But but do I have anything there based on your because, Mike, you've been in a lot of the same discussions that I have and with some of the principles. Is anything that I just characterized wrong or is anything you'd want to add to that? Yeah, I don't think there's anything massively incorrect or whatever there. I guess for me, it's kind of an emphasis thing. Just to jump back, I guess maybe a bit of context that might be helpful for folks of where I fit into this party.

26:25So I'm a homebrew maintainer, homebrew being a macOS package manager. If you've not used it before, you can use it on Linux now as well. Fun fact. Yeah, I've worked on that for 16 years. I've essentially been probably the main person since the creator left who's kind of stepped into leadership stuff and have kind of led us through various levels of financing and fiscal hosting and all the kind of a lot of the kind of boring non-profit-esque stuff but notably homebrew does not have a dedicated non-profit we do not have any dedicated employees or anything like that but we have an open collective which essentially if you've never used open collective before is like a online banking app but is in the spirit of open source public right so you can go and see two homebrew maintainers went out for lunch about a month and a half ago in singapore together as our expenses public docs say that they can do and they had lunch they talked about homebrew and they expensed that to the project and we i approved that expense right so like essentially all the money coming in and out of the project you can just go and look right with without even logging in and see like what's going on here you can't see people's specific receipts with their credit card numbers for hopefully obvious reasons but the thing i i struggle with with a lot of this stuff is right like okay like homebrew and ruby gems would be going for about the same amount of time i ruby gems has definitely received dramatically more money in that time i would bet than homebrew it would surprise me if it was as little as 10x more than homebrew but yet we a group of volunteers scattered around the world have been able to have transparent governance transparent finances for like five plus years and you know i appreciate like this is all part of a kind of tightening process and whatever but i the thing that to me that all of these kind of blog posts and a lot of the discussion is missing is like okay who got what money from who and when right like that goes as far as ruby central employees ruby central board members ruby central contractors it goes like you know there's been a lot of conspiracy about like how much mike perham like has provided or removed funding dhh has provided or removed funding shopify has provided or removed funding right and i don't even want to speculate on one of those because i don't know what's true or not true but the thing i find slightly depressing about it all is like it would be very easy to have all that information be at least semi-public right but it's not so it becomes like an exercise and i do think again like with the like what access andre had to what and when and how and whatever i also think again what i said earlier about the open source maintenance or you nothing thing it's like at that point is he an unpaid volunteer working on a service right and providing that to the best of his abilities like if i certainly think from the accounts we're looking at had andre never received uh sent from ruby central ever i think he would read his narrative and be like that is 100 defensible like what he did and ruby central are 100 of the wrong because they are a well-funded organization with full-time employees who like sorry the bar is just much much higher for them than it is for unpaid volunteers but if volunteers are paid how much are they employees are they contractors like what's their contract say or not say or whatever and i think that stuff is where it just all gets very murky and that stuff is where personally it makes me not happy that this is happening but i've been sort of saying sometimes privately sometimes a bit more diplomatically publicly for years that like hey look it seems like a lot of people have decided that open source sustainability is a problem we solve by just throwing more money at things right and this is the type of thing that happens when we do that right it's not to say that we shouldn't no one should have been getting paid or we shouldn't have had money or whatever but like once you start getting a lot of money involved in these things things get very complicated right and you need to have significant levels of like maturity and governance and transparency and experience in open source and experience in non-profits to not up and then maybe even if you have all those things you still f*** up right but like I think that's where this stuff gets interesting for me is I'm like well you know in some ways if you were to look at homebrew and look at ruby gems you would say like well you know homebrews all this in this precarious silly situation because they don't have a dedicated non-profit they don't have significant corporate backing whatever but in a funny way we are immune to a lot of the problems that have happened here because we have not gone in so hard on like we now have significant dependencies on paying significant numbers of people like their monthly wage right and again not to say we're doing it better they're doing it worse whatever but i think there's a lot of the open source i guess i sometimes call it like big open source right that is trying to push a lot of people in this direction that like we all need to just get maintainers to be paid full-time employees right and contract everything out and whatever and i think what gets lost is like well what happens if we do that what are the pros and cons and to what extent that events like this happen or at least get a lot more messy and complicated than they could have been otherwise if there was not the same degree of money involved

32:12What if AI agents could work together just like developers do? That's exactly what agency is making possible. Spelled A-G-N-T-C-Y, agency is now an open source collective under the Linux Foundation, building the internet of agents. This is a global collaboration layer where the AI agents can discover each other, connect, and execute multi-agent workflows across any framework. Everything engineers need to build and deploy multi-agent software is now available to anyone building on agency, including trusted identity and access management, open standards for agent discovery, agent-to-agent communication protocols, and modular pieces you can remix for scalable systems.

32:56This is a true collaboration from Cisco, Dell, Google Cloud, Red Hat, Oracle, and more than 75 other companies all contributing to the next-gen AI stack. The code, the specs, the services, they're dropping. No strings attached. Visit agency.org, that's A-G-N-T-C-Y dot org to learn more and get involved. Again, that's agency, A-G-N-T-C-Y dot org.

33:28So if I were to just jump to the end of this, and I'm going to jump right back where you are, Mike. But if I were to jump to the end, as a guy who just types gem install every once in a while or bundle, right? I know you too. I've interviewed DHH. I've interviewed Shopify people. I've never met Andre myself. I'm tangentially related to the Ruby community as a regular old Ruby user. and to speak to Mike's point from earlier at the end of this is a rubygems.org aws root access event like if that's what I hear and I find out it was days or hours or however long it was and was it Andre was it somebody else were they malicious were they not can we verify like that's a five alarm fire isn't it I mean I install my gems just like anybody else does unless you've switched over to gem.coop from rubygems.org.

34:21And somebody had root access to their AWS account for some amount of time. And that's probably all that I'm hearing, maybe a little bit more about other things. And so this, the end result is a disaster. I mean, this has been disastrous. And now we're in, like you said, my damage control. And so that's just incredibly unfortunate and a fact of history now that I think comes from whether he said, she said, they did this, they did that, who's to blame, et cetera. It comes down to like money has just muddied and created no end of trouble. And it's just really, really murky now, like how you navigate money and open source.

35:05I mean, just combining those two things together, which has been a desire and something I've preached for many years is like, we need more money and open source. We need to fund these people. We need to sustain these people. We need to help these people because they're giving things away for free and then other people are using them and taking advantage and applying pressure and et cetera, et cetera. But we've gotten some money now. I mean, I'm not talking about now this year, but like over the last 15, 10, 15 years, money's come in in certain amounts. You know, it's not evenly distributed by any means.

35:34And it seems like I don't know if I can say it's caused more trouble than it's solved problems. Maybe it's been better than, maybe it's a net positive. But man, it sure made things even more complicated. And I'm not sure how we navigate this. I'm not sure how we navigate this going forward. Maybe the answer is complete transparency. And maybe the answer is, I don't know. I don't even can't even imagine an answer that makes sense. But Mike, your stance is like, you can't, you can't do it. You can't do full-time open source maintainer as, you know, free to work on the project, however they like.

36:14Like whatever we all imagine would be the perfect life of an open source maintainer. Like there is no such thing. Is that your stance? Pretty much. I mean, Justin's like, you know, hot fix podcast thing was like, okay, come with like a pithy quote that's like a controversial statement. and i think the shortest pithiest version i got was like open source is not a career right like and what i mean from that is that i think there's plenty of ways to be an open source maintainer and make a lot of money right like i've done fairly well for myself financially i have had some doors open for me that would not have been opened otherwise were it not for my open source work for sure right i mean arguably maybe bar my first job out of university college whatever like i think every other job my open source maintenance has influenced me getting that job but also every other job has never has my paid main work been working on open source right like that i'm particularly working on homebrew right like i've right when i was at github i was a get which I was, you know, given permission to help migrate us urgently from Bintray to GitHub packages, right?

37:35And I worked on a bunch of internal code for that. I worked on a bunch of external code for that in homebrew. But like, bar that, like, that was not my job. I did homebrew stuff in bits of spare time, in evenings and weekends, in time between meetings, whatever it may be, right? And that was not what I was paid for or promoted for or whatever, right? I built stuff internally, right? I guess not unrelatedly, I was one of the first people to, first four engineers to build GitHub sponsors, right? So that was an interesting thing for me because it was being on the front line of like, well, what happens if we put a bunch more money into open source?

38:15And I think GitHub sponsors, again, it was telling because if you looked, and a lot of this is all public knowledge, right? If you look at the people who have made the most money out of GitHub sponsors, they are not the best open source maintainers and they would not be offended in me stating that they are not the best open source maintainers they are the people who have done the best job selling themselves and selling something which other people value through github sponsors as like a payment provider essentially right and good on them that's that's great that they do right but but there's a lot of people myself included who just slap up a github sponsors right like i do a lot of homebrew stuff and have done for 16 years my monthly github sponsors payment is 22 a month right that's not me going and saying i want to get a bunch more i get you know a bit more than that i get 300 a month from homebrew um as like our kind of maintainer stipend but you know the reason why i don't get a load of money that way is because i have not dedicated time and energy into building essentially a sales process for my sponsorship pipeline and that's how it works right If you want to be an open source maintainer that gets funded primarily through sponsorships and money and whatever, it doesn't look like a tip jar.

Read the full transcript

39:28It looks like you are now running essentially like, you know, in the same way that other influencers might have an influencer economy or whatever. And there's various routes of making that money and paying those bills and getting that open source work. Right. But there's not a single easily treaded path that is not without compromises. and it makes me very cross to see a bunch of particularly younger main terrorists being told like no this is the way if you follow this you will both be rich and you can work on whatever source you ever want whenever you want right that's just a lie that's just right yeah well hold on just let me just say this for those who are putting them through the pain of watching us on video.

40:10The fringe benefit of doing the video version of this is for the last 10 minutes, you can watch Justin sit there and chomp at the bit for his opportunity. Because we've said so many things that I'm sure he wants to address so much so that at one point he was literally holding his mouth shut because he has so many things to say right now. This guy talks for three hours uninterrupted and he hasn't had a chance to say anything for the last 10 minutes. So Justin, just turning the floor over to you, my friend, which of these many points would you like to address first gotta admit to anyone watching the video i did get distracted at one point because my pen ran out of ink and i had to write down because he literally left at one point he literally left and then came back yeah i uh so that so that was distraction number two distraction number one was i uh uh saw somebody texted me that uh the vision pro with m5 was announced oh so well there's a five alarm fire right there yeah if i don't yeah that just to tell you my priority is as one as one of the five remaining daily driver vision pro users who i use the mac virtual display every day like we've discussed several times on the show even so i will not be buying it uh because because it's just basically i'm using it as a monitor but uh and i'd much rather just talk about that now but to to try to honor what mike just said when we say open source is not a career is kind of running a consultancy uh it's helping co-found help start whatever like a consulting company speaking at conferences doing some amount of open source you know none of i was very fortunate in life in that none of my open source was super successful it seems like a huge pain in the ass when it when that happens for for the most part in terms of the burden of issues and pull requests and yada yada but i was visible enough that people would come up to me.

42:05Younger folks, less experienced people, people trying to succeed in this industry. And they would, whether it was about speaking or whether it was about blogging or whether it was about doing open source, a lot of the activities that people saw me do, they'd look at that and they'd confuse the means with the ends. So they'd say, Hey, how do I break into open source? And I'm like that's a real weird goal because like i do open source because i'm trying to get something done that makes me money like working out for a client and like we got a you know the first real project i did was like i was a java client and like we had a whole lot of javascript and no way to run tests against it in ci and i was like that won't do and so like we started unit testing our javascript with jasmine like locally well how do you get that running in ci i was like oh i had to figure out a you know this is back in 2010 or whatever like run a a pseudo html and javascript like fake environment in a java runtime and and then make a maven plugin that we could incorporate into the build like and i did that on my own time on a weekend or you know late at night or something and then i just plugged it into the client code the next day right now here you go a gift free of charge because it makes my life easier at work and we're going to ship your code better right And almost every one of my open source projects was that it was, I have a job that pays me money, that that job would be massively improved in terms of the outcomes or my life at that job by writing some open source.

43:38So I'm going to solve my problem and I'm going to make it open because that's that's easier than getting approval to make it closed internally. Right. Like if I if I have some like, you know, asinine idea for how I can make things a little bit better. forgiveness is way better than permission. Maybe it won't work. Like why, why would I fight for like budget and time to go on some, you know, escapade to like, Hey, I can vaguely improve things in a way that you don't understand when I could just go on my own GitHub, publish something publicly and then go and consume that at work. And if it turns out that it's useful, then work is happy to like, let me spend some hours building it because then I've got a virtuous, you know, I've got at least one person depending on it and that's the person paying me.

44:20So then I can keep working on it a little bit and make it a little bit better respond to issues and feedback and that's typically how i've done open source right like that's one way to do it and in the in a very very small sense that at least has like incentives aligned where it's like i make this thing better because it's built for purpose for somebody who needs it and that's not that's not breaking into open source that's not saying like okay so what i want to do is i want to work on this open source project and i've seen this play out lots of times whether it's through the sponsorship deal or you know what um ruby together and later ruby central did was they actually paid hourly for people to work on bundler and ruby gems code bases and when you're like talking about like a high 150 an hour or whatever it is hourly rate to work on an open source tool then a lot of questions arise like what do you work on uh who chooses the priority of that work like it's a You know, if you're talking about 150 bucks an hour or zero dollars an hour with most of the people contributing, making zero dollars an hour, like suddenly there's a perverse incentive there to be like, all right, well, either, you know, what if there's nothing else to do?

45:30Like what if bundler is a solved problem and basically does everything it needs? Like now you've got a perverse incentive to create make work to justify more hours to get more money. and and if the goal at the end of the ends is i want to get make make a you know replacement level tech career doing open source activities i think like the places that leaves you in terms of the amount of complexity and machinations in terms of like how that funding gets to you and the amount of singing and dancing and and and and glad handing and arm twisting that you need to do to like you know extract those dollars from people who might not necessarily see a direct value or benefit or ROI for giving you that money, it leads to places like this that are as goddamn confusing as the situation that we're in now.

46:20And that's, that's, you know, I guess maybe a, a, a twisted knife version of, of the picture that Mike's painting is like, this is just all about at the end of the day, it's like incentives were not aligned because people wanted to get paid. And this is where this leads you. And yes, it's really sad that a lot of people do open source for free but like a lot of people have hobbies for free and if they choose to keep doing them it's kind of their their task i don't know what to tell you and that's the thing like for me genuinely open source for free as a hobby is a beautiful thing like and we should think very carefully before we decide to kill that by either paying everyone, which won't happen, or by making people who aren't being paid feel like they are being exploited, right?

47:09Like I, again, it really f***s me off no end when you have people often with minimal involvement in open source themselves going around telling open source maintainers big companies are exploiting your labor. And I said, well, if only there was a way to get a big company to pay me to write software for them. Oh wait, we have lots of that. But the reason why lots of people, including me, enjoy open source software and have continued to work on it for a very long time is it's like I don't have an engineering manager or product manager or technical project manager being like, please sign your TPS reports.

47:44When will this be done? Is this a yellow T-shirt or a green T-shirt sized project? right like being able to just opt out from all of that bureaucracy is you know that bureaucracy is important and necessary sometimes but it's also nice to not have to do that right and when you don't have to do that you can operate in a different way and work in a different way and that's fine and again we go back to the open source maintainers owe you nothing where it's like if someone doesn't like it like i mean there's legitimately issues on homebrew that people file and it's like this is a legit issue but you're being a head about it so i'm just going to close your issue and when they're like oh but then i'm like well tough tough luck i can do what i want right but if i'm a paid employee and if that person is a paid customer right in some companies you can do that right sure right but that's not terribly advisable and i think this goes back to what we were saying about perverse incentives and like who gets paid and who doesn't get paid it's like well open source maintainers owe you nothing sure people who are being paid to do something owe someone something right right it might and again in homebrew's case we specifically do we have like all open tooling and open documentation and blah blah blah and we pay maintainers that hit a certain threshold three hundred dollars a month we call it a stipend there are people for whom i'm sure the average you know american child delivering newspapers if that's still a thing that happens like is making significantly better hourly wage than some of these open source maintainers are but it's fine because that's just a token amount for appreciation for them right and we're not like but even then we have had it's not we've not done anything publicly or whatever because we try and in homebrew do a reasonable job at keeping some of our drama behind closed doors but even in that case for a very small amount of money we had a person with a very well-paid day job who was doing the wrong thing essentially because they wanted to hit a threshold to get an extra 300 bucks a month right and that made us reconsider how we do this stuff but to go way back to something that justin said right at the beginning right like about you know he did open source to solve his own problems right went back when i got involved first with open source in the heady days of the linux desktop back in like 2007 when i did my first google summer of code and met a lot of these kde people and i was like a linux guy like the thing that people used to say all the time then that I never hear anyone saying now is open source is about scratching your own itch right and what people meant by that back then was like open source is primarily about solving your own problems and then releasing it in a way that other people can benefit from you doing that right and that's why I did it and it's why I do it because when I work on homebrew and I make homebrew a little bit better it's usually because something in homebrew annoys me and I use homebrew therefore I make it better and that's completely the opposite from the attitude Justin was saying of like how do i break it into open source it's like well whenever anyone's asked me that i'm like well find a tool that you use find something annoying with that tool and then go fix it right and they're like oh but you know i don't know javascript yet or i don't know this or i haven't contributed to that code base or i can't find a mentor or whatever and like again as we're being a bit more spicy on this podcast it's like well congratulations you lose you're never going to be a successful open source maintainer right like i've never seen someone who's been an open good open source maintainer who has been taught into being so right or encouraged or given enough money that they kind of finally get over a line or whatever right that helps people contribute and it's great and we shouldn't discount that as being a thing that we do for some people sometimes but like most of the time most of those people it's intrinsic internal motivation that gets them to do this stuff right and it's that doesn't come from i want money i want clout i want my resume or CV to look better.

51:32It has to come from like, I just want to do it because it's interesting and fun for me. Right. I think this goes beyond open source software because the pattern is very generic. It's like, I love doing X. So I do it for fun. I would love to do X more. If I could only make money doing X, I could do it more. And then X becomes not fun anymore. If that's successful, like basically that's the pattern. So it's not just software, but creation of all kinds. Anytime you can parlay your hobby or your passion into a job. Your passion is now your job and your job's a job and jobs aren't fun. Even if you can, you can add to that, Jared, cause then you can, you can take all your friends you have good relationships with.

52:13And I tried this one. It was a lot of fun. And then you hire your friends and then your friends aren't your friends either. That's right. And you live in a basement in Ohio and you're like, Oh my God, what have I done with my life i've destroyed my hobby and my friends but i got money in exchange you know we're just training it all in for money yeah that's the unsolvable problem i think right there and i you know for years and years we've been looking for more paths to funding more ways because there's so many different kinds of open source and there's ones that have an easy time making money because they are right there staring you in the face like they're like end user applications and then there's So the dependency, the dependency, the dependency, who only has a GitHub account and is not on any social networks and is never going to make a dollar on their GitHub sponsors because nobody even knows that they're transitively installing, you know, XZ, for instance, just naming one that was exploited.

53:07And so maybe I just thought there was different models. We need to just explore all these different models. And I remember going back years to Nadia Ekbal's lemonade stand repo, which she published back when she was doing her open source funding, writing. And she documented like, here's all the different ways, bounty programs, open core, blah, blah, blah, blah. And it's like, pick one that helps you. And we've explored on this show over the course of, you know, a decade now, different people doing these different models. And with more or less success. at the end of the day the happiest people that we've ever talked about talked to about their work are the ones that are like yeah i do this for fun i'm not going to monetize and it's like that's that ends up being the healthiest relationship to your open source code is i do this for fun i'm not trying to monetize it because every one of these models we can go through them all and they all produce at some point the perverse incentives that have happened in the Ruby community.

54:06To me, it's not even monetization versus not. It's like direct monetization versus indirect monetization, right? And I can't remember what it was. I'm sure it's some much wizened old philosopher or whatever who said this. I'm going to paraphrase it and butcher it horribly. But basically, the idea of the best things in life are achieved indirectly, right? So let's not be overly crude. I'll try and be relatively diplomatic. but basically you know for example if your goal is romantic companionship right there's ways of getting elements of that very quickly in exchange for money right but most people would say that actually that's probably not the most fulfilling long-term option and the most fulfilling long-term option you know i've been with my now wife for 23 years like we have a perfect marriage and relationship i'm very very happy that takes a lot of time and effort right and again i i have almost like a pending blog post brewing about just being patient feels like it pays a lot of dividends on this stuff like i was at github for 10 years i've been with my wife for 23 my best friend who comes around to my house we're currently watching alien earth is very good we've been friends right now you're watching it well i mean not right now because i'm on a podcast okay well you said your best friend coming over and you're currently watching alien earth i'm like dang this guy can multitask i'll do my best to multitask but yeah i mean we've been friends for like 30 years right and most and homebrew for 16 years like most of the good things in my life are things that i have done for more than 10 years right and there has been ups and downs in those times and there's been times where if you were to look at some tiny microcosm of like the first you know months or weeks or whatever or a particular segment you'd be like oh well this isn't worth that i'm gonna to bail i'm going to quit i'm going to move on right but again like all of these things are things that i've got and i've have made me very very happy and i'm delighted with not because i wanted to make as much money as possible or have as much whatever as possible human relationship interaction whatever but just because like i enjoy the process going along and i still enjoy the process going along and that tends to get you to a very good place if every day you enjoy your life and you keep doing that and keep enjoying your life and at the same time you know stuff like money you're like okay well i need to pay the bills i need to make sure that i make enough money to provide for me and my family and whatever but you're also really excited about what you're doing then that tends to work pretty well and if you go and chase like maximum financial return for anything right on the short-term basis like okay you might make a bunch of money like often you don't but you're probably going to be miserable in the longer term and you're going to be like why am i doing this and i need to quit and whatever right and that's i mean almost that's the definition of sustainability right like when when we're not talking about open source sustainability when we talk about anything being sustainable the idea is how do we get people to be able to do this for a long period of time and without being a you know a cheese ball like open source sustainability comes from within like the reason why i have been able to do it for a long time and not burn out and literally in that 16 year window i don't think i've gone a month without working on homebrew i've maybe not even gone three weeks without working on homebrew and the reason why is because i enjoyed it then and i enjoy it now and i know what i'm willing to do and what i'm going to quit and i built a group of maintainers where i'm very protective over them because i know that's the same for them right and to me just almost looking at yourself in the mirror and be like am i enjoying this is this good like and if it is great do more of that and if it's not then just stop right and that terrifies a lot of people because it's like oh well open source will collapse and we have all these maintainers who walk away and it's like well actually no because someone will step up and do what needs to be done if what you're doing is really important and that's that's maybe the hardest part of it all it's like maybe that open source project you've spent a huge amount of time and energy into maybe it's not that important maybe it is replaceable and maybe your role is replaceable and that sucks to look in the mirror and think that but maybe that's true maybe you need to do that look if you're watching this video you're gonna be probably noticing that like we're three white men you know the the collective noun for white middle-aged men is podcast i get it but it's true and one thing that a piece of context right about like that 2015 to 2021 era especially in the u.s and politically is like this conversation about like you know just being tut tutted by older guys who were already successful in their careers oh just do it as a hobby just do open source in your free time or something when that comes into contact with this motivation that like open sources and ends, not a means it's a way to get, because highly visible people are doing it.

59:09People rightly assume, you know, for whatever reason you're doing it, if I were to do that at the same stage or at the same level of impact or in the same high profile project, then I too would be highly visible. And therefore I could parlay that into, you know, more marketability, right. As a, as an employee, I'd be, I'd be hired in at the staff level or the principal level, or I'd have better employment prospects. And so there's a, you know, even though I started doing open source to scratch my own itch to Mike's point, and that's still the reason I'm ever motivated to do it, it created a virtuous cycle, not just for my employer to be able to benefit from my hobby work, but for me to be able to parlay those projects into new relationships and credibility because your GitHub profile kind of redounds to like at least some kind of proof that this guy can write working software.

1:00:01And this is what it solves. Right. And mixed in with all of that is like, well, what if you don't have the free time or if you've got family responsibilities or there's some other, you know, systemic reason why you aren't able to just work for free and make this time possible? it's creating an avenue for more privileged people who do have that luxury of time to pursue that hobby and then and then even though it's just a hobby it's not like i definitely made more more money out of my like programming habit than out of my japanese language acquisition habit you know like in terms of a hobby so so like that's not that's not lost on me here it's just kind of a fact of life and I don't know how to solve it because when you try to solve this through the lens of, and that's why we got like when the conclusion, and I heard this a lot in the late 2010s was, and that's why we have to pay people to write open source.

1:00:59I was like, that's And there's just so many, like, you know, the number of circles and loops necessary to kind of connect these dots together in a way that's actually going to get the outcome that you want. is so convoluted that this is probably just going to make things worse. I can't say we're in a much better place in all of these experiments where people are, and again, to Mike's point, where people are being directly compensated for their open source efforts, especially in an ad hoc or a semi-directed pseudo-employment manner, like through contracting and through kind of an amalgamation of funds and sponsors and donors.

1:01:41like i don't know what to do i just want i just want to put it out there so we don't get emails about privilege i'll be honest that's why i said those things i think it's a good point and i think it's well made and i'm glad you made that i think for me my take is like should we try and improve the diversity of open source etc like yeah we should i do like hopefully all of us would agree with that to some degree but i also think not everyone having the free time again it's one of those things where if sometimes i think the people pushing a certain narrative haven't done the five whys on like the reason why they're often doing that is because they themselves come from a position of like you need to do open source to have a really great career right and i'm like well no i've i've worked with plenty of like staff plus engineers at github who are phenomenal engineers who've literally never done a single open source commit ever right and i would not tell those people that they should or shouldn't right like considering the number of open source related emails i've had that have fascinating things to say about the size or presence of my and whatever may relate to that and various interactions with my mother etc like like i don't encourage anyone who like doesn't have a current interest in open source to sign up to receive those types of emails right and i don't think we're going to solve that problem anytime soon but i think that's the thing it's like do we see open source as like an essential on-ramp that we have to use to like get people to be successful in the software industry and if you start from that like prior then it's like yeah of course you're going to start thinking like we have to improve diversity and pay people to encourage people in because otherwise you're just gonna you know really up the software industry by not like solving that but i don't think that is a problem i think and ironically i think that is a problem that is exacerbated by people saying we have to pay and we need to put more money in rather than it being solved by that right because no one has to write open source right like that's i think that's the fundamental thing if i can say anything to any person listen to this it's like literally if you have a job where you write open source even even if you're a paid employee or contractor or whatever like i'm sure you can find something else where you don't have to do that right like everyone writing open source in some degree has some element of choice maybe not short term maybe this month's mortgage payment relies on you you know writing open source and whatever right but like long term in the career and also something justin you said you pointed this out on your podcast a lot about how there was this golden age of you know the three of us again are probably similar sort of age there was this golden age of programming like the early 2000s where you know if you came out and you're interested in open source like chances are that was going to help you into a reasonable tech job and you could probably make a decent amount of money and then now we're seeing you know like things are completely horrific for a lot of juniors trying to get into the industry and i think that's the thing it's like i don't like that i don't think anyone in this school likes that but you can't we can't just magically go backwards and undo that and fix that and i think often the people i hear advocating this type of stuff around open source just have wishful thinking of like no if we can go back we'll do it right this time and we'll like reinvent it and whatever and so well that's not how it's been and i loved your point jared about how this is just universal for hobbies right like we could probably have had exactly the same conversation we had right now about like music or whatever right like and money and whatever like i remember when i was at github and there was i can't remember the name of the band it was some like top 10 indie rock band and one like github conference like github had paid for this band to come play and the band came out was that when cold was that when cold war kids played at uh that's the name of the band that's the name of the band but like having been there in the room and i think there was a silicon valley episode that was loosely based on this like they came out and started ever hold on i gotta interrupt you like if you don't know this like most silicon valley episodes were based on interviews with chris wanstrith and people i re-watched it all recently with my wife and it's aged well but anyway so like they came on stage they started playing and like 75 of the people immediately left the room because they were like i don't want to be here right and i'm going to confess something to the you know the two of you here hopefully no one else hears this but you know like i used to be an aspiring musician i have anyone on video can see my mostly now unplayed guitars behind me right and i immediately thought to myself what a bunch of sellouts right like i i would hope to myself that i would never be at a level where i would take any amount of money to go play to a room of nerds myself included like who don't want you to be here and would just immediately leave the room as soon as you start playing right like right and and again like you could say we can have the same conversation money and music right like was that bad that they had that money or took that money or whatever right like i'm not a musician i'm sure lots of musicians are very angry at me for based on what i've said and i'm being a massive hypocrite but like yeah it's i'm sure there's another podcast i'm an identical conversation about this and i think like we're not special in software open source and this is not the first industry to have this problem nor will it be the last no i think that's a great point and i think that i've said this before that people by and large people don't make music in order to make money they make money so that they can make music, right?

1:07:15And I think that there are people who've done both and they're called rich and famous rock stars or whatever. And of course, people idolize those because wouldn't it be the dream to be able to be rich and famous and make music? Like that's, yeah, that's a lot of people's dream, which is why it's really hard to do. And we draw that across to open source and we have had some people who've made livings, who've made really good livings, publishing open source code and creating a following and becoming whatever you have to be in order to get that done. You can go to the top of GitHub sponsors and see a few of those people there.

1:07:49It's an entirely different skill set, just like being a rich and famous rock star requires more than being able to play the guitar because lots of people can play the guitar, but there's more to it than just that. One of those major factors, in fact, is timing and luck and has nothing to do with who you are, your skill set. Another major factor is what you look like, unfortunately, but that's the case. and so open source as career might follow the exact same trajectory as music as career it's like yeah a few lucky very privileged people find a way to make that work and they live a great life and the rest of us it's like you got to decide if you want to do it or not at the end of the day open source is a gift to the world it's you giving back a lot of the motivations for doing it is people saying, well, I got so much for free that I felt like I should just give back.

1:08:41And so that's what I do. And so that's a gift and a gift comes from a place of privilege. You have excess and so you give it. And one of the beautiful things about the digital economy is that we can give it to everybody. Whereas if I was going to go out and buy a new Vision Pro M5, I could just give it to Justin. I couldn't give it to the entire world. it's an amazing thing to be able to do your work once and gift it to the entire world and sometimes it just has to stay that you got my address right for that i figured you already have it on order so i'm probably just no no no not yet you you need the phone you got to scan your face i buy you the new one so you send me your your original maybe you got it i got justin searles original vision pro there's a thing here right because we're kind of conflating programming and making a living programming and open source as like a hobby activity or whatever.

1:09:37And just like music, there's a difference between being able to play music as a skill. Being able to program a computer is a skill. Right. And being a songwriter who puts love and craft and passion and creativity and something of themselves into the music that they create is a passion, a craft, you know, it's an individual pursuit. and yes if you do that you are lucky to get paid and if it does all work out and the stars align then that's a miracle and good for you like but at the same time getting paid as a musician with that skill to go play gigs like there's a guy who you know sings at the lobby bar at a hotel next to my house every tuesday and he's mostly playing you know wonder wall and and you know the country road and yeah and like he's not there for his health but like there's a transaction happening and I don't begrudge him at all right it's like that's you know there there's ambience and there's music and so like hell you know the Cold War kids made me laugh Mike because across the street there's a new hotel that opened I live in Orlando and it's just all resorts and stuff and pools and whatnot the new hotel opened earlier this year or late last year and they had the Goo Goo Dolls play and I was like hell yeah I'm gonna go over for a free Goo Goo Dolls concert and free food and drinks and uh yeah right and it was great I don't begrudge them at all because that was like that was them applying their skill for for for money in that in in that sense you know i mean the songs were written all 20 years ago and everyone's really old and they look suspiciously good and that made me wonder about how they're maintaining that but like when we're not when a programmer is applying that skill to make money at the at the end of the day somebody whoever's paying that money is going to be looking for some kind of value out of it.

1:11:25And if you're, whether you're working for somebody and they're, you know, why do we have planning sessions? Why do we have product owners? Why do we have requirements handed to us? It's because the things that we're typically being asked to build as programmers are at the behest of somebody else who wants to see that software built or continue to operate or to be refined or whatever, in order for them to extract some kind of value out of it. And just like with the singer songwriter who can like eventually get to the point where they get to open new hotels and, and get paid to sing their own songs.

1:11:58Like every now and then you get really, really lucky. Like you, I worked on Ruby and rails for years and years and years. And now there's a Ruby and rails team at a company like Shopify and they hired me and I get to continue doing the stuff. I talked with Aaron Patterson's a good friend with me of mine. And yes, that's part of my bias and my allegiances as I talk to like that crowd of people more than the maintainer side of people who are involved in this particular dispute and fully own that. But like, oh, I'll talk to him about his job. And it's confusing sometimes. I'm like, well, he has work stresses here and there and stuff.

1:12:33But like at the end of the day, he makes good money doing doing that for Shopify. Shopify gets a lot of benefit out of that. but like if he were to quit he would basically be doing the same thing every day for free you know like so that is the stars completely aligning and you know what like I know half a dozen people for whom that is true out of how many thousands of people that I've interacted with and so it's just an unrealistic thing and now this is back to Mike and our original kind of hot fix premise it's an unrealistic thing to just plan on your career being that it's way too high of a bar it's way too skinny of a bottleneck to hope that you're gonna like with any level of confidence squeeze through because so few people do and not for lack of trying well it's like all the youth right now they all want to be youtubers or or tiktokers and it's like that's the it's the new version of i want to be a rock star it's like Like, you know how many rock stars there are?

1:13:35There's like seven of them. Yeah, but the influence of your economy, I think that's, it's similar. And I think - It's been democratized to a certain degree, yeah. Yeah, and we're, I guess, as again, like, you know, three white men in our 40s, like we're probably like, if we had like some Gen Z guest on, yes, it's Gen Z because I'm British. And then I'm sure they would have a very different perspective here. But again, I sort of wonder whether some of this comes from like the concept of like the side hustle right where like the side hustle is often the like i have a hobby and i am going to on top of my job i am going to monetize my hobby and hopefully i can get to a point like you said earlier jared like where my hobby can become my job because i fully monetize it and i can pay the bills and whatever right and i think again music is an obvious example right where there are people for whom music is their career right and they i i know some of them for whom they then go home and they are not interested in playing or producing music in their spare time at all anymore like it's i would just do it for money there's people for whom they are not interested ever making any money from their career ever right in which if we wanted to have a horrific open source metaphor you know some like i was going to say man or woman it's probably like a dude with long hair playing their guitar around a fire while their friends some of them might want to listen probably most of them don't you know someone could go up to them you're being exploited for your labor like you should be paid the same as taylor swift for this right like and it's like well actually no one wants to pay that person because they're not very good and they don't want that job right that person is doing it entirely as a hobby and then there's the people where there's like a blend between the two maybe it's their hobby and it's their job right and i think that's the thing it's like career hobby both right and all of those are acceptable options but it feels like this stuff often gets conflated and even someone like aaron parrson right good example right he's written a absolute boatload of open source code of the years it would be interesting if you went back and somehow did accounting of like okay well what's that that's almost take the amount of money you've been paid to write open source and then the amount of hours you have spent doing open source and hobby related things say any work on a public repo on github in your entire history as a programmer and let's figure out like what your hourly rate is and my my guess would be like it's obviously getting better each year that he is employed by shopify but my guess would be it's actually a lot worse than you think it is because he again like musicians right like musicians are not getting paid to play their scales right people are just sitting when i used to actually be a half decent musician a lot of it was just sitting and spending two hours playing the same riff again and again and again and again slightly faster slightly faster slightly faster slightly faster and like you know no one's going to pay you to do that really boring stuff right and it's i don't think open source is dissimilar and like what i worry about is again i'm from an era of which it wasn't clear that open source was going to win right when i was at university there was still all the kind of like linux and like i can't remember the name of the company that basically there was this big lawsuit and you know steve ballmer linux is a cancer all this type of stuff right and it looked it was like a battle between proprietary software and open source software and some reason the only reason we're even having this conversation is because open source software so clearly and unambiguously won and i maybe i'm being paranoid here but i worry for a world in which we say okay any big company that uses any open source software in any capacity is extractive and unless you are paying all those maintainers a bay area like living wage then you're an evil company like what happens if we actually go all in that viewpoint like do we make those companies be like well you know what i'm actually not going to touch open source anymore i'm just going to pay a team internally to build this stuff right and for a lot of people like me like that would be a very sad thing right and it would that would be the end in some ways of a lot of the non-hobbyists like open source right and right i just think where does the money come from to pay every single open source container with 10 stars on github like a living bay area salary right particularly if as justin said we say to them hey we just give you that money unconditionally you don't need to have a product manager or whatever you just build whatever you think is best however you think is best right like that's right i mean it seems ridiculous to me maybe that's just me but like i think that's the logical conclusion we get of the like peak we should pay everyone because otherwise it's unethical argument here right right yeah to that point we just did a show recently with faras abuka dj about npm security in light of the just the onslaught of NPM hacks, which have been going on and continue.

1:18:19I think after he published that, there's even some newer ones. And one of the things, and he runs, you know, he owns and operates a socket security company. And so he's very much in the InfoSec world and talking with, you know, CTOs and CEOs of larger corporations. And they're saying things like, well, this is not because of open source sustainability, but it's because of open source security and this, you can't trust a network thing. They're starting to have those conversations, especially because of the, uh, you know, first time to say it on the episode, I'm glad we're over an hour in because of the new enthusiasm around AI code gen tools.

1:18:58They're saying things like, you know, do we need NPM? Should we have, should we use, this is not, should we contribute? This is, should we even use Ruby gems? Why don't we just write everything in house? and like that is starting to percolate amongst leadership in you know silicon valley companies and you add to that an open source tax so to speak of whatever whatever it would be mike when you talk about every maintainer has to get this much money therefore every user has to pay in according to their dependencies or whatever however you'd actually work out the impossible logistics of all that it would just be one more reason why people will start to opt out of the economy altogether together and say, yeah, because I look at a world, I don't know if we're going to get there guys, where my co-gen tools can reproduce for me instead of a vendoring a gem.

1:19:49Why don't you just reproduce a gem? And now I don't think we're going to be there myself anytime real soon, especially with gems such as a large, you know, rails, for instance, which is not a gem. It's a meta gem of many gems, but the smaller ones, it's like, why would I even have, why would I care about open source i can just generate everything jared it's funny you mentioned this because it's not just your fever dream but it's like increasingly a thing that i am also hearing in fact world i i'm living it but i i okay my brother uh jeremy he works for cars.com he's elixir and elixir programmer okay and you he gave a talk at elixir conf last month which the i don't know if it was the title, but basically the thrust is zero dependency software.

1:20:36Instead of pulling in these dependencies, and it's not from a security perspective, although when you're talking about open source tax, most people aren't thinking about how this stuff gets funded. They're thinking in terms of yes, maybe the security concerns that I don't trust the software necessarily, especially if you're in a regulated industry and you've got to go and have lawyers go and check licenses and verify all that stuff there there's that tax for sure but more so like i now you know i am running code that i don't control or understand and it's going to have its own update schedule and i have to keep all of these dependencies up to date and of course of course the npm community is famous for like really really tiny modules and that's lots and lots of things that you have to keep up to date and so that upgrade burden is really high and right now you you you take cloud code you take codec cli you point it at a readme and you say all right go clone this repo and i just want this section from the readme i just need this kind of a couple of features right here just go clean room implement that for me if you don't mind and like it'll do it and you can just vendor that in to your point you vendor that into your project and so like i'm working on this posse party rails app and and since going with agents i'm trying to think now i started working with agents in april you know started with you know the github copilot stuff moved on to cursor moved on to cloud code now i'm in the heart of drugs and uh i think that i may have added zero new gems like zero new dependencies definitely zero jobs like oauth stuff you're you're talking to apis i mean this is almost all integration work yes i would be you know this would be for me to as a starting point, it'd be all gems.

1:22:20I'd be like, I get the, the blue sky gem. I get the Instagram gem, right. I owe off gem. And then I just like tie those things together. Cause it's just posting, you know, across different social networks. I won't say just to belittle it, but my point is like, I would expect that to be mostly third-party code. And 10 years ago, that's how I would have done it too. But I, you know, it's not just because of AI enabling this. It's like, I learned the hard way that if you're writing code, that's basically glue code of like eight other different things. Like it's kind of like you're on one train and trying to jump onto another moving train, you know, like in real time is to try to keep everything in line and you're just holding the stuff together.

1:22:56And so, no, I've got, I've, I've written, in fact, this week I'm rewriting my LinkedIn integration that, you know, it's not just a whole bunch of HTTP requests to post stuff. You got to like, wait for it to download. So you need another whole series of, you know, self and queuing tasks to go check to see if the download's done. And then my wife, Becky is like, well, if it doesn't support stories, I'm not going to use it. So I'm adding story support, which I think is supported by as far as I know. No, definitely no Ruby gems, but I don't know if any dependencies are doing this much. And so the nice thing is that when you own the code, you can build on top of it.

1:23:32And when it's inside the code base and it's part of the context of whatever your agent's doing, there's a lot to be said for as the cost of code, and this is how we tie back to this conversation, as the cost of code basically craters to zero asymptotically here. like the writing of the code is not the part that is necessarily making is worth money anymore. So if I'm a maintainer and I want to get paid to write open source code like that, the market dynamics for that are also flatlining right now. And so what we could be experiencing this conflict being a flashpoint and you know, where did, where did it all start?

1:24:07According to Ruby central, it started with them cutting budgets, right? And why were they cutting budgets because sponsorship's declining. Why is sponsorship declining? Apart from the macro stuff and apart from the conference stuff that Ruby Central also runs, I think a part of it is a general sense that we've already hit peak open source, right? In the sense of people's unpaid labor is the way that we're going to get all of this stuff built, not in the sense that things are going to be necessarily open or built on open protocols and platforms, if anything, that's probably going in the opposite direction but the the value of an individual programmer going and hacking out a particular issue or a pr is going to go down if like now you can just at codex something or at claude something and and mike you've been working with this too like using copilot agent and finding it you tell me how you found it yeah so i mean it's funny because a lot there's a lot of copilot related stuff i was one of the first people to test an internal beta of that it's alpha technically um and the reason why lots of people inside github would like me to test things is because i seem to be allergic to telling people that things were good when i thought they were a heap of even when it was strategically and politically advisable for me to say like this person's pet project is wonderful and so yeah my feedback on copilot pretty early on was like wow this is surprisingly not a piece of like when you describe i mean you have to remember like when Copilot came out before ChatGPT and stuff, right?

1:25:34Or at least it was being alpha'd before that. So this sounded like ridiculous, right? That we would like use AI, whatever. And I was like, wow, this is a better auto-completion for Ruby than I've ever seen using any ID or indexing or whatever, right? And it immediately made me more productive. So fast forward to the kind of Copilot coding agent stuff. Again, I saw the kind of memes on hack and use of like Microsoft employees being encouraged or forced to use this publicly and it just being an absolute disaster. and i was like lol i'm gonna try this out and again like maybe because umbrew has borderline fascistic issue templates that demand everything of you and essentially like force you into mike mcquade's opinionated way of how you file a bug right but if you follow that template properly it's actually really great context for an lm particularly when it has all the comments of us discussing it right and i i basically just i think a couple months ago assigned every bug in the homebrew package manager to copilot agents and then you know it took a couple of weeks some of them got their 99 their first time some of them got 50 in the way and i finished off a lot of the stuff but like essentially in two weeks those were all fixed right and you can go and look at the public record and see how well that went or didn't go whatever but like anyone who says like this stuff is not productivity boost is like in any circumstance is massively kidding themselves and the awkward reality of it again back to the conversation is i would say is copilot agent great does it avoid hand-holding no definitely not is it better than the standards drive by a homebrew contributor jury's out right it's certainly comparable and i i definitely think at this point like the first iteration of pr i would struggle to tell the difference to between co-pilot and a first-time contributor right a homebrew maintainer and indeed myself who's worked on homebrew longer than anyone else will do a much better job but even then like i find myself leaning on it because sometimes it's like there's 10 ways of fixing this co-pilot go pick one right and whatever mess you make i will clean that up and get out of the line but it's that like empty page problem and yeah i i think this i'm probably not quite as uh not like pro ai but like i i don't maybe buy stuff quite as heavily as justin says about like the cost going to zero but i definitely think it's impacting stuff pretty heavily and i think we're in some ways seeing like a reversion in the tech industry of like back to what skills are valuable who's valuable whatever right and back perhaps to being like maybe tech is just a slightly less fun place to work right like going way back for me like back in 2009 i got a job on like the third application or whatever to a company called kdab who i knew about them because they employed more than anyone else of kde maintainers in the kde ecosystem and i was like a big linux on the desktop guy and being contributing to kde i was like woohoo i'm gonna go work for this company and i can get paid to write open source right i discovered pretty quickly on my first like 100 open source project that it's like ah actually getting paid to work on open source as a consultancy looks like very tedious boring work right and i can probably say specifically now considering it's been that long ago so k office which was like kd's like open office alternative essentially like a corporate sponsor was like we want k office to be good here's a spreadsheet with 5 000 regressions compared to microsoft word in k office go for these particular import documents go through and just fix these line by line one by one right incredibly tedious work no volunteer wanted to spend their spare time doing it so a company paid people to do it right and again this kind of comes back to a lot of the stuff in the early conversation all the fun enjoyable parts of open source i don't think you're ever going to struggle to find people to do those at least not until you tell them all they're being horribly exploited by capitalism by doing so but like there's gonna always be a bunch of really boring work in open source maybe it's supply chain security stuff maybe it's whatever that's the stuff we need to get the money towards and fund the stuff that people don't want to do and i think that's gonna be there and again it's one of those things where the jury's out with all the supply chain security stuff whether the costs of that balloon beyond what people are willing to pay right like if we have a team internally or we have LLMs that mean that we don't have to pay this tax, then maybe that's what we do now.

1:30:10I've seen some people on the internet be critical of like in way back to Ruby Central, that organization we're talking about at the beginning of this conversation, it kind of incited this back and forth. That Chan, the new executive director is not technical and not from technical communities, but rather is like more there for her nonprofit experience. you know i i remember when uh ruby central was just ben and evan and then they added marty like in 2012 or whatever and it was just the three of them as as the chair people i guess uh and all rubyists all programmers and that felt right and back then in that era that we kind of keep hearkening back to the writing of the code the building of the tool that like you know the brilliant API and the just the the blood sweat and tears to get it over the finish line at a high enough level of quality whether it's a CLI or whatever it is a library and then to publish it that was like where all the action was that was the work that was the thing that required brilliance and that's what the market was you know rewarding so handsomely in terms of great tech salaries if it's the case that it is now no longer you know an incredibly rare thing to have capacity for writing replacement level decent code that means everything else now is more valuable and so to mike's point if i'm run if i'm operating a service and you know jared was scared he said he said he bleeped it out no i'm kidding i believe the whole i must have bleeped the whole sentence out because i don't remember i want a more bleep uh uh more bleeps for a minute i want to be mike i was lying earlier i do want to be oh gosh he's got you down he he does but like if i if i'm running a service and i'm going to be scared you know bleepless to have uh a root level security event occur at the place that i'm downloading all of my gems which could then be root kidding my computer for all of i know for i don't know what it was 12 days like i'm actually really glad that the executive director has a like the hat on now to finally like shore up the governance make sure that like their regulatory and their finances and their tax situation is all buttoned up.

1:32:30And probably I think at the end of the day, we'll probably end up being much more transparent than they've been in the past, which was just the result of negligence, I'm sure, and not malevolence up to this point. Like those are actually the skills that are more valuable because you can't just easily replace them. It requires good judgment and diligence and like experience and oversight. so like you know part of this is a story of just an organization maturing but i think part of it is also like a reflection of like the change in what's what's valuable and important right now and as you look at open source or your conversation with frost which i thought was excellent you know frost is a real smart guy this is where the new locus of of of control goes when when the writing of the code is no longer the most important thing i'm out of things to say so i'll just say a cliche the times they are a-changing, are they not?

1:33:21That was a musical cliche on Mike's behalf. You like that one, Mike? Bob Dylan, right? Yeah, I love it. I don't know that Bob Dylan song, sorry. You don't know Bob Dylan? Come on. Unless it's like Northern European power metal, I'm pretty lacking right now. Yeah, I don't know if they got Dylan in Scotland. They still have newspaper boys and children. Do you have Milkmen still up there, Mike? We until recently had our milk delivered to our house by Jesus. That's amazing. That's so idyllic. Living the dream over here. Well, you knew so much about American culture. I figure Bob Dylan would be right in your wheelhouse, but you know, that only extends so far, I guess.

1:34:02Yeah. I only do the parts of American culture, I guess, to echo this conversation that I'm paid in order to. You're forced to. Forced to learn in order to maintain and sustain employment. Right. And that hasn't yet gone as far as Bob Dylan. Well, I'll send you a$10 donation and a Bob Dylan album. You can just get to work on that. The moment when the Americans should make some sort of sports metaphor, and I nod along as if I understand what baseball's fourth strike, third innings catch, MLB championship Fridays means. Well, this is a nerdier podcast. The joke I was going to make was going to say, no wonder you like alien earth so much because it takes place in a world where America doesn't exist anymore.

1:34:43You can finally relax. It's just five corporations. Each get a continent. Just like how it should be, right? All right, Justin, this is as much your podcast as it is mine. If it were mine, I would say thanks and end it. But do you have more things you want to talk about? Well, since this is going to show up on my feed as a hot fix, we try to end every single interview with some sort of pithy one-liner that represents what is the fix to the problem statement. And it's the guest who I guess in this case is Mike being double hosted by us.

1:35:18It's, Hey, I'm just trying to, can I believe that? I'm trying to beat the bleep filter. You can't, you gotta keep it in. That stays in Mike. Mike, it's your job now to like help us land the plane and find a title for this thing, at least on my feed. Like what is, so if the problem statement is, you know, open source is not a career. like what's the fix like how do what what do you tell people instead like like like how should they how should they what's the takeaway for them in terms of like where should their attention be or you tell me well i guess in some ways i would divide the statement in two right so from the open source side of things do open source if you want to do open source right if you don't want to do it anymore don't do it anymore this is when like when this podcast gets published and like 99 % of open source maintenance quit and we have a world crisis and i'm like oh well uh but like genuinely like and we i very strongly encourage people in homebrew to be like hey the day you're not using homebrew anymore thanks for all your work stop using it move on get on with your life there's been people kicked out of homebrew who are doing a good job but clearly homebrew has been very bad for their mental health so we kicked them out of homebrew right like ultimately this stuff needs to be fun and it needs to be something that you enjoy and if you care about sustainability and burnout and open source you want that stuff to be better like go you know if you're an source maintainer go get some therapy right you probably have some you need to deal with like chances are and then the career side of things it's like again same deal like right if you work in tech chances are you have a career which is nice right it's harder right now than it used to be i'm lucky enough to have a lot of friends with careers outside of tech you know people who are personal trainers who are opening up the gym at like five o 'clock in the morning working like a 60 hour week with a split shift right like that's hard those people do not get paid a lot of money they work really hard and they make a really big difference in people's lives right if you're in a situation where you're getting paid good money to sit in your ass in your home office nine to five monday to friday like you know again maybe it's about figuring out a way to be happy with that or your life and if you don't like that then quit go do something else but like same deal right find a career that has some happy medium point between paying your bills getting what you need out of life and that you can actually enjoy and not hate right and do that right just in both camps do what makes you happy right because that's at the end of the day that's probably what is going to give you a better life and also give those around you a better life and even give like other people that work with you at your work where you're open source or whatever if you're miserable doing what you're doing like you're probably not very nice to work with so let's just all be happy kids that's going to make some people cross i think uh all right so i started with don't do open source if you don't want to which is a little bit long for a podcast title Then I said, do open source for you.

1:38:28And then I just flipped your problem statement. I said, open source is a hobby. Yeah, that works. Works for you. All right. Unhappy maintainers should quit. If you don't like it, quit. Yeah, pretty much. All right. Well, on that note, I'll pretend I'm going to hit my button that plays my music now. And then I'll have my call out and I'll say, hey, Jared, thanks a lot for we're playing at Jared's house right now because we're in his Riverside account instead of Mike's Riverside account or my squad. account just really we're we're all broken but we're glad that you're listening hello hi but it makes us happy especially listening this if you're still listening at this point nobody's paying me i've got no sponsors that's why i get to skip the bleeps that's right our sponsors pay us extra to bleep things out you know so i'm gonna make lots of money off this episode yes i hope it was sufficiently brand safe for you that's a new business model pay per bleep Here's some good news for us.

1:39:28This morning, as I prepare to shift this episode, that's October 17th, 2025, Ruby creator, Mats, posted on rubylang.org about rubygems.org saying, quote, Ruby Gems and Bundler are essential official clients for rubygems.org and the Ruby ecosystem. Bundled with the Ruby language for many years and functioning as part of the standard library, despite this crucial role, Ruby Gems and Bundler have historically been developed outside the Ruby organization on GitHub, unlike other major components of the Ruby ecosystem. To provide the community with long-term stability and continuity, the Ruby core team, led by Mats, has decided to assume stewardship of these projects from Ruby Central, end quote.

1:40:10He goes on from there, lots of details, link in the show notes. Thanks again to our partners at Fly.io and to our sponsors of this episode, coderabit.ai and agency.org, That's A-G-N-T-C-Y dot org. And thanks also to the best beat freak in the biz, Breakmaster Cylinder. Next week on the pod, news on Monday, Ellie Huxtable talking Atuin Desktop on Wednesday, and Kaizen 21 with Gerhard Lazu on Friday. Have yourself a great weekend. Give someone a compliment if you find the opportunity. And let's talk again real soon.

1:41:05there's some words i decided in advance i wasn't going to say so you should be glad for those i appreciate it that's sign of a good friend mike appreciate that all right well we'll just hit the button on both sides i'm not going to end it i'm going to let justin's be the end i'm going to hit the music when he said he's going to hit his music so the show's over at this point justin got the outro well all right okay okay i'm going to keep this stuff in so am i then all right well maybe i should just sing your music if you're going to ruin your show i'm going to ruin mine yeah that that's mutually mutually assured content uh change log plus plus it's better

From the publisher

Mike McQuaid and Justin Searls join Jerod in the wake of the RubyGems debacle to discuss what happened, what it says about money in open source, what sustainability really means for our community, making a career out of open source (or not), and more. Bleep!

More from The Changelog: Software Development, Open Source

All 232 episodes
There will be bleeps (Friends)The Changelog: Software Development, Open Source · 1 h 42 min
Listen in VO