Code and the Coding Coders who Code it

Ruby’s Trustquake

5 snips
Oct 7, 2025
Rachael Wright-Munn, a Ruby community maintainer and governance commentator, joins the discussion to explore the recent upheaval regarding RubyGems and Bundler. The trio dives into the controversy's timeline, revealing communication failures and security concerns. Rachael highlights funding pressures and the influence of major sponsors like Shopify on Ruby Central's governance. They emphasize the need for constructive dialogue and better community engagement, while reflecting on the fragility of open-source projects dependent on limited resources.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Triggering Permission Changes

  • The GitHub org rename and mass removal of maintainers triggered claims of a hostile takeover of RubyGems and Bundler.
  • Permissions were partially restored days later but further revocations escalated the crisis.
ADVICE

Demand Verified Sources

  • Ask clear, sourced questions before sharing theories and timelines.
  • Avoid posting unverified claims presented as facts that worsen confusion.
INSIGHT

Governance And Operator Agreement Conflict

  • Governance proposals and operator agreements appeared around the same time as access changes.
  • Maintainers disputed whether RubyGems and RubyGems.org fell under those agreements.
Get the Snipd Podcast app to discover more snips from this episode
Get the app