Theregister RubyGems Fracture: Governance Crisis in Ruby Community
Article Content
- •The RubyGems GitHub repository was taken over by Ruby Central, removing existing maintainers.
- •Internal conflicts arose from perceived competition between former maintainers and Ruby Central.
- •The incident led to the formation of Gem Cooperative by ousted maintainers.
The RubyGems Fracture incident, occurring from September 10-18, 2025, involved a contentious takeover of the RubyGems GitHub repository by Ruby Central, leading to the removal of several long-time maintainers. The incident was triggered by internal conflicts, particularly involving André Arko and Samuel Giddins, who were seen as competitors after launching their own Ruby management tool. Ruby Central's actions were characterized by poor communication and a lack of transparency, resulting in significant backlash from the community. The report by Richard Schneeman aims to clarify the events and decisions made during this period, although it is not fully independent as it was approved by the Ruby Central board. The fallout included the formation of a new group, Gem Cooperative, by the ousted maintainers. Ruby Central has committed to improving governance and community participation following the incident. The report highlights the subjective nature of the events and the challenges in achieving consensus among stakeholders.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Gem Cooperative in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…