Live data from Hacker News

Ruby core team takes ownership of RubyGems and Bundler

ruby-lang.org

371–380 of 407 posts

Re: Ruby core team takes ownership of RubyGems and Bundler

#371

Earlier quoted context omitted.

I'll repeat: When you twist protective measures against ongoing theft or shitty proposals that went nowhere into a nefarious conspiracy to justify the theft of critical Ruby infrastructure, it’s time to take a hard look in the mirror. What are you trying to achieve here, bringing up debunked insinuations over and over and over again? And haha no, going over every cherry-picked fact and half-truth you explicitly state…

Which of these insinuations have been "debunked"? Did they happen or not? If they happened, but you're OK with the reason they happened, they weren't "debunked"; they were, to you , "mitigated".

Arko explained why he changed the password. Yes, he should have communicated the change, and that's on him. I still can't understand why RC preferred to publish a hit piece on him instead of... calling him to ask if he had changed the password? Bonkers.

Now, are you using that to justify the hostile takeover of critical infrastructure to the entire Ruby community? I'm baffled. RC did a *hostile takeover*. How many times do I have to repeat this?

Re: Ruby core team takes ownership of RubyGems and Bundler

#372

Earlier quoted context omitted.

Yes, and he already explained why he did it. Yes, he should have communicated it clearly. That's on him. At the same time, why didn't RC call him to ask? Was it easier to write about a security INCIDENT throwing shade at Arko? With that said, let's keep focused on the real issue: RC did a hostile takeover of the projects. That's not been properly disputed so far. Matz is, therefore, accepting to steward stolen projec…

It doesn't matter why you break into your former employer's server. That's the point. > Matz is, therefore, accepting to steward stolen projects. You know Arko didn't even start working on Rubygems until it was nearly 10 years old, right? One of the original authors is in here and on X saying he supports it being taken over by RubyCore. Which matters much more than whatever the maintainers who were locked out think.

With that interpretation Marty Haught attempted to incite a federal crime on Oct 3rd, where he tried to trick Arko into doing trial logins:

https://andre.arko.net/2025/10/09/the-rubygems-security-inci...

"Please confirm that you cannot access the Ruby Central AWS root account credentials, either through the console or by access keys."

Alternatively, we could see the whole issue for what it is: a power struggle between political factions of an open source project that is unprofessionally handled by at least one side.

Re: Ruby core team takes ownership of RubyGems and Bundler

#373

Earlier quoted context omitted.

Which of these insinuations have been "debunked"? Did they happen or not? If they happened, but you're OK with the reason they happened, they weren't "debunked"; they were, to you , "mitigated".

Arko explained why he changed the password. Yes, he should have communicated the change, and that's on him. I still can't understand why RC preferred to publish a hit piece on him instead of... calling him to ask if he had changed the password? Bonkers. Now, are you using that to justify the hostile takeover of critical infrastructure to the entire Ruby community? I'm baffled. RC did a *hostile takeover*. How many ti…

Here you are, saying out loud that RC would have needed to call Arko to ask if Arko had changed the password. There are one too many "if"'s in that sentence!

Re: Ruby core team takes ownership of RubyGems and Bundler

#374

Earlier quoted context omitted.

It doesn't matter why you break into your former employer's server. That's the point. > Matz is, therefore, accepting to steward stolen projects. You know Arko didn't even start working on Rubygems until it was nearly 10 years old, right? One of the original authors is in here and on X saying he supports it being taken over by RubyCore. Which matters much more than whatever the maintainers who were locked out think.

With that interpretation Marty Haught attempted to incite a federal crime on Oct 3rd, where he tried to trick Arko into doing trial logins: https://andre.arko.net/2025/10/09/the-rubygems-security-inci... "Please confirm that you cannot access the Ruby Central AWS root account credentials, either through the console or by access keys." Alternatively, we could see the whole issue for what it is: a power struggle betwee…

Incite? It was already done at this point. He was letting him dig his own grave...

Re: Ruby core team takes ownership of RubyGems and Bundler

#375

Earlier quoted context omitted.

It doesn't matter why you break into your former employer's server. That's the point. > Matz is, therefore, accepting to steward stolen projects. You know Arko didn't even start working on Rubygems until it was nearly 10 years old, right? One of the original authors is in here and on X saying he supports it being taken over by RubyCore. Which matters much more than whatever the maintainers who were locked out think.

> It doesn't matter why you break into your former employer's server. Arko already stated that he didn't know he had been fired. Geez. > You know Arko didn't even start working on Rubygems until it was nearly 10 years old, right? The project was stolen from a set of maintainers, not just Arko. Let's stick to the facts: someone with admin rights over the repos revoked the access of other admins without their consent.…

> have a lot of respect for Rich, but he wasn't a maintainer.

LMAO

No. He's one of the few people on the planet that could lay claim to it's copyright. He also gave the insight that Rubygems has literally ALWAYS been a part of RubyCentral.

Re: Ruby core team takes ownership of RubyGems and Bundler

#376

Earlier quoted context omitted.

No, it's not. I haven't weighed in on that at all in this thread. This thread is very specifically about Andre Arko's credibility and the credibility of projects that associate with him. Regardless of what Ruby Central did, his own actions warrant every bit of criticism he's getting. Stop trying to redirect the narrative. There are other threads where that discussion is happening. You can view Ruby Central as being i…

Arko explained why he changed the password; I agree that he should have communicated the change. Now, does that justify the hostile takeover of the projects? C'mon... folks, there was a hostile takeover of two projects. Will we, as a community, ignore that? I don't understand how Matz accepted this as-is. Taking over these projects without addressing the takeover makes them toxic assets that will taint the Ruby commu…

Look. I brought up Arko's credibility. I didn't bring up the Ruby Central folks credibility. That's a separate thread -- there's literally like 500 other threads to discuss that topic.

What you're doing is called a Whataboutism. I was responding to a comment about gem.coop.

Andre Arko is not credible and thus gem.coop is not credible. He can explain all he wants but his actions were plainly inexcusable. Whatever Ruby Central did is immaterial to the point of whether or not Andre Arko can be involved with services that we rely on.

Re: Ruby core team takes ownership of RubyGems and Bundler

#377

Earlier quoted context omitted.

The label is meaningless now because it's been so over used. At this point a facist is anyone to the right of anarcho-communism. People still trying to use the term are labeling themselves more than anybody else.

https://news.ycombinator.com/item?id=45622861

Case in point

https://x.com/awesomekling/status/1979601199927083373?s=46

Re: Ruby core team takes ownership of RubyGems and Bundler

#378

Earlier quoted context omitted.

Arko explained why he changed the password. Yes, he should have communicated the change, and that's on him. I still can't understand why RC preferred to publish a hit piece on him instead of... calling him to ask if he had changed the password? Bonkers. Now, are you using that to justify the hostile takeover of critical infrastructure to the entire Ruby community? I'm baffled. RC did a *hostile takeover*. How many ti…

Here you are, saying out loud that RC would have needed to call Arko to ask if Arko had changed the password. There are one too many "if"'s in that sentence!

I'm questioning why they didn't call him. Why?

And why are you ignoring that RC did a hostile takeover of the repos? Again, RC stole the repos. What do you think of that?

Re: Ruby core team takes ownership of RubyGems and Bundler

#379

Earlier quoted context omitted.

Here you are, saying out loud that RC would have needed to call Arko to ask if Arko had changed the password. There are one too many "if"'s in that sentence!

I'm questioning why they didn't call him. Why? And why are you ignoring that RC did a hostile takeover of the repos? Again, RC stole the repos. What do you think of that?

Why in the everloving cosmic fuck did he not tell them? In a great many circumstances what he did is a crime. Nobody's coming after him on this but if this was me I would paper the everloving fuck out of what I did so there wasn't even a possibility that the owner of the account had any uncertainty as to what happened.

I don't know what happened with "the repos", is why I haven't offered an opinion about it. I have a professional interest in stories about people gaining unauthorized access to accounts. I assure you, the law doesn't weigh one party's transgression against the other the way you suggest it should.

Re: Ruby core team takes ownership of RubyGems and Bundler

#380
post #362

Earlier quoted context omitted.

But would they still build with Ruby if they had to rewrite it today? It seems other commenters are saying they wouldn't. I wanted to see if it offered anything more than my python and Go preference.

Let me ask you a different question: Would they be where they are today if there weren't been built at that moment with Ruby? Both these questions are hard to answer without connecting the dots, looking backward. Github was started in 2007, Shopify in 2006, Gitlab in 2011, Whop in 2021 It takes a long time approximately for a company to get out of the medium zone and go really big. So the only answer for this is we d…

I don't know. Do programming languages really make that big of a difference, other than with developer unhappiness and talent scarcity when hiring?

I think how many quality devs you can hire with that language is really the only question that matters 90% of the time (ballparking), so long as the language is designed for that use case, like don't use assembly to write a production webapp.

I don't know many devs that code with Ruby, I know of more devs that code in rust and Go which are newer by at least a decade? so the question of what actual benefits it has is important.

For Go, it makes it hard to mess up error handling and easy to deploy your apps since it's all a static blob, but memory footprint and optimization can be challenging at times. For rust, it takes a long time to do things, so fast shipping timelines might not be a good fit. For Ruby, does it have anything that makes it more secure, faster to code with,resilient to failure, easier to scale,etc...? I don't think anyone answered that here.

What can it do _better_ that the other languages you listed can't or can't as well?

Post reply on HN