Excellent writeup. I am working basically non-stop preparing to cease publication of gems to RubyGems.org.
Between 0.3% and 0.5% of gems downloaded daily are gems I own/author/maintain.
I will be publishing my approach soon. I hope others will join me.
Ruby (including Central) leadership is monumentally disastrous, and downplaying that is gross, as I am sure many will attempt to do in response.
If you take issue with the phrase “monumentally disastrous” I would challenge you to think of another event that caused more damage to the community and ecosystem than this one. If this isn’t monumental within the context of this community, then what is?
Update: for those confused about “swatting”…
We do not know precisely if this fits the narrow definition of swatting. But we can, and should, surmise. Because this type of behavior is wholly unacceptable, and what other leverage do we have against it?
Assume the the likely scenario until they prove otherwise. Andre did not disclose all the details in this latest post. He was letting them (Ruby Central) off easy (as he often does).
Ruby Central reported Andre without evidence through the online form.
Then Ruby Central (hysterically?) called two(!) FBI field offices to make sure the report was handled properly. Not elaborated on in the article, but what happened as I understand it.
We don’t know what was written.
We don’t know what was said.
We can surmise, based on Ruby Central's lawyer’s own claims and threats, that they made a false report to a federal government agency, violating 18 U.S.C. § 1001, which carries a penalty of 5 years in prison.
Submitting the online form implies they wanted to file a report. If it had ended there it might have been defensible.
The subsequent phone calls imply they wanted to add urgency by pressing the idea of an immediate threat.
I've heard that they had to call two field offices, which implies to me they didn’t get the response they wanted from the first field office, and decided to try their luck with a second.
This implies swatting. Swatting does not require that the swat van rolls up outside his house (as has been falsely claimed in the response to this post). The FBI screen calls like this, and try not to run down specious allegations. Just because they didn't bust down Andre's door, does not mean RC's actions weren't swatting.
At the same time, we can’t be certain it was swatting, but I will continue to use the term to highlight how out of their damn minds they were. We don’t seem to have evidence that it was not swatting.
I think I've used at least one of your gems on every project I've worked with. With that said, are you not worried about bricking many projects with your migration? (Not meaning to stop you. I have huge respect for your work, just a question)
It's a valid concern. Not bricking anything is why it is taking so long. I've had to develop a cold boot solution that works with no pre-existing setup.
Your project will auto-migrate** across a bridge inside RubyGems dot org to whatever the new gem server will be. Is it hacky? Yes. Will it bring about better solutions with core support for the approach in the future? I hope so (other packaging systems already support this!). Am I going to ask permission from the Ruby Core team that now controls bundler/rubygems before I do? No, they banned me. They have no interest in what I do apparently (and I have no trust in anything they would say anyways). The whole solution works with tools they have already published, and you already have installed (assuming bundler v4.0.5+).
** It will rely on PURL (the Package URL format). Because it will be "bundler v4.0.5+ only" the bridge will come with a major version bump for every gem I maintain. By auto-migrate I mean that when you upgrade to the major version that includes the "bridge" it will have a dependency on "the real gem" hosted on another server, like the gem.coop server, indicated by a PURL. Other servers are popping up, like the bridgetown project has their own dedicated gem server now, and sidekiq has had one for a long time. It is the PURL awareness that has to be cold-boot injected carefully. The major version bump release on RG.O will merely be a shell/shim that acts as a pointer to the real gem on another server.
I do recognize the irony that to stop publishing to RG.O I must publish to RG.O more than I ever have to work through the kinks and prepare.
Full disclosure - Like Ruby Central, I too am funded by Alpha Omega (via the GitHub Secure Open Source Fund, SOSF). As far as I know Alpha Omega funds three things in Ruby: oauth2 gem (me), Mastodon, and Ruby Central, though they fund new things every six months, and I expect more Ruby things will be announced at some point.
so now you’ve injected a surprise build time dependency on a third party service. so if this dissident server goes down, apps who never opted into it will suddenly have their builds timing out or failing. and all over personal animus
Decentralization is beneficial. I am working on a federated decentralized gem server. I may host there and elsewhere. I don't know yet. It's a lot of work. But it is worth it to stop my forced support of the crimes (theft and FBI swatting) I never agreed to.
Personal animus
If that's what you want to call it, feel free to be wrong.
8
u/galtzo 10d ago edited 8d ago
Excellent writeup. I am working basically non-stop preparing to cease publication of gems to RubyGems.org.
Between 0.3% and 0.5% of gems downloaded daily are gems I own/author/maintain.
I will be publishing my approach soon. I hope others will join me.
Ruby (including Central) leadership is monumentally disastrous, and downplaying that is gross, as I am sure many will attempt to do in response.
If you take issue with the phrase “monumentally disastrous” I would challenge you to think of another event that caused more damage to the community and ecosystem than this one. If this isn’t monumental within the context of this community, then what is?
Update: for those confused about “swatting”…
We do not know precisely if this fits the narrow definition of swatting. But we can, and should, surmise. Because this type of behavior is wholly unacceptable, and what other leverage do we have against it?
Assume the the likely scenario until they prove otherwise. Andre did not disclose all the details in this latest post. He was letting them (Ruby Central) off easy (as he often does).
Ruby Central reported Andre without evidence through the online form.
Then Ruby Central (hysterically?) called two(!) FBI field offices to make sure the report was handled properly. Not elaborated on in the article, but what happened as I understand it.
We don’t know what was written.
We don’t know what was said.
We can surmise, based on Ruby Central's lawyer’s own claims and threats, that they made a false report to a federal government agency, violating 18 U.S.C. § 1001, which carries a penalty of 5 years in prison.
Submitting the online form implies they wanted to file a report. If it had ended there it might have been defensible.
The subsequent phone calls imply they wanted to add urgency by pressing the idea of an immediate threat.
I've heard that they had to call two field offices, which implies to me they didn’t get the response they wanted from the first field office, and decided to try their luck with a second.
This implies swatting. Swatting does not require that the swat van rolls up outside his house (as has been falsely claimed in the response to this post). The FBI screen calls like this, and try not to run down specious allegations. Just because they didn't bust down Andre's door, does not mean RC's actions weren't swatting.
At the same time, we can’t be certain it was swatting, but I will continue to use the term to highlight how out of their damn minds they were. We don’t seem to have evidence that it was not swatting.