Gå offline med appen Player FM !
Ruby’s Trustquake
Manage episode 511876780 series 3310917
In this episode of C4, Andrew Mason and Rachael Wright-Munn join Drew to unpack recent controversies surrounding Ruby Central and its alleged takeover of Ruby Gems and Bundler. The trio delves into the timeline of events, conflicting narratives, communication failures, and the underlying security concerns. They address theories and facts, scrutinize the governance of Ruby Central, and discuss the implications for the Ruby community. The episode emphasizes the importance of asking questions and seeking clarity, while advocating for a balanced and constructive approach to resolving the community's issues.
Sources discussed*:
- Ellen's first post on the RubyGems controversy
- A board member's perspective on the RubyGems controversy
- An Update From Ruby Central (Video)
- Investigation (allegedly) reveals Shopify manipulated Ruby Central to force takeover of Bundler and RubyGems
- Strengthening the Stewardship of RubyGems and Bundler
- Martin Emde's post on Bluesky
- Reddit post for "An update from Ruby Central"
- Bundler Policies on GitHub
- Ruby Central "About" page
- Advocacy for Reduced Rails Usage
- Alpha-Omega Project
- Organization & Structure of Open Source Software Development Initiatives - Cyberlaw Clinic
- Ruby Central News Post: Alpha-Omega support
- StepSecurity: npm supply chain compromise
- Socket: npm supply chain attack
- Palo Alto Networks Unit 42: npm supply chain attack
* Some sources include unverified information being presented as fact. Read with caution.
HoneybadgerHoneybadger is an application health monitoring tool built by developers for developers.
Judoscale
Autoscaling that actually works. Take control of your cloud hosting.
Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.
Support the show
Kapitel
1. Setting The Stage: Ruby Drama (00:00:00)
2. Guests And Goals For The Talk (00:00:16)
3. How We Got Here: Early Merger Context (00:01:09)
4. Competing Timelines And Claims (00:02:26)
5. The September Timeline: Removals And Restorations (00:02:57)
6. Theories, Facts, And Misinformation (00:04:26)
7. Operator Agreements And Governance PR (00:05:04)
8. Funding Loss, Sponsors, And Dependence (00:06:03)
9. Communication Breakdowns And Public Perception (00:07:20)
10. Security As Justification (00:09:06)
11. Nonprofit Compliance And New Leadership (00:11:19)
12. Alpha-Omega, Shopify, And Policies (00:12:50)
13. Is This A Hostile Takeover? (00:14:39)
14. Ownership: Service Versus Code (00:16:27)
15. Governance Gaps And Single-Point Risks (00:17:59)
16. Maintainers Leaving And Coverage Claims (00:19:49)
17. Forking Versus Lockdown (00:21:12)
18. Emotion, Burnout, And Trust (00:22:42)
19. Board Structure And Community Voice (00:24:00)
20. A Gray Situation, Not Villains (00:25:44)
21. What Now: Accountability Without Drama (00:27:45)
22. Final Thoughts And Ways Forward (00:28:51)
66 episoder
Manage episode 511876780 series 3310917
In this episode of C4, Andrew Mason and Rachael Wright-Munn join Drew to unpack recent controversies surrounding Ruby Central and its alleged takeover of Ruby Gems and Bundler. The trio delves into the timeline of events, conflicting narratives, communication failures, and the underlying security concerns. They address theories and facts, scrutinize the governance of Ruby Central, and discuss the implications for the Ruby community. The episode emphasizes the importance of asking questions and seeking clarity, while advocating for a balanced and constructive approach to resolving the community's issues.
Sources discussed*:
- Ellen's first post on the RubyGems controversy
- A board member's perspective on the RubyGems controversy
- An Update From Ruby Central (Video)
- Investigation (allegedly) reveals Shopify manipulated Ruby Central to force takeover of Bundler and RubyGems
- Strengthening the Stewardship of RubyGems and Bundler
- Martin Emde's post on Bluesky
- Reddit post for "An update from Ruby Central"
- Bundler Policies on GitHub
- Ruby Central "About" page
- Advocacy for Reduced Rails Usage
- Alpha-Omega Project
- Organization & Structure of Open Source Software Development Initiatives - Cyberlaw Clinic
- Ruby Central News Post: Alpha-Omega support
- StepSecurity: npm supply chain compromise
- Socket: npm supply chain attack
- Palo Alto Networks Unit 42: npm supply chain attack
* Some sources include unverified information being presented as fact. Read with caution.
HoneybadgerHoneybadger is an application health monitoring tool built by developers for developers.
Judoscale
Autoscaling that actually works. Take control of your cloud hosting.
Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.
Support the show
Kapitel
1. Setting The Stage: Ruby Drama (00:00:00)
2. Guests And Goals For The Talk (00:00:16)
3. How We Got Here: Early Merger Context (00:01:09)
4. Competing Timelines And Claims (00:02:26)
5. The September Timeline: Removals And Restorations (00:02:57)
6. Theories, Facts, And Misinformation (00:04:26)
7. Operator Agreements And Governance PR (00:05:04)
8. Funding Loss, Sponsors, And Dependence (00:06:03)
9. Communication Breakdowns And Public Perception (00:07:20)
10. Security As Justification (00:09:06)
11. Nonprofit Compliance And New Leadership (00:11:19)
12. Alpha-Omega, Shopify, And Policies (00:12:50)
13. Is This A Hostile Takeover? (00:14:39)
14. Ownership: Service Versus Code (00:16:27)
15. Governance Gaps And Single-Point Risks (00:17:59)
16. Maintainers Leaving And Coverage Claims (00:19:49)
17. Forking Versus Lockdown (00:21:12)
18. Emotion, Burnout, And Trust (00:22:42)
19. Board Structure And Community Voice (00:24:00)
20. A Gray Situation, Not Villains (00:25:44)
21. What Now: Accountability Without Drama (00:27:45)
22. Final Thoughts And Ways Forward (00:28:51)
66 episoder
Alla avsnitt
×Välkommen till Player FM
Player FM scannar webben för högkvalitativa podcasts för dig att njuta av nu direkt. Den är den bästa podcast-appen och den fungerar med Android, Iphone och webben. Bli medlem för att synka prenumerationer mellan enheter.