Live data from Hacker News

Ruby Central's Attack on RubyGems [pdf]

pup-e.com

61–70 of 286 posts

Re: Ruby Central's Attack on RubyGems [pdf]

#61
post #51
post #13

The recent actions taken by Ruby Central - removing long-time RubyGems and Bundler maintainers without warning, seizing administrative access, and consolidating control under a small, centralized group - represent a serious breach of trust within the Ruby ecosystem. This was not a misunderstanding. It was a hostile takeover of key infrastructure, undermining both the long-standing maintainers and the broader communit…

Why did you include that list of sponsors at the bottom of your post? What's with the "contingent on employment status or ideological alignment" bit about? That's not been mentioned anywhere else so far. Were those parts (or indeed your entire comment) written with the help of an LLM?

The post is quite clear? They call on the sponsors to stop funding ruby central, and the employment status bit is a clear concern extending from ruby central’s supposed takeover.

Read the post more clearly before accusing someone of LLM usage. And even if it is, they are still valid points to be discussed, as opposed to trying to bury it with an LLM accusation.

Re: Ruby Central's Attack on RubyGems [pdf]

#63
post #13

The recent actions taken by Ruby Central - removing long-time RubyGems and Bundler maintainers without warning, seizing administrative access, and consolidating control under a small, centralized group - represent a serious breach of trust within the Ruby ecosystem. This was not a misunderstanding. It was a hostile takeover of key infrastructure, undermining both the long-standing maintainers and the broader communit…

[flagged]

I don't think posts like this: an off-topic reply to a post where the same off-topic topic has already been killed, will have the effect you want it to have.

Unless that effect is to make yourself more angry and to have your comments downvoted in order to feel more righteous and to justify your behavior... but otherwise this won't change anything.

Please do write a blog post about, and feel free to share it on HN.

Re: Ruby Central's Attack on RubyGems [pdf]

#64
post #34

Earlier quoted context omitted.

Someone with absolutely no technical background, a recipe for disaster.

Opposed to hiring someone with a technical background but no experience running a non-profit?

It's easier to learn to run a non-profit coming from a technical management background than it is for an MBA to learn to be an engineer.

Re: Ruby Central's Attack on RubyGems [pdf]

#66

An update from Ruby Central: Strengthening the Stewardship of RubyGems and Bundler https://rubycentral.org/news/strengthening-the-stewardship-o...

Aren’t supply chain attacks caused by package maintainer accounts being compromised? I suppose too many people with keys to the package repository itself is also liability, but those accounts being compromised just hasn’t been what is happening.

Re: Ruby Central's Attack on RubyGems [pdf]

#67

An update from Ruby Central: Strengthening the Stewardship of RubyGems and Bundler https://rubycentral.org/news/strengthening-the-stewardship-o...

I think the fear from Ruby Central might have been that, had they communicated openly, a maintainer/community member with admin access could do their own hostile take-over, and that that would expose Ruby Central to some legal liability, if not a complete loss of control. I'm not in a position where I'd have to make a decision like this, and I don't have all the information, but I like to think that if I had made a d…

1. You lock everyone out of the org for whichever valid but idiotic reason. 2. The instant you do, you send them all an email explaining the situation.

That’s how you do it in those cases. You don’t blindside them and then wait for them to react, restore their access back (which totally negated and nullified the “I wanted to preempt a takeover attempt” argument) and continue to skulk around instead of being open about it.

Re: Ruby Central's Attack on RubyGems [pdf]

#68

An update from Ruby Central: Strengthening the Stewardship of RubyGems and Bundler https://rubycentral.org/news/strengthening-the-stewardship-o...

It reads like lawyers and auditors took over RubyCentral.

* Get appointed as paid managers of a non-profit * Get advice from legal * Legal suggests removing long-term maintainers without liability contract the same way people get fired: immediately and instantly, and screw the consequences. "Open-source? Never heard of it. Protect your entity legally" * Instantly follow the advice of the lawyers to the letter.

Well done, well done.

Re: Ruby Central's Attack on RubyGems [pdf]

#69

Earlier quoted context omitted.

I think the fear from Ruby Central might have been that, had they communicated openly, a maintainer/community member with admin access could do their own hostile take-over, and that that would expose Ruby Central to some legal liability, if not a complete loss of control. I'm not in a position where I'd have to make a decision like this, and I don't have all the information, but I like to think that if I had made a d…

1. You lock everyone out of the org for whichever valid but idiotic reason. 2. The instant you do, you send them all an email explaining the situation. That’s how you do it in those cases. You don’t blindside them and then wait for them to react, restore their access back (which totally negated and nullified the “I wanted to preempt a takeover attempt” argument) and continue to skulk around instead of being open abou…

You're completely right. In a generous interpretation, having so little communication over such a long period is where this went wrong. In any case, having your highly-tenured team dissolve and feeling like things were "hostile," is an indicator that you'll need to do better. Then again, who knows what the goal actually was? Maybe this went perfectly to plan. Given there was nothing approaching an acknowledgement of regret or apology in the press release, maybe this went exactly to plan.

Re: Ruby Central's Attack on RubyGems [pdf]

#70
post #51
post #13

The recent actions taken by Ruby Central - removing long-time RubyGems and Bundler maintainers without warning, seizing administrative access, and consolidating control under a small, centralized group - represent a serious breach of trust within the Ruby ecosystem. This was not a misunderstanding. It was a hostile takeover of key infrastructure, undermining both the long-standing maintainers and the broader communit…

Why did you include that list of sponsors at the bottom of your post? What's with the "contingent on employment status or ideological alignment" bit about? That's not been mentioned anywhere else so far. Were those parts (or indeed your entire comment) written with the help of an LLM?

> Why did you include that list of sponsors at the bottom of your post?

Clearly, that was because this information directly supports readers following through on the call to action: “And if Ruby Central does not do this we must pressure sponsors to stop funding Ruby Central”. That’s obvious.

> What's with the "contingent on employment status or ideological alignment" bit about? That's not been mentioned anywhere else so far.

Yes, both the original pdf and the RubyCentral statement edplicitly refer to admin status being made contingent on being full-time employee of RubyCentral. If you just mean no one has explicitly brought upthe ideological angle, well, that’s a fairly easy concer to reach wrih something being contingent on employment at a particular nonprofit, so it would be weird to interogate like this even if you had clearly focussed on kn just that point.

Post reply on HN