Live data from Hacker News

A board member's perspective of the RubyGems controversy

apiguy.substack.com

21–30 of 175 posts

Re: A board member's perspective of the RubyGems controversy

#21
The only reason why Ruby and other open source projects survive is because large companies can trust them to do the right thing. Given the critical nature of the supply chain attacks, what the board did was 100% right. Like he said, some people's egos got hurt but if no one can trust the maintainers, then Ruby has no future in the industry and it will die quickly.

This is basically like fixing technical debt. It's painful and it's political but sometimes you have to do the right thing for the community as opposed to trying to assuage individuals' egos.

Re: A board member's perspective of the RubyGems controversy

#22

The only reason why Ruby and other open source projects survive is because large companies can trust them to do the right thing. Given the critical nature of the supply chain attacks, what the board did was 100% right. Like he said, some people's egos got hurt but if no one can trust the maintainers, then Ruby has no future in the industry and it will die quickly. This is basically like fixing technical debt. It's pa…

I think you got things mixed up, open source projects survive because volunteers believe in them and want to contribute to them. Large companies rarely get involved, occasionally with some funding.

It sounds like they sold something to their donors they couldn't really guarantee – supply chain safety – and they decided to alienate their contributors to try to appease them.

Only time will tell if this was really damaging to the ruby community or just a temporary hurdle

Re: A board member's perspective of the RubyGems controversy

#24
post #13

This story is missing any context around what occurred. The only thing I was able to find was by searching, and I came to this PDF statement. https://pup-e.com/goodbye-rubygems.pdf > On September 9th, with no warning or communication, a RubyGems maintainer unilaterally: > renamed the “RubyGems” GitHub enterprise to “Ruby Central”, > added non-maintainer Marty Haught of Ruby Central, and > removed every other maintain…

Everything you're quoting is from one aggrieved person, who clearly felt slighted, and who left out a whole lot of context in their own post. The article above is a lot more reasoned, less emotional, and seems completely reasonable to me. Ruby Central clearly has issues with both internal and external communication. And the above article isn't an official statement either; it's just one person, not involve in the decision, offering another perspective.

Re: A board member's perspective of the RubyGems controversy

#25

It's such a weird thought process to have gone through, to write this. The sentiments expressed are basically: "I WANT to apologize ... that I feel awful." "How can you possibly talk to someone about changing access, when multiple people tell you no, you are wrong?! A coup is the only way!" "Because funding deadline, we executed a coup, which will keep everyone safe from hostile actors... Taking over accounts and acc…

> Ruby Central has been responsible for RubyGems and Bundler for a long time. This isn't a new development, and I'm honestly very confused about the confusion. That's the opposite claim from a coup. It's not fair for you to put those words in his mouth.

[flagged]

Re: A board member's perspective of the RubyGems controversy

#26

The only reason why Ruby and other open source projects survive is because large companies can trust them to do the right thing. Given the critical nature of the supply chain attacks, what the board did was 100% right. Like he said, some people's egos got hurt but if no one can trust the maintainers, then Ruby has no future in the industry and it will die quickly. This is basically like fixing technical debt. It's pa…

I think you got things mixed up, open source projects survive because volunteers believe in them and want to contribute to them. Large companies rarely get involved, occasionally with some funding. It sounds like they sold something to their donors they couldn't really guarantee – supply chain safety – and they decided to alienate their contributors to try to appease them. Only time will tell if this was really damag…

Look at the core maintainers of Rails for example. Many are paid by Shopify and Basecamp, so it’s much more commercial than your regular open source project.

Which isn’t a bad thing that people get to contribute on company time.

Re: A board member's perspective of the RubyGems controversy

#28

Earlier quoted context omitted.

> Ruby Central has been responsible for RubyGems and Bundler for a long time. This isn't a new development, and I'm honestly very confused about the confusion. That's the opposite claim from a coup. It's not fair for you to put those words in his mouth.

[flagged]

He is claiming that Ruby Central has the authority. True or not, that claim is not consistent with a coup. You seem to be catastrophizing and constructing misleading quotes, including inverting his words, not because his claim is not true but because of how he communicated it and the impact of it.

Re: A board member's perspective of the RubyGems controversy

#29
> A deadline (which as far as I understand, we agreed to) loomed. Either Ruby Central puts controls in place to ensure the safety and stability of the infrastructure we are responsible for, or lose the funding that we use to keep those things online and going.

This makes a lot of sense, and it puts the 'drastic' action in understandable light.

It also contrasts with the 'On September 9th, with no warning or communication, a RubyGems maintainer unilaterally...' from the Goodbye RubyGems letter. Perhaps that person did not have communications or insight?

Going forward I think we could judge the good faith, if it's uncertain, by if we do see people reinstated. Cutting off access (for urgency with a deadline) followed by reinstatement (because they contribute) would match this post. No doubt there will be hurt feelings on all sides, which is understandable, but I hope as humans everyone can get through it.

Re: A board member's perspective of the RubyGems controversy

#30
post #26

Earlier quoted context omitted.

I think you got things mixed up, open source projects survive because volunteers believe in them and want to contribute to them. Large companies rarely get involved, occasionally with some funding. It sounds like they sold something to their donors they couldn't really guarantee – supply chain safety – and they decided to alienate their contributors to try to appease them. Only time will tell if this was really damag…

Look at the core maintainers of Rails for example. Many are paid by Shopify and Basecamp, so it’s much more commercial than your regular open source project. Which isn’t a bad thing that people get to contribute on company time.

Again this is mixed causality. Rails did not take off because of commercial interests – besides dhh who was working on it on the side, all the initial committers were doing that for fun.

Eventually they brought rails in many commercial companies and these companies succeeded to the point they could pay people to maintain rails.

Post reply on HN