Live data from Hacker News

Ruby Central's Attack on RubyGems [pdf]

pup-e.com

71–80 of 286 posts

Re: Ruby Central's Attack on RubyGems [pdf]

#71
post #51

Earlier quoted context omitted.

Why did you include that list of sponsors at the bottom of your post? What's with the "contingent on employment status or ideological alignment" bit about? That's not been mentioned anywhere else so far. Were those parts (or indeed your entire comment) written with the help of an LLM?

The post is quite clear? They call on the sponsors to stop funding ruby central, and the employment status bit is a clear concern extending from ruby central’s supposed takeover. Read the post more clearly before accusing someone of LLM usage. And even if it is, they are still valid points to be discussed, as opposed to trying to bury it with an LLM accusation.

I brought up LLM usage precisely because the two things I called out here are weird - the kind of details an LLM might add.

If that's what happened then it's bad because it leaves people who read the comment confused - hence my questions asking about those.

If the author confirms that those pieces I asked about serve an intentional purpose then I don't care if they used an LLM or not.

My problem isn't with using LLMs to help write comments - there are plenty of reasonable reasons for doing that (like English as a second language). My problem is letting an LLM invent content that doesn't accurately represent the situation or reflect the LLM user's own position.

(The author could also say "I didn't use an LLM", which notably they haven't done elsewhere on this thread yet.)

Re: Ruby Central's Attack on RubyGems [pdf]

#72

Looks like Homebrew are mediating in some capacity: https://bsky.app/profile/mikemcquaid.com/post/3lz6pkabzwk2o

Why is homebrew involved in this?

It's not. The lead maintainer of Homebrew (Mike McQuaid) is helping to mediate the conversation between the parties, per his own post.

Has nothing specifically to do with Homebrew.

Re: Ruby Central's Attack on RubyGems [pdf]

#73
post #51

Earlier quoted context omitted.

Why did you include that list of sponsors at the bottom of your post? What's with the "contingent on employment status or ideological alignment" bit about? That's not been mentioned anywhere else so far. Were those parts (or indeed your entire comment) written with the help of an LLM?

> Why did you include that list of sponsors at the bottom of your post? Clearly, that was because this information directly supports readers following through on the call to action: “And if Ruby Central does not do this we must pressure sponsors to stop funding Ruby Central”. That’s obvious. > What's with the "contingent on employment status or ideological alignment" bit about? That's not been mentioned anywhere else…

Where did the ideological alignment piece come from then?

Re: Ruby Central's Attack on RubyGems [pdf]

#74
Hasn't Ruby Central always 'owned' RubyGems.org, Bundler, and all related infra?

Removing existing maintainers from the project isn't good - and hopefully it's a temporary oversight as Ruby Central gets things set up in the new org. Either bad communication from Ruby Central - or they really did made a bad mistake here (maybe even with the best intentions, given recent NPM issues).

Edit: It seems like there's a lot more to the story here. Many volunteer RubyGems/Bundler maintainers have left because they disagree with decisions that Ruby Central (the nonprofit organization) has made and it seems like all of this is fallout related to that.

Re: Ruby Central's Attack on RubyGems [pdf]

#75

Earlier quoted context omitted.

I think the missing piece here is that almost every person publicly involved with RubyGems’ development has left the project in recent weeks. I don’t have any special insight here, but from an outsider’s perspective it seems as through Ruby Central is trying to turn a former “host” relationship into a “control” relationship.

I think you're right, but I suspect the root here is one of legal liability - if rubycentral is operating as a nonprofit that hosts _a recurring attack vector on other companies_, they'll have legal obligations to secure that service against those attacks. I assume they are continuously deploying out of that repository, and took the simplest route to controlling the attack vectors? I'm not sure how anyone familiar wi…

there is no contract to assign liability

and I doubt you could ever get negligence to stick, given you are downloading code from some website and running it, on your own accord, entirely unprompted

(but IANAL)

Re: Ruby Central's Attack on RubyGems [pdf]

#76

An update from Ruby Central: Strengthening the Stewardship of RubyGems and Bundler https://rubycentral.org/news/strengthening-the-stewardship-o...

> We thank the maintainers and respect their legacy.

After removing them without explanation, cutting them off projects they have maintained over a decade and ignoring them when they asked for restoration or dialogue. I feel sad for the maintainers. This is not how they deserve to be treated.

Re: Ruby Central's Attack on RubyGems [pdf]

#77

Earlier quoted context omitted.

I think the fear from Ruby Central might have been that, had they communicated openly, a maintainer/community member with admin access could do their own hostile take-over, and that that would expose Ruby Central to some legal liability, if not a complete loss of control. I'm not in a position where I'd have to make a decision like this, and I don't have all the information, but I like to think that if I had made a d…

1. You lock everyone out of the org for whichever valid but idiotic reason. 2. The instant you do, you send them all an email explaining the situation. That’s how you do it in those cases. You don’t blindside them and then wait for them to react, restore their access back (which totally negated and nullified the “I wanted to preempt a takeover attempt” argument) and continue to skulk around instead of being open abou…

Seconding this.

Ruby Central is not a large organization by headcount, but in terms of impact, it is massive. Any person up to the task of leading an organization like this must know that drastic, public action involving long-term contributors will necessarily require an explanation. Inevitably. They must also know that in an information vacuum, people will assume the worst.

This is not difficult to foresee.

I truly hope this is settled without too much collateral damage, and I hope that the people in leadership learn a lesson about communication.

Re: Ruby Central's Attack on RubyGems [pdf]

#78
post #6

Ruby Central's whole thing is they maintain, develop, and secure bundler and ruby gems. Marty was previously a lead at Ruby Central and recently came back to RC as their Open Source Lead. It sounds like there was a clusterfuck getting the repo switched over but I'm not seeing how this is an attack on Ruby gems. Am I missing something?

I think the missing piece here is that almost every person publicly involved with RubyGems’ development has left the project in recent weeks. I don’t have any special insight here, but from an outsider’s perspective it seems as through Ruby Central is trying to turn a former “host” relationship into a “control” relationship.

Who? Everyone I recognize is continuing to contribute. https://github.com/rubygems/rubygems/graphs/contributors?fro...

Re: Ruby Central's Attack on RubyGems [pdf]

#80
post #13

The recent actions taken by Ruby Central - removing long-time RubyGems and Bundler maintainers without warning, seizing administrative access, and consolidating control under a small, centralized group - represent a serious breach of trust within the Ruby ecosystem. This was not a misunderstanding. It was a hostile takeover of key infrastructure, undermining both the long-standing maintainers and the broader communit…

From https://rubycentral.org/news/strengthening-the-stewardship-o...

> "Their work laid much of the foundation we are building on today, and we are committed to carrying that legacy forward with the same spirit of openness and collaboration."

what do they mean by openness, it doesn't even say who wrote this

Post reply on HN