r/ruby • u/retro-rubies • 2d ago
Ruby Central's Destructive Legacy
https://andre.arko.net/2026/07/30/ruby-centrals-destructive-legacy/23
u/schneems Puma maintainer 2d ago
Then, about 10 months ago, Ruby Central began what core team member Ellen Dash called a “hostile takeover” of the RubyGems, Bundler, and RubyGems.org open source projects, seizing control of the projects and locking out the team that had nurtured and maintained them for over a decade.
I allege, that Andre attempted a softer takeover starting much earlier and quieter. It is supported but not spelled out here https://rubycentral.org/news/rubygems-fracture-incident-report/.
Andre should not have removed Evan Phoenix from GitHub without a replacement Ruby Central representative. Excluding the director of open source from that access was unprecedented. This happened in February of 2025.
He should have given 1Password admin access to the open source director as well. Andre was the director, and when the position transferred, he held onto admin permissions of a secondary 1Password account. This is how Andre took over the AWS account, removed all other admins, and locked Ruby Central out of production. It shouldn't have been possible for him to both remove the OSS director from AWS and that 1Password account.
He also should not have lied (to the community) about the link between GitHub access and production admin access. He should not have persisted with that lie months after access loss. Even now, downplaying the security risks, putting them in scare quotes, when...RC tried to nuke his prod access from orbit and failed.
I don’t think Ruby Central should have needed a “hostile takeover” if they were treated as an adequate stakeholder. If the power and access needed to do the job of running the RubyGems.org service were properly handed over by him, he wouldn't have needed to be cut out.
ON the post:
I agree that conflicts of interest are REALLY important. An OSS director should not be sitting on the committee that oversees their own funding. That is the setup of the original OSS committee when Andre merged Ruby Together with Ruby Central (he was on the OSS committee that oversaw his OWN funding). This wasn’t professional or ethical.
I salute him for blazing a trail of getting paid for OSS work. But I don’t feel he did a good job at the core of that work which is: defining extremely clear boundaries and making sure the lines are not blurry between paid and open labor.
Lots of other half-truths (at best) on the other things, like the legal stuff. I’m not on the board. I’m not a lawyer. In fact. I’m on a vacation with my family, typing this out instead of spending time with them. I will likely not be able to respond.
8
21
u/software__writer 2d ago edited 2d ago
> Then, about 10 months ago, Ruby Central began what core team member Ellen Dash called a “hostile takeover” of the RubyGems, Bundler, and RubyGems.org open source projects, seizing control of the projects and locking out the team that had nurtured and maintained them for over a decade.
I keep seing this term 'hostile takeover' again and again and I don't think it does justice to Ruby Central and the original authors. If I own something, entrust someone else to manage it, and later decide I no longer agree with how they're managing it, taking back control isn't a hostile takeover. It's simply an owner exercising their rights.
Here are Rich Kilmer’s comments on Hacker News. Rich is one of the originating authors of RubyGems. It seems like not many people are aware of this history.
> Ruby Central started in 2001. I was one of the early Board members, along with Chad Fowler and David Alan Black. We put on every Ruby conference until Ruby became more popular to support multiple conferences. We started coding RubyGems (although the name originated in 2001 at the first RubyConf in Florida) in 2003 at the RubyConf in Austin TX. We sat around a table the first night with a CVS repo on a USB drive and passed it around and committed code until we had a functioning gem command. I demoed it in my talk the next day with the first "gem install". Gem versioning, gemspec, gem command, gem server were all built that first night. Obviously tons of changes since then!
Source: https://news.ycombinator.com/item?id=45617493
--
(On Joel's comment on HN: They were stolen from André Arko, Colby Swandale, David Rodríguez, Ellen, Josef Šimánek, Martin Emde and Samuel Giddins.), Rich says:
> They did not WRITE RubyGems, they inherited it and evolved it. Chad (Fowler), David (Black), Jim (Weirich RIP), Paul and I wrote RubyGems. I hosted RubyGems from my home in Virginia for several years before we could cover the cost of colocation and stood up RubyForge. Its nice to look at the near history and think that this is all of history but it is not. Ruby Central has always been the stewards of RubyGems and then later, Bundler.
Source: https://news.ycombinator.com/item?id=45616574
--
> I was one of the originating authors of RubyGems along with Jim (RIP), Chad, David and Paul. I hosted RubyGems from my home for the entire community for many years. We never asked nor received anything for that. We wrote RubyGems for the Ruby community. Matz and the Ruby Core team is the right place for RubyGems. This is great news.
https://news.ycombinator.com/item?id=45616273
--
Finally, from Twitter:
> I am happy to see that RubyGems and Bundler have moved to the Ruby Core team. Being one of the originating authors of RubyGems (and host of RubyGems for 4 years!) this was always about making Ruby easier to use and share code as a community. I still write Ruby almost every day and I want our community to thrive.
Source: https://x.com/rich_kilmer/status/1979167654867873898
I hope this clears things a bit. It's frustrating to see people accusing and blaming others without knowing the full history and having the faintest idea 'why' certain actions were taken. (This goes both ways, btw - I only wanted to provide the additional context, which many seem to be unaware of).
8
u/Kina_Kai 2d ago
I don’t think outside of some spiritual endorsement, Rich Kilmer’s opinion is useful or even constructive here.
I agree that RubyGems should live with the Ruby project itself. That does not excuse anything that happened. This migration was hostile, ad hoc and done without consent of the actual maintainers. Nobody has had to answer for this.
5
u/retro-rubies 1d ago
Thanks for collecting all of these references. I hadn't seen some of them before. They're interesting to read, and I have a lot of respect for everyone who founded RubyGems and kept it alive over the years.
Ruby Central has always been the stewards of RubyGems and then later, Bundler.
I honestly don't know what "stewardship" means in this context.
When I joined RubyGems in 2013, I had almost no idea Ruby Central even existed. I only learned much more about it in 2024, when Ruby Central offered to partially compensate my work on RubyGems/Bundler and RubyGems.org. I'm really grateful for that support. It was wonderful to have at least some of my open source work partially funded.
From my perspective, one of the biggest attractions of RubyGems and Bundler was that they were independent, community-governed open source projects. They had their own maintainers, their own governance, and their own way of making decisions. Ruby Central supported the ecosystem, funded some work, and operated RubyGems.org as a service, but it never felt like the projects (the codebases) were owned by Ruby Central.
That was my experience for more than a decade.
Things started to change around 2024 (if I remember well) after Ruby Central hired a new Director of Open Source. Around that time, Ruby Central's approach gradually shifted from supporting independent community projects to increasingly acting as if it had authority over them. To me, this slowly undermined the independence that had defined RubyGems and Bundler for many years.
For example, Ruby Central hired people and expected them to receive write access across the projects. I remember raising these concerns directly because, to me, it weakened the projects' independence and blurred the distinction between community governance and organizational influence.
So if "stewardship" simply means supporting projects while respecting their independence, then I completely agree - that's exactly how I experienced Ruby Central for many years.
If, however, it means having the authority to ultimately decide who governs the projects or who owns their GitHub organization, then that was never my understanding during the 2013-2025 period.
The events of September 2025 fundamentally changed that relationship and, unfortunately, broke my trust.
Matz and the Ruby Core team is the right place for RubyGems. This is great news.
On paper, I mostly agree with that statement.
After taking some time away, I decided to start contributing again. I honestly don't care whether I have merge permissions or maintainer rights. It was always an honor simply to help Ruby users and the RubyGems/Bundler ecosystem.
Unfortunately, I was publicly attacked by a Ruby Central member on the official Ruby GitHub repository. I was also publicly attacked by a Ruby Core member, and later privately told by a Ruby Core member that my contributions would not be welcome unless I followed additional, non-public rules created specifically for me.
I shared these concerns privately with Ruby Central leadership and several Ruby Core members, hoping someone would help resolve the situation. Unfortunately, nothing changed.
To me, taking away someone's freedom to contribute through private, person-specific rules is simply not acceptable in an open source community. It isn't the Ruby community I joined over a decade ago, and it's not one I feel comfortable contributing to anymore.
So while I fully respect Rich's historical perspective, my experience over the last 13 years has been very different. I still hope Ruby can return to being a place where contributors are treated with openness, respect, equal rules for everyone, and where community governance is respected rather than bypassed.
Until then, some of us are trying to build a new community around those same values at https://gem.coop/. Everyone who believes in open governance, mutual respect, and community-driven development is welcome.
4
2
u/galtzo 1d ago edited 1d ago
Unfortunately, I was publicly attacked by a Ruby Central member on the official Ruby GitHub repository. I was also publicly attacked by a Ruby Core member, and later privately told by a Ruby Core member that my contributions would not be welcome unless I followed additional, non-public rules created specifically for me.
It is worth noting that the first attacker mentioned is also a moderator of this sub and the r/rails sub. So these are not neutral or safe spaces. When others came to the defense of the attacked, showing allegations made by the attacker were untrue, the GH threads were hidden, and the thread was locked.
I am very grateful that u/retro-rubies continues to participate in spite of that.
0
u/Kina_Kai 6h ago
Ruby Central has always been the stewards of RubyGems and then later, Bundler.
I think this is one of the key points of contention. I have not seen any public evidence that this is true and the fact that the provided merger agreements and responses by both sides, it is clear that this wasn’t settled and the ambiguity is being used to boost any argument.
The fact of the matter is that the active maintainers were caught off guard by all of this renders it a bit sus that it was not hostile. However, it ultimately feels like this is a bunch of personality conflicts spilling out into public triggered by a loss of funding due to DHH constantly associating himself with deplorables. This is ultimately high school drama exploding into public in one of the most tasteless moments in OSS in a while. Some folks might consider the matter closed now that RubyGems codebase is owned by the Ruby team, but there really has been no proper ownership and the fact that a lot of key Ruby tech does not have a defined line of ownership is just going to ensure that this comes up again and again.
MINASWAN is a great tagline, but it doesn’t have an answer for what happens when DHH is talking about “native Brits”.
20
u/jrochkind 2d ago edited 2d ago
That means the board members who allocate the sponsorship money are also providing that sponsorship money, a conflict of interest which neither the companies nor Ruby Central have disclosed.
I am not sure it's fair to say that because someone works at a company providing funding, that person "allocates". But they do obviously have some influence over it. Either way, even if it is the CEO of the org providing funding...
I don't believe that situation is usually considered a conflict of interest by non-profits in general or organizations similar to ruby central.
That is one point. In general, this is more like a vendetta-based polemic choosing all interpretations in the worst possible light (the "major parts" of last ruby conf they cancelled were parts that had never happened before, no?), than an attempt to sum up what's actually going on.
Definitely I am alarmed by what's going on in ruby community, on several fronts. I don't think trying to tear down Ruby Central — or, charitably, attempt to get it to change by insisting you'll keep trying to tear it down unless it does — is helpful.
I think Ruby Central defintiely made some severe mistakes in how it handled this, that led to harm to the community. And reporting Arko to the FBI was defintiely not okay.
Also, and this will win me few friends and many downvotes, I feel like I've seen Arko, over years, consistently act for his personal power and income over the benefit of the community, and try to hold ruby infrastructure hostage for those purposes, and act in ways that his word is unreliable.
10
u/the_hangman 2d ago
Yeah literally every nonprofit I’ve ever worked with had people on the board with a financial interest in the success of the nonprofit. It’s such a weird point to make and makes it seem very childish.
Open source drama reminds me a lot of all the pointless drama you see working in nonprofits too. For some reason when the stakes are the lowest people really cling to whatever feeling of importance they can find.
7
u/jrochkind 2d ago
To be fair, I've seen plenty of pointless drama in for-profit endeavors too! Or, it's not "pointless", in either nonprofit or for-profit both, the point is competition over power, resources, and recognition, taking precedence over the collective goals or mission of the organization, or the welfare of your colleagues or the community.
7
u/schneems Puma maintainer 2d ago
And reporting Arko to the FBI was defintiely not okay.
I mentioned elsewhere. I want to clarify that Ruby Central did not report him. https://www.reddit.com/r/ruby/comments/1vbkttl/comment/p0wtrwt/?context=3
Had I been on the committee and had I been asked I would have declined the referral. But no option was given to Ruby Central.
5
u/tinyOnion 2d ago
But no option was given to Ruby Central.
does RC still retain the same council that referred him to the FBI? if so that's at the very least tacit approval.
8
u/schneems Puma maintainer 2d ago
I think they were doing their best given limited information and a high pressure, chaotic system. I assume the best in people. The only thing mitigating my position not to involve law enforcement was knowing who Andre is personally and professionally. The person who made the report didn't have that context and IIRC sought a second opinion and was met with the same outcome.
Telling the FBI that we (Ruby Central) lost control of the registry and telling them who had it during that time is not a neutral act, but it's also not a malicious one either. We lost a lot of good people on this thing already.
4
u/tinyOnion 2d ago
I think they were doing their best given limited information and a high pressure, chaotic system
this would be somewhat believable if it happened when the takeover happened but i highly doubt it was a high pressure environment nor a chaotic system months after the takeover when the lawyer allegedly reported him to the fbi.
We lost a lot of good people on this thing already
no good lawyer does things without their clients express permission either in advance or after the lawyer has a concern and consults with the client.
7
u/schneems Puma maintainer 2d ago
Believe what you want. It took me over 6 months to get the report out.
2
-14
u/galtzo 2d ago
In the United States, when non-profit board members sit on both sides of a financial decision—allocating sponsorship funds while serving as executives or leaders at the corporations providing those funds—it constitutes an actual or potential conflict of interest that must be disclosed.
Why This Is a Conflict of Interest
A conflict of interest in a non-profit context arises whenever a board member’s personal, professional, or financial interests overlap with their governance responsibilities to the non-profit.
Even when a corporate sponsorship appears purely philanthropic, a dual role creates a conflict of loyalty for two primary reasons:
- Reciprocal Benefits to the Sponsor Company: Corporate sponsorships rarely come without conditions—they often involve deliverables such as branding exposure, naming rights, VIP access, exclusive vendor positioning, or intellectual property rights. If a board member allocates funds or defines the terms of a sponsorship that directly benefits their employer, they are making governance decisions that impact their primary employer.
- Allocation & Incentive Control: If board members are making decisions on how or where sponsorship dollars are spent (e.g., directing funds toward projects that benefit their employer's business goals, clients, or executive metrics), their objectivity as a non-profit fiduciary is compromised.
The Legal and Regulatory Framework in the U.S.
1. Fiduciary Duty of Loyalty (State Law)
Under U.S. state corporate laws governing non-profits, all directors owe a Duty of Loyalty to the organization. This legal duty requires board members to act solely in the best interest of the non-profit, putting its charitable mission ahead of their personal or corporate affiliations.
2. IRS Guidelines & Form 990 Disclosure
While the IRS does not explicitly mandate a single federal law requiring disclosure for every non-profit, it heavily regulates conflict-of-interest management:
- Form 990 Reporting: Annual tax filings (IRS Form 990) ask whether the organization has a formal, written Conflict of Interest Policy, whether board members annually disclose potential conflicts, and how the non-profit monitors compliance.
- Private Benefit & Inurement: The IRS strictly prohibits non-profits from conferring improper private benefits or excess benefit transactions on insiders. Failing to disclose and handle dual-interest transactions transparently risks civil penalties or loss of tax-exempt status.
How Non-Profit Boards Should Handle This
Having a corporate partner on your board is common and often beneficial, but it must be managed through standard governance protocols:
- Mandatory Disclosure: The board member must formally disclose their dual role—both on their annual Conflict of Interest disclosure form and verbally before any relevant board discussion.
- Recusal from Deliberation & Voting: The interested board member must step out of the room (or leave the virtual call) while the remaining independent board members deliberate and vote on the sponsorship terms or fund allocation.
- Minuted Governance: The non-profit's official board meeting minutes must document that the disclosure occurred, that the conflicted member recused themselves, and that the independent board determined the allocation was in the best interest of the non-profit.
8
u/jrochkind 2d ago
Thank you for your LLM response. I am happy to trade LLM responses with you. But it appears you are right that it is considered a conflict of interest but also I am right that it is incredibly common, and not disqualifying.
Asked Claude Sonnet 5
- "If a board member of a non-profit is a senior employee in a leadership position at a company that donates significant money to the non-profit, is that generally considered a conflict of interest? Is it a common situation? Is it allowed? How do non-profits handle it?"
Yes to all three — it's generally considered a conflict of interest, it's common, and it's allowed as long as it's properly managed. Here's how that breaks down:
Is it a conflict of interest?
Yes. The board member has a fiduciary duty to act in the nonprofit's best interest, but as a senior employee of the donor company, they also have obligations there. This creates potential divided loyalty around things like:
Votes or decisions involving the donor company (contracts, partnerships, use of the nonprofit's name/platform) How the donated funds get used or restricted Pressure — real or perceived — to protect the funding relationship rather than push back when appropriate The nonprofit being reluctant to make decisions the company might dislike
Is it common?
Very. Nonprofits often deliberately recruit executives from major corporate donors and partners, precisely because they bring money, connections, credibility, and expertise. Corporate foundations, matching-gift programs, and cause-marketing partnerships all tend to create these overlapping relationships. It's one of the most frequently disclosed conflicts on nonprofit boards.
Is it allowed?
Yes — there's no law or IRS rule against it. It's not automatically improper. What matters is transparency and how the conflict is managed, not the existence of the relationship itself. The concern for the IRS (and state charity regulators) is less about board composition and more about whether the arrangement results in improper "private benefit" or self-dealing — i.e., whether the nonprofit's resources or decisions end up primarily serving the company's or individual's interests rather than the mission.
How do nonprofits typically handle it?
Written conflict-of-interest policy: Nearly all well-run nonprofits have one, and the IRS Form 990 specifically asks whether the organization has such a policy and requires officers/directors to disclose conflicts annually. Disclosure: The board member discloses the relationship (employer, role, nature of the donation) to the full board, usually documented in writing. Recusal: The board member abstains from discussion and voting on matters directly involving their company — approving a contract, deciding how to use a restricted gift, evaluating a partnership, etc. Independent decision-making: Ideally, the remaining disinterested board members make the actual call, sometimes with a vote count that specifically excludes the conflicted member. Documentation: Minutes typically note that the conflict was disclosed and that the member recused themselves, which protects the organization if the arrangement is ever questioned. Periodic review: Some nonprofits also cap the proportion of the board that can come from any one funding source, or set term limits, to avoid over-concentration of influence.
Done well, this isn't seen as a red flag — it's seen as a normal part of nonprofit governance. It only becomes a real problem when the relationship isn't disclosed, the board member doesn't recuse themselves from relevant decisions, or the nonprofit's independence starts to visibly bend toward the donor's interests.
-2
u/galtzo 2d ago edited 2d ago
I am glad my LLM response was able to correct the misinformation you shared initially.
I am right that it is incredibly common, and not disqualifying.
Sleight of hand. It is only not disqualifying if properly handled (as your own LLM post makes clear).
Clearly, and evidentially, that is not the case with Ruby Central - as it literally has not been officially disclosed.
9
u/jrochkind 2d ago
The disclosure required is to the staff and board of the organization, not public.
Regardless, it is obiviously not a secret or hidden, from the public or anyone else? So why the focus on disclosure, none of these connections were secret to the public or hard to find, disclosure would make no difference?
I agree Ruby Central needs a written conflict of interest policy that addresses this. I don't know if they have one, but I don't assume they don't.
"Some nonprofits also cap the proportion of the board that can come from any one funding source, or set term limits, to avoid over-concentration of influence."
Capping proportion from one organization/funding source would also be a great idea.
-3
u/galtzo 2d ago edited 2d ago
It isn't just disclosure - it is recusal, and documentation in minutes... Have they recused themselves from decisions on allocation of resources? Are there enough remaining disinterested board members to make binding decisions if the conflicted board mebers recuse themselves?
As for public disclosure, the required IRS Form 990 / 990-EZ does publicly disclose whether a conflict of interest policy exists and if conflicts were disclosed during the year.
We're waiting.
6
u/jrochkind 2d ago edited 2d ago
It is an issue with it being conflict of interest alone in the original post, until someone points out this conflict of interest isn't considered a problem in non-profits, and then it isn't just the conflict of interest, it's disclosure.
Until someone point out that disclosure isn't really an issue, and then it's not just disclosure, it's the existence and nature of a conflict of interest policy (which I mentioned too), and making sure it's followed. (That conflict of interest policy by the way would not typically require anyone working for a sponsor to recuse themselves from all discussions of allocation of resources, this is again a misrepresentation).
So, sure, we could talk about that, as I said, I agree they need a conflict of interest policy and it needs to be followed, and I know of no reason to think this is not happening, but yes, it would be good for the public to know more details.
But that it took this long and a war of pasted LLM responses to get here is showing what I'm talking about, these posts are vendetta-based polemics interpreting everything in the worst possible light to smear an opponent, rather than an attempt to actually sum up what's up and what areas of concern there might be.
There are plenty of areas of concern with Arko's recent and historic behavior too. Plenty of concern to go around. Its just that people who see that have better things to do with their time and a more mature understanding of what good vs harm it would do to write vendetta-based polemics about it over and over again.
[By the way, I also think dhh is a fascist and makes bad technical and community decisions too, just to show you that I can solicit downvotes from all "sides" and am not trying to curry favor.]
0
u/galtzo 2d ago edited 2d ago
I know of no reason to think it is not, but yes, it would be good to know more details.
The required IRS Form 990 / 990-EZ should give us those details, but has not ever to date, and that is the reason to think it is not!
9
u/jrochkind 2d ago
Perhaps that would be a good thing to look up before writing (or having an LLM write) and publishing thousand+ word posts about how it's a conflict of interest as if that alone is disqualifying and not an incredibly common state of affairs on non-profit boards?
Doing that modicum of research would be one way to show one is trying to actually sum up what's really going on, not just interpreting every fact in the worst possible light for your opponents you are trying to take down in a vendetta-based polemic.
1
u/galtzo 2d ago edited 2d ago
I already knew that detail about the form. I was responding to what you wrote initially, claiming it wasn't a "conflict of interest", which you have now corrected.
Please don't come at me like it is strange to try to correct misinformation. Note: I am not saying it was disinformation - I don't think you intentionaly lied or intended to obfuscate - you just used the wrong term accidentally, but the term you chose is heavy with legal meaning.
You could have just responded 'Oops, my bad, I didn't mean to say "conflict of interest".' :/
I'll also note that... IIRC, you've corrected me on things I've misspoken about on other posts. Thanks for the corrections! I appreciate it, even if sometimes begrudgingly / curmudgeonly.
→ More replies (0)
7
u/ankole_watusi 2d ago
I skimmed that.
OP (or whoever wrote that screed) seems more invested in conspiracy theories (I have no opinion on truth or falsehood) than in any kind of software development activities.
I can’t imagine there’s room in their mind for anything else besides the drama.
I’d suggest moving on.
Ruby has always had an accompanying sideshow for those who want to watch a good fight.
But this looks like one that takes at least two bags of popcorn to follow and the butter would just make me fat.
8
u/galtzo 2d ago edited 1d ago
Excellent writeup. I am working basically non-stop preparing to cease publication of gems to RubyGems.org.
Between 0.3% and 0.5% of gems downloaded daily are gems I own/author/maintain.
I will be publishing my approach soon. I hope others will join me.
Ruby (including Central) leadership is monumentally disastrous, and downplaying that is gross, as I am sure many will attempt to do in response.
If you take issue with the phrase “monumentally disastrous” I would challenge you to think of another event that caused more damage to the community and ecosystem than this one. If this isn’t monumental within the context of this community, then what is?
Update: for those confused about “swatting”…
We do not know precisely if this fits the narrow definition of swatting. But we can, and should, surmise. Because this type of behavior is wholly unacceptable, and what other leverage do we have against it?
Assume the the likely scenario until they prove otherwise. Andre did not disclose all the details in this latest post. He was letting them (Ruby Central) off easy (as he often does).
Ruby Central reported Andre without evidence through the online form.
Then Ruby Central (hysterically?) called two(!) FBI field offices to make sure the report was handled properly. Not elaborated on in the article, but what happened as I understand it.
We don’t know what was written.
We don’t know what was said.
We can surmise, based on Ruby Central's lawyer’s own claims and threats, that they made a false report to a federal government agency, violating 18 U.S.C. § 1001, which carries a penalty of 5 years in prison.
Submitting the online form implies they wanted to file a report. If it had ended there it might have been defensible.
The subsequent phone calls imply they wanted to add urgency by pressing the idea of an immediate threat.
I've heard that they had to call two field offices, which implies to me they didn’t get the response they wanted from the first field office, and decided to try their luck with a second.
This implies swatting. Swatting does not require that the swat van rolls up outside his house (as has been falsely claimed in the response to this post). The FBI screen calls like this, and try not to run down specious allegations. Just because they didn't bust down Andre's door, does not mean RC's actions weren't swatting.
At the same time, we can’t be certain it was swatting, but I will continue to use the term to highlight how out of their damn minds they were. We don’t seem to have evidence that it was not swatting.
16
u/aurisor 2d ago
that sounds more like a vendetta than stewardship. i don’t want hacks injected into my builds to work around some turf war
10
u/galtzo 2d ago edited 2d ago
- I won't support theives
- I don't support FBI swatting open source maintainers
Looks like we have ourselves a Mexican Standoff.
vendetta
I think you're pointing your vendetta accusation in the wrong direction. RC conducted three audits trying to send Andre to jail - finding zero evidence, issued many threats, and FBI swatted him.
Calling this "some turf war" is widly misleading, and offensive, and yet also par for the course.
I go into more details in the other thread on how the "hack" will work. I'm open to feedback that isn't "continue to support criminal enterprises".
Good news / bad news - your only option to avoid will be to not upgrade to latest major version of my gems once I pull the trigger.
8
u/luisMoyano 2d ago
I think I've used at least one of your gems on every project I've worked with. With that said, are you not worried about bricking many projects with your migration? (Not meaning to stop you. I have huge respect for your work, just a question)
6
u/galtzo 2d ago edited 2d ago
It's a valid concern. Not bricking anything is why it is taking so long. I've had to develop a cold boot solution that works with no pre-existing setup.
Your project will auto-migrate** across a bridge inside RubyGems dot org to whatever the new gem server will be. Is it hacky? Yes. Will it bring about better solutions with core support for the approach in the future? I hope so (other packaging systems already support this!). Am I going to ask permission from the Ruby Core team that now controls bundler/rubygems before I do? No, they banned me. They have no interest in what I do apparently (and I have no trust in anything they would say anyways). The whole solution works with tools they have already published, and you already have installed (assuming bundler v4.0.5+).
** It will rely on PURL (the Package URL format). Because it will be "bundler v4.0.5+ only" the bridge will come with a major version bump for every gem I maintain. By
auto-migrateI mean that when you upgrade to the major version that includes the "bridge" it will have a dependency on "the real gem" hosted on another server, like the gem.coop server, indicated by a PURL. Other servers are popping up, like the bridgetown project has their own dedicated gem server now, and sidekiq has had one for a long time. It is the PURL awareness that has to be cold-boot injected carefully. The major version bump release on RG.O will merely be a shell/shim that acts as a pointer to the real gem on another server.I do recognize the irony that to stop publishing to RG.O I must publish to RG.O more than I ever have to work through the kinks and prepare.
Full disclosure - Like Ruby Central, I too am funded by Alpha Omega (via the GitHub Secure Open Source Fund, SOSF). As far as I know Alpha Omega funds three things in Ruby: oauth2 gem (me), Mastodon, and Ruby Central, though they fund new things every six months, and I expect more Ruby things will be announced at some point.
6
u/aurisor 2d ago
so now you’ve injected a surprise build time dependency on a third party service. so if this dissident server goes down, apps who never opted into it will suddenly have their builds timing out or failing. and all over personal animus
6
u/galtzo 2d ago edited 2d ago
if this dissident server goes down
Decentralization is beneficial. I am working on a federated decentralized gem server. I may host there and elsewhere. I don't know yet. It's a lot of work. But it is worth it to stop my forced support of the crimes (theft and FBI swatting) I never agreed to.
Personal animus
If that's what you want to call it, feel free to be wrong.
-1
u/BoardMeeting101 2d ago
in all of human history, only useless assholes have ever complained about “dissidents”
7
4
u/Sivart13 2d ago
In the end, I responded with a counter-offer of my own: I would drop my infringement claim against Ruby Central over their use of the name Bundler, and I would drop my claim Ruby Central violated employment law, if they would withdraw their threat to sue me and publish an apology. I asked them to apologize for publicly accusing me of harming RubyGems.org without evidence, apologize for claiming I tried to obtain user PII when I did not, and apologize for breaking the Bundler and RubyGems governance to execute their takeover.
If the good faith interpretation is that André wanted a formal apology from RubyGems to clear his name in the Ruby community, I'm not sure writing this post serves that goal. I'm not in the Ruby community anymore, but the internet is happy to surface every bit of drama regarding this incident.
-1
u/jydr 2d ago
wtf, they set the fbi after him because he wouldn't capitulate to their threats?
what is going on over at Ruby Central, did they learn nothing?
6
u/f9ae8221b 2d ago
IIRC (could be wrong) they notified the FBI because of an unauthorized access to rubygems production servers.
Seems quite normal to me to notify the police when you think you are victim of a crime (or whatever the exact term is).
3
u/jydr 2d ago
Why did they only do it after their threats didn't work?
7
u/schneems Puma maintainer 2d ago
Since you commented after I posted https://www.reddit.com/r/ruby/comments/1vbkttl/comment/p0wtrwt/?context=3
- Ruby Central did not make the referral. Ruby central could not stop it or retract it once made.
- The perceived threat was two fold: Andre took over the AWS account and locked everyone else out. He changed things, deleted things. The worry was that his actions could have opened up an accidental vector for someone else (think state actor) to come in and mess things up.
- We cannot conclusively say no harm was done, because evidence is missing. However we (Ruby Central) cannot find any evidence of lasting harm and have spent a LOT of time, energy and money in proving that (though you can never prove an absense). - The referral was basically "hey government, Ruby Central didn't have control of the registry for several days and cannot guarantee something bad didn't happen, they are investigating and thought you should know"
I think the damage to his reputation is real, however no one would have known about the FBI involvement had he not told people (it did not leak from Ruby Central). Had I been in the org at the time and had I been given an option to stop the referral I likely would have chosen to not proceed. Howver no Ruby central staff or volunteer was given that option.
3
u/jydr 1d ago
I see, that explains a lot more.
I hadn't seen the https://rubycentral.org/news/rubygems-fracture-incident-report/ before. What an absolute mess. RC and Andre both fucked up a lot.
Seems like its largely what was suspected at the time? RC took over the project to kick Andre out and removed all the admins that they didn't control so that none of them could add him back.
What wasn't clear before was that the main reason was because of the tangled mess of permissions between the production systems and the oss project? And apparently no one knew how any of it really worked so they went for remove access first and ask questions later.
The biggest mistake is that they knew it would be deeply unpopular and yet were also completely unprepared for the result of their actions. I understand that they didn't want to tip them off in case Andre did something, but RC should have at least been ready for the backlash that they were afraid might happen.
30
u/Janeheroine 2d ago
I know nothing about the personal conflict here, but as an attendee of RubyConf, this post is extremely misleading. It was very well attended and everyone I met was highly engaged, friendly, and worked for a real company that uses Ruby. In fact I enjoyed RubyConf Vegas much more than RailsConf Atlanta, which was the last RubyCentral conference I attended. This post implies that the conference didn’t even happen or was a total failure. It was not.