Live data from Hacker News

Ruby Central's Attack on RubyGems [pdf]

pup-e.com

51–60 of 286 posts

Re: Ruby Central's Attack on RubyGems [pdf]

#51
post #13

The recent actions taken by Ruby Central - removing long-time RubyGems and Bundler maintainers without warning, seizing administrative access, and consolidating control under a small, centralized group - represent a serious breach of trust within the Ruby ecosystem. This was not a misunderstanding. It was a hostile takeover of key infrastructure, undermining both the long-standing maintainers and the broader communit…

Why did you include that list of sponsors at the bottom of your post?

What's with the "contingent on employment status or ideological alignment" bit about? That's not been mentioned anywhere else so far.

Were those parts (or indeed your entire comment) written with the help of an LLM?

Re: Ruby Central's Attack on RubyGems [pdf]

#52

An update from Ruby Central: Strengthening the Stewardship of RubyGems and Bundler https://rubycentral.org/news/strengthening-the-stewardship-o...

If they're trying to strengthen security, this feels like an odd way to go about it.

Making unplanned unexpected changes to GitHub ownership and removing people with lots of experience and institutional knowledge with little notice (based on the original story) and presumably no great hand-over, feels risky and not a great way to improve people's trust in their governance.

Re: Ruby Central's Attack on RubyGems [pdf]

#53
post #13

The recent actions taken by Ruby Central - removing long-time RubyGems and Bundler maintainers without warning, seizing administrative access, and consolidating control under a small, centralized group - represent a serious breach of trust within the Ruby ecosystem. This was not a misunderstanding. It was a hostile takeover of key infrastructure, undermining both the long-standing maintainers and the broader communit…

[flagged]

Re: Ruby Central's Attack on RubyGems [pdf]

#54

An update from Ruby Central: Strengthening the Stewardship of RubyGems and Bundler https://rubycentral.org/news/strengthening-the-stewardship-o...

So essentially they randomly cut off a bunch of long time maintainers for some vague legal and/or security reasons. If there was real reason to do that in a hurry, that's what we need to see, not a corporate PR message.

Re: Ruby Central's Attack on RubyGems [pdf]

#56

An update from Ruby Central: Strengthening the Stewardship of RubyGems and Bundler https://rubycentral.org/news/strengthening-the-stewardship-o...

> We want to express our deep gratitude to the many cohorts of maintainers who have contributed to Bundler and RubyGems over the past two decades. Ruby tooling would not be what it is today without their dedication and leadership. Their work laid much of the foundation we are building on today, and we are committed to carrying that legacy forward with the same spirit of *openness and collaboration*

- The bolded part doesn’t track with locking out the entire team without notice or explanation.

- “Thanks for the hard work, the adults will take it from here” rarely works out.

Re: Ruby Central's Attack on RubyGems [pdf]

#58
post #13

The recent actions taken by Ruby Central - removing long-time RubyGems and Bundler maintainers without warning, seizing administrative access, and consolidating control under a small, centralized group - represent a serious breach of trust within the Ruby ecosystem. This was not a misunderstanding. It was a hostile takeover of key infrastructure, undermining both the long-standing maintainers and the broader communit…

[flagged]

  >- Immediately restore access to all maintainers removed during this incident. […]

  Markdown bullet points in a place with no markdown support.
Markdown quote markers in a place with no markdown support.

Re: Ruby Central's Attack on RubyGems [pdf]

#59

An update from Ruby Central: Strengthening the Stewardship of RubyGems and Bundler https://rubycentral.org/news/strengthening-the-stewardship-o...

I think the fear from Ruby Central might have been that, had they communicated openly, a maintainer/community member with admin access could do their own hostile take-over, and that that would expose Ruby Central to some legal liability, if not a complete loss of control.

I'm not in a position where I'd have to make a decision like this, and I don't have all the information, but I like to think that if I had made a decision like this, I'd show some more respect in the aftermath.

Something more akin to: "That was really awful, I'm sorry. We were suddenly faced with the severity of our legal exposure and had to immediately lock everything down. It's not a reflection of trust or anything, it was legally what had to be done. Now that we've taken stock and are now squared away, we have to make a more explicit controls framework, and we hope we can make it up to you, make this right, and have you lead as a maintainer again."

...Then again, maybe this wasn't about legal exposure. Or maybe it was and former contributors/maintainers are getting apologetic emails right now...

Re: Ruby Central's Attack on RubyGems [pdf]

#60

Earlier quoted context omitted.

Yes, they recently hired a new Executive Director.

Links: https://rubycentral.org/news/reflections-on-railsconf-2025-f... https://www.linkedin.com/in/shancureton

looking at that CV, I have zero doubt that this will be a subscription service in 5 years time
Post reply on HN