Live data from Hacker News

Ruby core team takes ownership of RubyGems and Bundler

ruby-lang.org

311–320 of 407 posts

Re: Ruby core team takes ownership of RubyGems and Bundler

#311

Earlier quoted context omitted.

Notice how this was taking over a GitHub repository from an entire team of maintainers, through deceit ; and now we are all a few weeks in and you have seemingly accepted the narrative that this is now one bad apple justifies every action taken before and since, with no questions answered, with a wave of inconsistencies (it's about the money/no, the treasurer is wrong it's not about the money!) , etc.

No, it's not. I haven't weighed in on that at all in this thread. This thread is very specifically about Andre Arko's credibility and the credibility of projects that associate with him. Regardless of what Ruby Central did, his own actions warrant every bit of criticism he's getting. Stop trying to redirect the narrative. There are other threads where that discussion is happening. You can view Ruby Central as being i…

Arko explained why he changed the password; I agree that he should have communicated the change. Now, does that justify the hostile takeover of the projects? C'mon... folks, there was a hostile takeover of two projects. Will we, as a community, ignore that?

I don't understand how Matz accepted this as-is. Taking over these projects without addressing the takeover makes them toxic assets that will taint the Ruby community for a long, long time.

Re: Ruby core team takes ownership of RubyGems and Bundler

#312

Earlier quoted context omitted.

that's the one thing I've heard them not address yet is the changing of the passwords.

Arko kind of did address it in his most recent blog post. He claims he was doing what was in Ruby Central's best interest. Unfortunately for him he basically admitted to a crime because it came after he was terminated. He tried appealing to community and whatnot but anyone who's ever worked for a corporation knows that once you're terminated, it doesn't matter if HR forgot to take away your credentials or not, you si…

He stated that he didn't know he had been terminated. RC admitted that no harm had been done. Yes, he should have communicated changing the password.

Re: Ruby core team takes ownership of RubyGems and Bundler

#313

Earlier quoted context omitted.

I can't comment on any authenticity. Others here apparently dispute Andre's version, who clearly says he was on call : "As this situation occurred, I was the primary on-call. My contractual, paid responsibility to Ruby Central was to defend the RubyGems.org service against potential threats."

I'm referring to the email containing the monetization offer, not the later controversy regarding disputedly-authorized access to the AWS account.

He ran the idea by a group of people, nothing more. We can disagree with it — so did RC — but that was it: bouncing an idea.

Re: Ruby core team takes ownership of RubyGems and Bundler

#314

Earlier quoted context omitted.

Arko kind of did address it in his most recent blog post. He claims he was doing what was in Ruby Central's best interest. Unfortunately for him he basically admitted to a crime because it came after he was terminated. He tried appealing to community and whatnot but anyone who's ever worked for a corporation knows that once you're terminated, it doesn't matter if HR forgot to take away your credentials or not, you si…

He stated that he didn't know he had been terminated. RC admitted that no harm had been done. Yes, he should have communicated changing the password.

He changed the AWS root password for the account.

Re: Ruby core team takes ownership of RubyGems and Bundler

#315

Earlier quoted context omitted.

Ruby Central is making legal threats to its critics, so I hope you can see why people don’t feel safe to come forward on the record. I can tell you that two people with direct knowledge of the situation told me that Shopify demanded that Ruby Central take full control of the RubyGems GitHub organisation and packages. You can believe that I am lying if you want. But I can’t directly cite my sources in this case.

I never said you were lying. I said the quote that person pulled from your article isn't true. IIRC your article came out before the one I linked came out.

I believe the quote pulled from my article is true. Freedom’s original article lines up with what other people told me. I know he’s tried to retract it, but I don’t trust him to be truthful in this matter. He has lied about other things like the takeover being necessary for security.

Re: Ruby core team takes ownership of RubyGems and Bundler

#316
post #144

Earlier quoted context omitted.

Your addition also misses an important part where the only reason he was able to do that was because the servers were forcibly taken from the previous owners for the ostensible purpose of security, but the new regime forgot to change the passwords as part of that. At this point, it's probable that any attempt to just list the pertinent events isn't going to end up being as neutral as one might hope because even the c…

Wait, you think the former maintainer breaking into Ruby Central's AWS account and changing its root password makes the former maintainers look better ?

That's the narrative from the new Ruby Central, which feels like a wild distortion of the actual situation.

You’re likely aware, though it’s worth mentioning, that the new owners ousted all existing maintainers without any explanation[1]. This follows a prior incident where access was revoked and later restored, with assurances that it was a mistake. This situation can only be viewed as a malicious attack, in which only the new owners had a full understanding of what transpired. Changing the password was a reasonable and appropriate response that any competent person in a similar position would've considered.

I’m shocked that we seem to be experiencing a Freenode 2.0 situation, but with some supporting the usurpers instead of the longstanding maintainers. It’s only been four years since the Freenode debacle, yet certain types of people seem to have grown bolder since then. A "win" for freedom of expression, huh?

[1]: https://pup-e.com/goodbye-rubygems.pdf

Re: Ruby core team takes ownership of RubyGems and Bundler

#317
Does this potentially mean that RHEL will include more gems in their supported repos? It would be nice to script in Ruby instead of having to do everything in Python. Ruby is maybe my favorite language simply because of how it flows from left to right and how functional idioms come so naturally. But adding a gem sourced from community would be a hassle for my organization.

Re: Ruby core team takes ownership of RubyGems and Bundler

#318

Earlier quoted context omitted.

Wait, you think the former maintainer breaking into Ruby Central's AWS account and changing its root password makes the former maintainers look better ?

That's the narrative from the new Ruby Central, which feels like a wild distortion of the actual situation. You’re likely aware, though it’s worth mentioning, that the new owners ousted all existing maintainers without any explanation[1]. This follows a prior incident where access was revoked and later restored, with assurances that it was a mistake. This situation can only be viewed as a malicious attack, in which o…

Did he or did he not log in to the AWS root account after losing his own credentials and change the root password? I don't need paragraphs of explication following that. Seems simple!

Re: Ruby core team takes ownership of RubyGems and Bundler

#319

Earlier quoted context omitted.

So this whole thing stems from a dislike of DHH? It also seems like rubygems.org could simply fork the rubygems code, perform whatever 'security and governance' changes they believed were needed in their fork, and run with that? Isn't that the open source way of handling disagreements in direction?

> So this whole thing stems from a dislike of DHH? Not really. Shopify threatened to pull funding for them which set the whole thing in motion

Which only had weight because Sidekiq pulled funding because Ruby Central wouldn't deplatform DHH.

Re: Ruby core team takes ownership of RubyGems and Bundler

#320

Earlier quoted context omitted.

DHH is at worst in the middle between left and right in the political spectrum. Keeping politics out of work place is like an extremely mild stance. For some reason, people label him as facist...

I don't think that's fair, I mostly thought that until I read his recent blog post[0] where he wished for fewer non-white people in London and praises a far-right fascist figure in England (Tommy Robinson, he was a member of the BNP[1] for while before he started the EDL which was more extreme). When you're advocating for ethno-nationalism and praising fascists, I don't think you can get mad at people thinking maybe…

I read it and I don't see it.

He praised one policy from Tommy Robinson. This doesn't mean he support every single action performed by Tommy Robinson for eternity.

He advocates for stricter immigration laws and is against mass immigration.

He then praises the stricter immigration laws in Denmark. Then, Denmark would be considered facist and ethno-nationalistic by your logic?

> I don't think you can get mad at people thinking maybe you're a little bit fascist, or can claim to be in the centre politically

I'm actually mad that the word fascist is losing its meaning.

Wanting a stricter immigration law is now fascist, and Denmark is basically considered fascist for all these years for having stricter immigration laws praised by DHH...

At worst, this view is centered.

Post reply on HN