Live data from Hacker News

A board member's perspective of the RubyGems controversy

apiguy.substack.com

1–10 of 175 posts

Re: A board member's perspective of the RubyGems controversy

#2
Very reasonable other side to this story, which doesn’t come as much of a surprise. Too bad it didn’t hit the front page.

People went WAY too far WAY too fast on this. There HAS to be urgency to this, the software supply chain is presently, undeniably, under attack.

Frankly, everyone blasting RubyCentral the last few days should feel shame and embarrassment. These aren’t evil suits at Microsoft, they’re normal people invested in maintaining a critical piece of infrastructure for the good of all who love and profit from Ruby.

Re: A board member's perspective of the RubyGems controversy

#3
So Ruby Central, by their own admission, agreed to take $$$$$ of funding on the premise that they would "secure RubyGems against supply chain attacks", and then sat on their hands not doing anything about it until a few days before the deadline, when it was too late to seek community consensus or figure out a good transition plan. So they ended up screwing over everybody who was actually doing work on the project in favor of their own funding. And also they apparently used this as an opportunity to consolidate their power in other ways (renaming the github org) for reasons that were unrelated to the self-imposed deadline. How does this make them look better?

Re: A board member's perspective of the RubyGems controversy

#4

Very reasonable other side to this story, which doesn’t come as much of a surprise. Too bad it didn’t hit the front page. People went WAY too far WAY too fast on this. There HAS to be urgency to this, the software supply chain is presently, undeniably, under attack. Frankly, everyone blasting RubyCentral the last few days should feel shame and embarrassment. These aren’t evil suits at Microsoft, they’re normal people…

What? This article is absolutely damning re: RC's leadership and the utter lack of proper transparency, strategic planning, marketing/PR, and solid OSS governance. Did we read the same article?!

Re: A board member's perspective of the RubyGems controversy

#5
> [The Ruby Central board] is a small group of volunteers

is somewhat at odds with

> Some [...] companies specifically pay Ruby Central to ensure the security and stability of that part of the supply chain,

but not so much. Then the sentence goes on with

> but then discovered that people with no active affiliation or agreement in place had top level privileges to some of this critical infrastructure.

So something has been wrongly managed or wrongly sold.

Then the final part about the emotional conversations and the dilemma sounds honest or at least very plausible, but as they write, the critical mistake already happened.

Re: A board member's perspective of the RubyGems controversy

#6
> I can't speak for the board or the Ruby Central staff. But I know them and they are like me. They do this because they love Ruby and our community. I'm certain of that.

I don't know how to reconcile 'they love Ruby and our community' with moves that are actively hostile to the community.

Re: A board member's perspective of the RubyGems controversy

#7
I think that if they had been up front and transparent, and cut the PR bullshit corpospeak from their damage-control post, this would have been something that's much less embarrassing for all involved.

Something like:

"Hey all, RC here: with the very real threat of supply-chain attacks looming around us, one of the critical financial backers of our nonprofit org gave us a deadline around tightening access to the Github Account for rubygems/bundler. We tried and failed to arrive at a consensus with the open-source volunteers and maintainers for the best path forward and were forced to make a decision between losing the funding and taking decisive (if ham-fisted) action to keep Ruby Central financially healthy. We think RC's continued work is important enough that we stand by our decision, upsetting though it might be, but want to work out a better one ASAP. We are genuinely sorry for any fear/disruption this has caused."

Something simple that just owns the fact that they screwed up and tried to handle it as best they could. Doing this proactively as soon as they made the changes and broadcasting it would have been even better, but even posting this in reply to the controversy would have done more imo...

Re: A board member's perspective of the RubyGems controversy

#9
post #7

I think that if they had been up front and transparent, and cut the PR bullshit corpospeak from their damage-control post, this would have been something that's much less embarrassing for all involved. Something like: "Hey all, RC here: with the very real threat of supply-chain attacks looming around us, one of the critical financial backers of our nonprofit org gave us a deadline around tightening access to the Gith…

Sounds like you should volunteer for Ruby Central to help them with their communications! I don't mean that facetiously: it seems that they could use you, or someone like you, with comms. As the OP readily admits, this is not a strong point for them.

My general take on this:

1) Nerds are often not the best at communicating.

2) People on the Internet can be very cruel towards people they don't know.

We could all do better, especially with #2. The Internet used to be cool as hell. Now, by and large, it sucks.

Post reply on HN