Skip to content
Artwork for The Ruby AI Podcast
The Ruby AI Podcast · Tuesday · 35 min

Omarchy, Astra Hype, and AI Security Risks

Send us Fan Mail The Ruby AI Podcast is going live weekly. Joe Leo and Valentino Stoll put themselves on the clock to work through what’s happening across Ruby, AI, security, and open source, with very little time to prepare and plenty of room to disagree. DHH’s Omarchy has a root escalation bug. OpenAI says Astra can find and exploit real zero-days. Claude Code can recognize that it’s been compromised, but its own safety system may stop it from cleaning up. Joe and Valentino talk about what these stories actually mean once you get past the announcements, including how Valentino sandboxes his agents and why Joe isn’t ready to trust an AI company grading its own security model. Rails has security problems of its own, with a critical Active Storage vulnerability forcing three emergency releases. That raises another question: when a fix is this important and the tests pass, should we just ship it? Then there’s open source. Vercel is putting agents to work on its backlog, other projects are closing the door on outside PRs, and AI can now generate code much faster than maintainers can review it. AI makes it cheap to write the pull request. It doesn’t make it cheap to be responsible for merging it. Plus: why ChatGPT is hauling around a copy of LibreOffice, whether Ractors delivering close to 7× memory savings deserves another look, and the gong that now decides when Joe and Valentino have talked long enough.

0:00-35:50

transcript

No transcript — this publisher did not publish one.

show notes

Send us Fan Mail

The Ruby AI Podcast is going live weekly. Joe Leo and Valentino Stoll put themselves on the clock to work through what’s happening across Ruby, AI, security, and open source, with very little time to prepare and plenty of room to disagree.

DHH’s Omarchy has a root escalation bug. OpenAI says Astra can find and exploit real zero-days. Claude Code can recognize that it’s been compromised, but its own safety system may stop it from cleaning up. Joe and Valentino talk about what these stories actually mean once you get past the announcements, including how Valentino sandboxes his agents and why Joe isn’t ready to trust an AI company grading its own security model.

Rails has security problems of its own, with a critical Active Storage vulnerability forcing three emergency releases. That raises another question: when a fix is this important and the tests pass, should we just ship it?
Then there’s open source. Vercel is putting agents to work on its backlog, other projects are closing the door on outside PRs, and AI can now generate code much faster than maintainers can review it.

AI makes it cheap to write the pull request. It doesn’t make it cheap to be responsible for merging it.

Plus: why ChatGPT is hauling around a copy of LibreOffice, whether Ractors delivering close to 7× memory savings deserves another look, and the gong that now decides when Joe and Valentino have talked long enough.

links1