Live data from Hacker News

A board member's perspective of the RubyGems controversy

apiguy.substack.com

81–90 of 175 posts

Re: A board member's perspective of the RubyGems controversy

#81

Earlier quoted context omitted.

I mean imagine you are at work and you need to so this for SOC2 or something but dont tell your colleagues.

Firstly, you can tell them you’re working on SOC2 compliance, and secondly, those colleagues are getting paid in dollars, not doing it for the love of the work.

> Firstly, you can tell them you’re working on SOC2 compliance

Bingo

Re: A board member's perspective of the RubyGems controversy

#82

Earlier quoted context omitted.

Everything he quoted is a fact, which can be proven or falsified. Taken together (and if true) they're pretty damning. You responded with an ad-hominem attack. If you can offer a rebuttal of the facts then please do, otherwise try to refrain from personal attacks.

I dunno what you read, but nothing I wrote included any attacks, personal or otherwise.

It’s “felt slighted” that makes me wonder how often you get into arguments that escalate “for no reason.”

Having access revoked with no heads up is a slight. You’re goddamned right they feel slighted. They were slighted.

“Feel slighted” is like “I’m sorry you’re upset”. You put everything on the aggrieved party when you say it like that.

Re: A board member's perspective of the RubyGems controversy

#83
I think that most Rubyists want to forgive each other and move forward. The board, staff, and volunteers at Ruby Central are all people and people are fallible, that's fine. The way to receive forgiveness isn't to convince others (who weren't there and who don't have the full context) that what was done was reasonable or justified. It doesn't matter. It doesn't even matter who is at fault. What matters is who will take responsibility.

The actions taken by people in service of Ruby Central have had unintended consequences, including damaging the community's trust in Ruby Central's stewardship.

A new governance model will solve only the problem of there not being a governance model. There also has to be an acknowledgment that the lack of an existing appropriate governance model wasn't just a "fiduciary failure," but a failure which cased harm to the community and contributors. Contributors who—like the board—are volunteers, and would have probably liked to have their significant dedication shown more respect.

You show respect to someone by giving them important information from which they can use to make their own decisions. As opposed to withholding information because you are uncomfortable with the possibility that they may make a decision you don't want them to.

Re: A board member's perspective of the RubyGems controversy

#84
Honestly this description makes me even more concerned. There’s a lot of “I don’t know what happened” and “I wasn’t involved” and “apparently we agreed to”.

In particular, after a long winded introduction and setting of the scene, suddenly there’s a mention out of the blue of a 24 hour deadline to cut off access or face losing funding (forever)? But who was holding this deadline over the board’s head is not explained (in fact the author doesn’t seem to know???).

Overall this just reinforces the impression that the RC board handled this sloppily and in a rushed manner, and failed to communicate with long term community members, and thought of themselves as the only parties who mattered, while not taking responsibility for holding such an important position (see the opening paragraphs about how “we don’t have time to communicate to the public because we’re busy programmers without a PR team”).

Re: A board member's perspective of the RubyGems controversy

#85
Here's a little bit of nitpicking:

> I want to apologize, genuinely, to people who have felt (...) outrage (...) after reading some of what others have shared.

He's apologizing for what others have shared, not for what they (Ruby Central) did.

> I often go out of my way to avoid making people feel bad

"I'm the good guy."

> and so to be part of what's caused so much chaos lately has really been awful.

"_I_ feel awful."

"I'm sorry for what others have said about what we _did_. I feel awful for people being outraged" Amazing.

> this is a small group of volunteers spread out all over the globe. (...) It's just us.

You didn't, for a single moment, think about notifying the people involved that you are removing them? It's the very first thing to do - notify someone who's involved of the change in their status. If your communication skills didn't reach a level in which you thought that would be the thing to do, I don't know what to tell you.

> It is really boring stuff. So why do I do it?

So what? Should we feel sorry for you?

> I love the community. I love the people who use Ruby, (...) I love the people who give their time to Ruby and I love the people and companies who generously provide financial support for Ruby.

Cool.

> I can't speak for the board or the Ruby Central staff. But (...)

proceeds to speak for the board and the Ruby Central staff.

> Ruby Central has been responsible for RubyGems and Bundler for a long time.

This is a lie. RubyGems and Bundler have been maintained by a group of core maintainers. Some members of this group were also Ruby Central staff, but not all.

> It's not a new story that Ruby Central has been working on (or trying to at least) improve the governance model for Bundler and RubyGems.

It's a new story to me. If it's not a new story, do you mind sharing some links to past discussions?

> How do you tell someone that has had commit and admin access to critical infrastructure long after that need has expired that you need to revoke that access without upsetting them?

You learn some basic English. And then let them know. It's called communication.

> And what if other people who do still need that access claim things like "If you remove their access, I'll just add it back" or "If you remove their access, I'll quit".

It's called consensus. And communication. You talk. You speak with people. And then you agree on a decision.

> These are emotional conversations.

Yes, they are. Is that why we shouldn't have them? When you want to leave your wife, do you just leave? What a strong person with strong values.

> I wasn't a part of them and can't actually speak to the content of the conversations or how they were handled.

Bad. They were handled bad. Why did you write this post? You don't have information, you don't know what happened...you just love people and community and companies. Happy happy joy joy.

> we don't have a "communications team"

You don't need a communications team. You just need to have a communication channel public or private, where you can reach all of the core members. It could be an email with everyone in CC.

> A deadline (which as far as I understand, we agreed to) loomed.

If you're not sure whether it was agreed on, again, communication. Learn how to communicate. Which deadline? Who set this deadline?

> With less than 24 hours to go

Did someone give you 24 hours deadline? Why wasn't this discussed long before the deadline?

> Marty, Ruby Central's Director of Open Source

How the f is Marty? If he wasn't one of RubyGems maintainers, why is he suddenly being put as the main maintainer? Aside from communication issues, you also have decision making issues. All of the core members should come to an agreement, without Marty.

> I love this community and I love Ruby.

Cool.

Please find some time to read a book or two on communication skills. As well as decision making.

Read the comments in this thread. Ignore mine, don't think too much about it. Just read other comments. Then think again about your decision and to which percentage people in this thread agree with it. And perhaps reevaluate it.

Re: A board member's perspective of the RubyGems controversy

#86
post #13

This story is missing any context around what occurred. The only thing I was able to find was by searching, and I came to this PDF statement. https://pup-e.com/goodbye-rubygems.pdf > On September 9th, with no warning or communication, a RubyGems maintainer unilaterally: > renamed the “RubyGems” GitHub enterprise to “Ruby Central”, > added non-maintainer Marty Haught of Ruby Central, and > removed every other maintain…

Everything you're quoting is from one aggrieved person, who clearly felt slighted, and who left out a whole lot of context in their own post. The article above is a lot more reasoned, less emotional, and seems completely reasonable to me. Ruby Central clearly has issues with both internal and external communication. And the above article isn't an official statement either; it's just one person, not involve in the dec…

Less emotional? It comes from someone who has no personal stake in the outcome, and was in the loop for the decision making. Versus someone who was personally slighted and was not properly communicated with about such a big change.

Re: A board member's perspective of the RubyGems controversy

#87

Earlier quoted context omitted.

Wow! When that one DHH blog went around the other day, I didn't actually pay attention to who the author was. All I saw was yet another bigoted rant and just skimmed it and rolled my eyes. (e: here it is to save people the effort: https://world.hey.com/dhh/as-i-remember-london-e7d38e64 ) I should not have skimmed it. From your link: > In the same post he praises Tommy Robinson (actual name Stephen Christopher Yaxley-…

... and this is the guy whose Linux "distro" Cloudflare has just announced funding for.

Not all _that_ surprising. From where I see things, pretty much every time you see "Cloudflare" and "free speech" in the same sentence, it always end up being about Cloudflare supporting free speech for nazis or white supremacists. DHH's racist and xenophobic views are totally on-brand for them.

Re: A board member's perspective of the RubyGems controversy

#88
post #48
post #13

This story is missing any context around what occurred. The only thing I was able to find was by searching, and I came to this PDF statement. https://pup-e.com/goodbye-rubygems.pdf > On September 9th, with no warning or communication, a RubyGems maintainer unilaterally: > renamed the “RubyGems” GitHub enterprise to “Ruby Central”, > added non-maintainer Marty Haught of Ruby Central, and > removed every other maintain…

How you can tell this is all lies from the board is simple: > How do you tell someone that has had commit and admin access to critical infrastructure long after that need has expired that you need to revoke that access without upsetting them? The first thing is they didn't tell them. The second bit is simple: "Hi [x], I'm sure you've seen the news about npm. Given supply chain attacks directed at them and the one rec…

99% agree, but it's a very sensitive topic and I'd take like an hour to pulish it.

Re: A board member's perspective of the RubyGems controversy

#89

Earlier quoted context omitted.

Everything he quoted is a fact, which can be proven or falsified. Taken together (and if true) they're pretty damning. You responded with an ad-hominem attack. If you can offer a rebuttal of the facts then please do, otherwise try to refrain from personal attacks.

I dunno what you read, but nothing I wrote included any attacks, personal or otherwise.

> Everything you're quoting is from one aggrieved person, who clearly felt slighted, and who left out a whole lot of context in their own post.

^ This was a personal attack.

Re: A board member's perspective of the RubyGems controversy

#90
post #40

Locking out a guy like David Rodriguez (the main person I see doing bundler commits) in a dramatic fashion just seems like absolute craziness. I can't fathom doing it without a very good reason, which has yet to be revealed if it exists.

Does “lest we lose critical funding because we don’t have proper agreements with our committers” not cut it as a reason for you? Genuinely curious, it seems like a reasonable explanation assuming it’s true.

What's the point of a foundation having funding if there's no ecosystem left to spend it on? And if a single source of funding is so critical that they can demand immediate wide-spreading changes to the ecosystem, is the foundation even independent at all, or just a corporate puppet pretending to be?

Who cares that you have funding for things like build servers and meetups when your core developers walk away and the project is left to rot?

Post reply on HN