Live data from Hacker News

Ruby core team takes ownership of RubyGems and Bundler

ruby-lang.org

241–250 of 407 posts

Re: Ruby core team takes ownership of RubyGems and Bundler

#241
Does that mean RubyCentral or anyone associated with them no longer have admin access to RubyGems GitHub organization? Watching the debacle unfold made me much less trusting of their "stewardship".

It's good to hear Ruby core team took the ownership. Thank you Matz.

Re: Ruby core team takes ownership of RubyGems and Bundler

#242

Matz' action and tone in the announcement is impeccable. Humbling reminder of what greatness looks like.

By not addressing HOW the project ended up in RC's hands, Matz is effectively whitewashing the move.

Right?

Why is there (seemingly) no public offer to former maintainers to rejoin, or acknowledgement of wrongdoing having been done as part of this? It's practically zero cost to do that; as the Ruby core team is (largely) not the party that inflicted harm.

Politeness? Conspiracy to have done this all along? Cultural differences around public vs private opinions? Something else?

What would we think if this wasn't a software project but a hijacked community bus, being passed from party to party, pretending nothing is untoward about the whole situation while the passengers are still aboard? "Oh good, the new bus drivers are politely accepting the keys from the hijackers; all is well!"?

Edit: https://www.reddit.com/r/ruby/comments/1o8zz3e/comment/njywb... No discussion with maintainers

Re: Ruby core team takes ownership of RubyGems and Bundler

#243
post #144

Earlier quoted context omitted.

Your addition also misses an important part where the only reason he was able to do that was because the servers were forcibly taken from the previous owners for the ostensible purpose of security, but the new regime forgot to change the passwords as part of that. At this point, it's probable that any attempt to just list the pertinent events isn't going to end up being as neutral as one might hope because even the c…

Wait, you think the former maintainer breaking into Ruby Central's AWS account and changing its root password makes the former maintainers look better ?

that's the one thing I've heard them not address yet is the changing of the passwords.

Re: Ruby core team takes ownership of RubyGems and Bundler

#244

Earlier quoted context omitted.

I more or less agree with the "no politics at work" stance but you've omitted his recent "contributions", where he went completely off the rails have a read of this https://world.hey.com/dhh/as-i-remember-london-e7d38e64 it's completely unacceptable, and he's promoting a self proclaimed fascist white nationalist (Tommy Robinson)

(political opinion incoming) Other than his mention of Tommy Robinson, it is not radical or unacceptable to say "Wow, my city has changed radically in the past 20 years and is losing its identity". If the center and the left completely reject the validity of national identity and the expectation of immigrant integration to British identity, then you leave people with those sentiments running into the only open arms l…

> Other than his mention of Tommy Robinson, it is not radical or unacceptable to say "Wow, my city has changed radically in the past 20 years and is losing its identity".

what does DHH, a Dane, who as far as I'm aware has never lived in London (and certainly doesn't now), know about London/the UK?

absolutely fuck all

he should keep his trap shut, in the same way Elon Musk should stop attempting to stoke nationalist fires in a foreign nation

I am also a (British, not American) liberal, and I agree with your comments about integration

the UK has an integration problem that successive political leaders have attempted to brush under the carpet, whilst ignoring the electorate's desire for a reduced rate of immigration

but the sort of nativist crassness displayed in that blog post is not the answer

and leads down a very nasty road that we thought we had defeated forever 60 years ago

> And the UK really seems to have a free speech problem. Support Palestine too much? Jail. Support immigration controls too much? Believe or not, jail.

I'm afraid this type of authoritarianism always seems to come with a labour government

Re: Ruby core team takes ownership of RubyGems and Bundler

#245

Earlier quoted context omitted.

I think it's pretty obvious to see the difference between being nice and jumping off a bridge? Curious why this cute phrase bothers you so much.

The phrase has been weaponized in the past many times. Some figures in the community are almost as far from "nice" as possible, but you're not allowed to call that out, because "it's not nice".

> but you're not allowed to call that out, because "it's not nice".

I don't know about the Ruby community, but I've seen this sort of complaint made about many other online spaces (including HN) and my general finding is that it simply isn't true. The problem is that for a proper call-out, both form and content matter, and most people in a mindset to make call-outs don't seem very interested in norms surrounding either of those things. Especially the part where part of good form is accepting that not all kind, well-meaning people have the same moral values and calculus.

Re: Ruby core team takes ownership of RubyGems and Bundler

#246
post #130

Earlier quoted context omitted.

Read his account of it ( https://andre.arko.net/2025/10/09/the-rubygems-security-inci... ) and you might change your mind (again).

No, it won't because I can read the timelines and see what he's omitting. He logged in and changed the password after the board emailed him and told him his services were terminated. That includes/specifically mentions his on-call services. His response claims only silence from the board and that he was just performing his on-call duties. I've been a corporate stooge for 25 years or so now. On call duties are one of…

Notice how this was taking over a GitHub repository from an entire team of maintainers, through deceit; and now we are all a few weeks in and you have seemingly accepted the narrative that this is now one bad apple justifies every action taken before and since, with no questions answered, with a wave of inconsistencies (it's about the money/no, the treasurer is wrong it's not about the money!), etc.

Re: Ruby core team takes ownership of RubyGems and Bundler

#247

Earlier quoted context omitted.

They keep on using buzzwords. These Ruby central guys never maintained a single gem used by many people in their life. I have no idea what they are writing, but it feels as if AI is writing their statements. Even then it is of such a poor, repetitive quality that even AI may just accidentally write better "summaries". People lost all trust in Ruby Central - there is no way for them to win back trust here. IMO it woul…

Afaik many of the people who were on board to help start gem.coop have stepped back after the recent controversies with Andre Arko, at this point I don’t think it will ever be anything more than a ruby gems mirror

I sincerely doubt this without a source

Re: Ruby core team takes ownership of RubyGems and Bundler

#249
post #11

In the long run, having multiple sources like gem.coop is probably a safer and more robust solution. But for RubyGems specifically, the trust was fully lost, through several layers - maintainers, community members, sponsors, etc. There's still open questions that probably need to be resolved like the funding and data privacy stuff, but I think most folks in ruby land will be supportive of this.

I can't believe that long gone maintainers still had root access, or any access at all to the core platform. Its has been wild to see ruby community members getting upset with modern and established security norms, for a platform that runs a lot of the web. Its not 2006 anymore, and we aren't just running random curl commands off the net to get rails installed. Scary to think how naive the backlash has been. Having an unmaintained security posture that is inherently insecure, just blows my mind. That supply chain was wide open to attacks, may still be, but at least someone tried to bring security up to this decade.

Re: Ruby core team takes ownership of RubyGems and Bundler

#250

Earlier quoted context omitted.

If only the drama stopped there: * DHH is not only considered racist / fascist due to some blog posts, but also for making Hyprland the default DE in Omarchy, developed by someone who goes by the name Vaxry Vaxerski, who is also considered fascist and racist, and thus banned from contributing to freedesktop projects due to supposed breach of CoC: https://blog.vaxry.net/articles/2024-fdo-and-redhat * Hyprland and all…

> Hyprland and all its contributors are now also considered fascist from taking sponsorship money from 37signals This methodology is definitely not how you discover fascism. But it is how fascists and communists defined and traced their enemies in the 20th century.

This.

While I am all for making conscious choices on what to support I can't take anything phrased like that seriously "all is contributors".

Hyprland, while inferior (imo) in some aspects to sway on the wayland tiling manager landscape is a fine piece of software that I use on my non-work computer (I still use sway for stability).

Back on the topic: I reiterate I'd be happy to avoid using or supporting projects based on non-purely technical issues (discussion on "pure technicality" omitted for brevity).

It's just... What, do I need to know every persons imo completely irrelevant opinions on whatever du jour hot political topic? Maybe the answer could be yes,

I would be fine with dropping Hyprland support, maybe I will after digging a bit more. But this whole thing just reeks to me of terminally informed and ragebaited people looking for a platform to vomit their completely irrelevant opinions, actions speak more (e.g. fostering a dangerous environment _adjacent to the project_ based on discrimination).

I just feel I want to nope out of this industry and everything related to it, it's very overwhelming.

Post reply on HN