zlacker

[return to "Ruby Central's Attack on RubyGems [pdf]"]
1. thomas+pH[view] [source] 2025-09-19 14:09:26
>>jolux+(OP)
An update from Ruby Central: Strengthening the Stewardship of RubyGems and Bundler

https://rubycentral.org/news/strengthening-the-stewardship-o...

◧◩
2. jmuguy+LK[view] [source] 2025-09-19 14:28:58
>>thomas+pH
So essentially they randomly cut off a bunch of long time maintainers for some vague legal and/or security reasons. If there was real reason to do that in a hurry, that's what we need to see, not a corporate PR message.
◧◩◪
3. awilso+yz1[view] [source] 2025-09-19 19:06:29
>>jmuguy+LK
100%. I assumed this was inspired by the supply chain attack, but what a horrible way to address this. Reverting it back before revoking it a second time is even more bizarre. Severely mixed messages from leadership, perhaps?
[go to top]