https://www.theregister.com/2021/03/25/ruby_rails_code/ The Register(r) -- Biting the hand that feeds IT search [ ] # # Sign in Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem All On-PremServersStorageNetworksHPCPersonal Tech (X) Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) SecurityOffbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Vendor Voice AdobeGoogle CloudGoogle Cloud's ApigeeNutanixRapid7Red hatSophosVeeam Virtru (X) # # # [devops] Devops Ruby off the Rails: Code library yanked over license blunder, sparks chaos for half a million projects Devs scramble for replacement mimetype data package Thomas Claburn in San Francisco Thu 25 Mar 2021 // 08:24 UTC Share reddit Twitter Facebook linkedin WhatsApp email [https://www.theregis] Copy --------------------------------------------------------------------- Updated On Wednesday, Bastien Nocera, the maintainer of a software library called shared-mime-info, informed Daniel Mendler, maintainer of a Ruby library called mimemagic, which incorporates Nocera's code, that he was shipping mimemagic under an incompatible software license. The shared-mime-info library is licensed under the GPLv2 license and mimemagic was listed as an MIT licensed project. [devops] "Using a GPL file as a source makes your whole codebase a derived work, making it all GPL, so I think it's pretty important that this problem gets corrected before somebody uses it in a pure MIT codebase, or a closed-source application," wrote Nocera in an Issues post. "You will also need to re-add the GPL header to the shared-mime-info XML file as a matter of urgency. It was stripped in release tarballs by the tool used to merge translations, but is visible in the .in version of the same file." [devops] Mendler thanked Nocera for letting him know and promptly moved the latest version, 0.4.0, and version 0.3.6 under GPLv2, and withdrew prior versions from distribution on RubyGems.org, the package registry used by Ruby developers. He then archived the mimemagic GitHub repo, meaning it's no longer being actively developed. A lot of people face palming And just like that, Amazon Web Services forked Elasticsearch, Kibana. Was that part of the plan, Elastic? READ MORE This had the unfortunate effect of breaking the popular web development framework Ruby on Rails, which includes mimemagic 0.3.5 as a dependency. It also affects 172 other packages, which between them touch 577,148 different software repositories. Not all of these projects are immediately affected, though any sort of build process that tries to fetch a withdrawn version of mimemagic from RubyGems.org will fail unless dependency caching has been implemented. Software projects that incorporate mimemagic must now consider the implications of incorporating GPLv2 licensed code, which may not be acceptable in some cases. If that's legally and practically viable, they can switch to either the 0.3.6 or the 0.4.0 version of the library, though not without some effort. Projects like a web app run by the UK government's Department for Business, Energy and Industrial Strategy, the Ruby SDK for the FileStack CMS, and Rails-based taggable image app Danbooru are pondering workarounds for a situation that recalls the left-pad incident of 2016. Since mimemagic is mostly a database of mime type data mappings, the Rails team is looking into replacement options, including 2-clause BSD-licensed libmagic or a Ruby translation of the mime data. But there's a non-trivial amount of work required to make this happen. As for everyone else, Sergey Alekseev, founder of Shopify app maker ASoft, asked Mendler to keep the mimemagic repo active to provide a place for the other affected projects to discuss their options. But Mendler disagreed, stating, "The Rails dependency is certainly the most impactful one. It is best if we find a solution which works for Rails and which is sanctioned by the Rails team." Paul Berg, an open-source licensing consultant, told The Register in an email that while this is a difficult situation, the developers involved appear to be handling it well. "Since the maintainers of the dependent mimemagic library discovered that it contained GPL code, they moved to a GPL license," he said. "The admirable thing is that they reacted once the issue was noticed rather than keeping silent about it and letting the issue persist." "It does cause a major issue for Rails though," Berg said. "Rails is widely used under the MIT license which is a permissive license. Since so many applications are authored using Rails under the assumption that those applications are not copyleft under the GPL, it is likely that a great many of those apps would not be complying with the terms of the GPL since they were not deployed with those terms in mind." "As a consequence of that, relicensing Rails to GPL for rails to be in compliance is likely to be a massive change for thousands of teams and really is not a tenable solution. Unfortunately, other solutions are likely not simple." Berg said mimemagic could try to replace GPL portions of the code and retain its MIT license. Another option, he said, would be for Rails to replace mimemagic altogether, assuming a suitable replacement exists. "In any event, resolving this issue is likely going to be a non-trivial amount of work in a short time frame given the critical nature of Rails to the industry because of its popularity," he said. "I do not envy their predicament." "This illustrates why being diligent in enumerating all dependencies and reused code whenever they are introduced and working to ensure that the licensing of those dependencies is compatible with your intent is so important." (r) Updated to add [devops] On Thursday 26 March, mimemagic was updated again to v0.4.1, which restored the MIT license and removed the GPL covered code - theFreedesktop.org Shared Mime Types database. Users must now provide that themselves. Versions 0.3.6 and 4.0 have been yanked, to the dismay of many. Get our Tech Resources * MORE * Open Source * Software Corrections Send us news 53 Comments reddit Twitter Facebook linkedin WhatsApp email Get our DevOps newsletter [devops] Most Read 1. Global tat supply line clogged as Suez Canal authorities come to aid of wedged 18-brontosaurus container ship 2. Ruby off the Rails: Code library yanked over license blunder, sparks chaos for half a million projects 3. Guilty: Sister and brother who over-ordered hundreds of MacBooks for university and sold the kit for millions 4. Richard Stallman says he has returned to the Free Software Foundation board of directors and won't be resigning again 5. Tesla broke US labor law with anti-union efforts - watchdog [devops] --------------------------------------------------------------------- [devops] Global tat supply line clogged as Suez Canal authorities come to aid of wedged 18-brontosaurus container ship At last, The Reg online standards converter's time has come Richard Speed Wed 24 Mar 2021 // 16:23 UTC Updated The ship that spawned a thousand IT container jokes has been partially refloated [ah, yeah, see update below - ed.] after becoming wedged across Egypt's Suez Canal, blocking a crucial global trade artery. Despite fears the route might be blocked for days - holding up as much as 10 per cent of the world's trade - the Gulf Agency Company (GAC) reported today the Ever Given container vessel was now alongside the bank of the canal [no, not quite, sadly - ed.] rather than its well-documented straddling of the waterway. Efforts to shift the behemoth, which weighs the same as 22,988,822 adult badgers, had been hindered by wind conditions as Suez Canal tugs sought to remove its snout from the banks of the canal. The ship is 400 metres long, "the length of four football pitches," according to the BBC. Continue reading Guilty: Sister and brother who over-ordered hundreds of MacBooks for university and sold the kit for millions Castanedas pocketed $2.3m from 800 laptops alone, Feds say Kieren McCarthy in San Francisco Tue 23 Mar 2021 // 22:38 UTC A sister and brother have admitted over-ordering hundreds of new MacBooks for "a private university" in Silicon Valley to steal and sell the expensive gear for millions of dollars. Patricia Castaneda, 37, of San Carlos, California, worked at the university's School of Humanities and Sciences, and was responsible for ordering replacement laptops for the faculty and its staff who were entitled to a new one every three years. Over the course of ten years, starting in 2009, she methodically over-ordered and then sold them on, initially for cash through ads on Craigslist, and then through a man she met through one Craigslist ad, again in cash. Continue reading Richard Stallman says he has returned to the Free Software Foundation board of directors and won't be resigning again 'Some of you will be happy at this, and some might be disappointed' Tim Anderson Mon 22 Mar 2021 // 12:26 UTC Updated Richard M Stallman, founder and former president of the Free Software Foundation (FSF), announced at the organisation's LibrePlanet virtual event that he has rejoined the board and does not intend to resign again. Stallman spoke at the event yesterday on the subject of unjust computing - covering locked-down operating systems, non-free client software, user-restricting app stores, and more. Before the talk he stated: "I have an announcement to make. I'm now on the Free Software Foundation Board of Directors once again. We were working on a video to announce this with, but that turned out to be difficult, we didn't have experience doing that sort of thing so it didn't get finished but here is the announcement. Some of you will be happy at this, and some might be disappointed, but who knows? In any case, that's how it is, and I'm not planning to resign a second time." Continue reading Tesla broke US labor law with anti-union efforts - watchdog And Elon Musk must delete 2018 tweet threatening loss of benefits for unionizing Thomas Claburn in San Francisco Fri 26 Mar 2021 // 20:28 UTC Tesla has been ordered to correct its unlawful labor practices, and its supremo Elon Musk must delete a related tweet from three years ago. In a ruling issued on Thursday, the US National Labor Relations Board (NLRB) concluded that Tesla violated federal labor law in its efforts to discourage workers from unionizing. It directed the company to cease various anti-union actions and policies like claiming workers would lose benefits if they vote for union representation. The NLRB found that Tesla violated labor law by coercively interrogating employees, threatening them with the loss of stock options if they supported unionization, and enacting unlawful policies like a confidentiality agreement that banned speaking to the press. Continue reading Clothes retailer Fatface: Someone's broken in and accessed your personal data, including partial card payment details... Don't tell anyone 'Strictly private and confidential'? SERIOUSLY? Jude Karabus Wed 24 Mar 2021 // 13:02 UTC British clothes retailer Fatface has infuriated some customers by telling them "an unauthorised third party" gained access to systems holding their data earlier this year, and then asking them to keep news of the blunder to themselves. Several people wrote into The Register to let us know about the personal data leak, with reader Terry saying: "You will notice the Fatface email is marked as confidential. This annoyed me." Chief exec Liz Evans wrote in an email titled "Strictly private and confidential - Notice of security incident" sent to users yesterday: Continue reading Chairman, CEO of Nominet ousted as member rebellion drives .uk registry back to non-commercial roots Senior management also booted off board in extraordinary vote Kieren McCarthy in San Francisco Mon 22 Mar 2021 // 22:33 UTC Special report The CEO and chairman of Nominet have been ousted by the .uk internet registry operator's membership. Three other members were also removed from the not-for-profit's board in a clear rejection of their efforts to push the company in a more commercial direction. At an extraordinary general meeting (EGM) on Monday, a single resolution to remove five of the 11-strong board passed narrowly [PDF ] with 52.7 per cent of the vote on a turnout of 53 per cent of members. Those five "have left the board with immediate effect," Nominet said in a statement. And they are: chairman Mark Wood, CEO Russell Haworth, registry managing director Eleanor Bradley, CFO Ben Hill, and non-exec director Jane Tozer. Bradley and Hill will remain in their day jobs at Nominet for now. Continue reading What could be worse than killing a golden goose? Killing someone else's golden goose When fixing legacy bugs turns out to be a career-limiting move Richard Speed Mon 22 Mar 2021 // 08:15 UTC Who, Me? The weekend is no more so start your working week with a Who, Me? tale about the hazards of simply trying to do the right thing. Our story comes from "Anne" and takes place many years ago in what she described as "a rather large bank," the identity of which will remain anonymous to spare the blushes and the need for legal instruction. She'd been working as a programmer for nine months at the august financial institution when an email turned up from a senior vice president. Addressed to a team member, but cc'ed to the entire team, it was effusive in its gratitude and praise. The recipient had "saved the bank," according to the email, "by fixing a problem and allowing the bank to post to accounts." Continue reading OVH writes off another data centre - SBG1 - and reveals new smoking battery incident Customers concerned over 2017 posts describing power outage, confession to sub-par design Simon Sharwood, APAC Editor Mon 22 Mar 2021 // 00:57 UTC OVH has written off a second data centre because of the March 10th fire that destroyed its SBG2 facility. In a Saturday update, OVH founder and CTO Octave Klaba wrote: "We don't plan to restart SBG1. Ever." Previous guidance on SBG1 suggested only a few racks were destroyed, while others were considered recoverable. The fire has already destroyed the SBG2 data centre. Klaba's announcement followed news of a second fire on the site. Continue reading Thousands of taxpayers' personal details potentially exposed online through councils' debt-chasing texts Got a link? Change the last character and bingo, it's blackmail time Gareth Corfield Tue 23 Mar 2021 // 11:08 UTC Exclusive Bulk SMS messages sent by local councils across the UK contained weblinks leading to pages that freely exposed to the public thousands of taxpayers' names, addresses, and outstanding debts, The Register can reveal. Text messages sent by Telsolutions Ltd on behalf of a dozen local authorities contained shortlinks to webpages urging council tax defaulters to pay up - and in a dozen cases seen by The Register there was little or no authentication protecting personal data from prying eyes. Sent in bulk by around a dozen councils, the messages have reached thousands of defaulters and late payers, although the loophole allowing the data leak has since been closed. Government statistics [PDF, 16 pages, table 2] show that in England around 3 per cent of council taxes by value were not collected during financial year 2019/20. Continue reading 'Agile' F-35 fighter software dev techniques failed to speed up supersonic jet deliveries Watchdog bites Uncle Sam and Lockheed Martin over $14bn-and-counting efforts Gareth Corfield Thu 25 Mar 2021 // 17:17 UTC Agile methodology has not succeeded in speeding up deliveries of onboard software for the F-35 fighter jet, a US government watchdog has warned in a new report. The US Government Accountability Office (GAO) said in its annual report into F-35 design and development that software development practices within the F-35 Joint Project Office (JPO) and jet manufacturer Lockheed Martin were below par - and had hindered the supersonic stealth fighter's progress. "The program's primary reliance on the contractor's monthly reports, often based on older data, has hindered program officials' timely decision making," said the GAO. "The program office has also not set software quality performance targets, inconsistent with another key practice. Without these targets, the program office is less able to assess whether the contractor has met acceptable quality performance levels." Continue reading [devops] ABOUT US[f] * Who we are * Under the hood * Contact us * Advertise with us MORE CONTENT[f] * Latest News * Popular Stories * Forums * Whitepapers * Webinars SITUATION PUBLISHING[f] * The Next Platform * DevClass * Blocks and Files * Continuous Lifecycle London * M-cubed Situation Publishing The Register - Independent news and views for the tech community. Part of Situation Publishing SIGN UP TO OUR DAILY NEWSLETTER Subscribe Twitter Facebook LinkedIn feeds no-js Biting the hand that feeds IT (c) 1998-2021 Do not sell my personal information Cookies Privacy Ts&Cs