In the long run, having multiple sources like gem.coop is probably a safer and more robust solution. But for RubyGems specifically, the trust was fully lost, through several layers - maintainers, community members, sponsors, etc. There's still open questions that probably need to be resolved like the funding and data privacy stuff, but I think most folks in ruby land will be supportive of this.
Any summary of what exaclty unfolded please (if you don't mind)? Sorry haven't been following the Ruby news for sometime.
Ruby core team takes ownership of RubyGems and Bundler
211–220 of 407 posts
Re: Ruby core team takes ownership of RubyGems and Bundler
#212Is Ruby ecosystem doing well?
Re: Ruby core team takes ownership of RubyGems and Bundler
#213Was there ever a mirror of this dustup in the Linux distro community? I'm unaware of one ever happening, and I'm wondering whether it's because of mere fortune or because there's something about the APT / dpkg model that precludes this kind of messiness. Perhaps the Ruby community is suffering the curse of having lived with reliable Internet for so long they never had to solve the problem of building up automatic pac…
Ideologically-rooted dustups are popping off all across open source right now, it seems. Forks-included. I've even seen unironic claims of certain pieces of technology containing "Hitler particles". That shook me a bit because that's an old in-joke and was always intended to be a joke...
Re: Ruby core team takes ownership of RubyGems and Bundler
#214Earlier quoted context omitted.
This is about a different part of the controversy, and doesn't respond to the allegation of a monetization proposal.
Yes it does. He's refuting that in this part of the post: > When they finally did reply, they seem to have developed some sort of theory that I was interested in “access to PII”, which is entirely false. I have no interest in any PII, commercially or otherwise. As my private email published by Ruby Central demonstrates, my entire proposal was based solely on company-level information, with no information about indivi…
Re: Ruby core team takes ownership of RubyGems and Bundler
#215Re: Ruby core team takes ownership of RubyGems and Bundler
#216Re: Ruby core team takes ownership of RubyGems and Bundler
#217Earlier quoted context omitted.
Ideologically-rooted dustups are popping off all across open source right now, it seems. Forks-included. I've even seen unironic claims of certain pieces of technology containing "Hitler particles". That shook me a bit because that's an old in-joke and was always intended to be a joke...
Who is the in-group for that in-joke?
Re: Ruby core team takes ownership of RubyGems and Bundler
#218In the long run, having multiple sources like gem.coop is probably a safer and more robust solution. But for RubyGems specifically, the trust was fully lost, through several layers - maintainers, community members, sponsors, etc. There's still open questions that probably need to be resolved like the funding and data privacy stuff, but I think most folks in ruby land will be supportive of this.
Any summary of what exaclty unfolded please (if you don't mind)? Sorry haven't been following the Ruby news for sometime.
Re: Ruby core team takes ownership of RubyGems and Bundler
#219Earlier quoted context omitted.
If only the drama stopped there: * DHH is not only considered racist / fascist due to some blog posts, but also for making Hyprland the default DE in Omarchy, developed by someone who goes by the name Vaxry Vaxerski, who is also considered fascist and racist, and thus banned from contributing to freedesktop projects due to supposed breach of CoC: https://blog.vaxry.net/articles/2024-fdo-and-redhat * Hyprland and all…
> I want to hop in a time machine back to the 90s/early 00s before all this crap started and everybody was just generally nice to each other. The internet was never nice. It, however, did at one time require technical savvy to use. With that savvy came the understanding that computers and people aren't the same thing, so when the computer emitted something not nice you'd laughed at how quant the technology was instea…
We tried "Don't feed the trolls." It's how we got where we are now.
Re: Ruby core team takes ownership of RubyGems and Bundler
#220Earlier quoted context omitted.
Even if you're not an old-timer and don't remember what Ruby Together was like, the AWS root password changing shenanigans, presumably done by Arko, is enough of a red flag that nothing he's associated with has any credibility. No serious business with real (business) customers will accept that kind of risk and gem.coop will never be a thing outside of hobbyists.
Read his account of it ( https://andre.arko.net/2025/10/09/the-rubygems-security-inci... ) and you might change your mind (again).
He logged in and changed the password after the board emailed him and told him his services were terminated. That includes/specifically mentions his on-call services. His response claims only silence from the board and that he was just performing his on-call duties.
I've been a corporate stooge for 25 years or so now. On call duties are one of my main responsibilities. I would NEVER probe out which logins I still have access to after receiving notice of termination. He admits to doing this in multiple places.
All his justifications are that he was under contract to do work that he was already notified was terminated. Everything that follows either tells me that he has bad judgment, that he's lying (by omissions), or in the worst case totally delusional.
If he was so worried about operational takeover, why did he _change a password_ without notifying anyone else with operational capabilities that he was doing so? Nobody reasonable would _ever_ do that. There's a certain amount of upfront communication and CYA required of reasonable actors in this space and he doesn't have it (Not that Ruby Central did any better).
So no, I won't be changing my mind, and I don't know why you put "(again)" in there.