Bundler
Search documents
Rails 创始人遭社区逼宫,金主立马撑腰,核心维护者被“血洗”出局,10 年了,DHH 还是 Ruby 社区的最大问题?
3 6 Ke· 2025-09-26 10:10
DHH 不肯沉默,Shopify 强势站队,Rails 社区的年度大戏来了。 这场大戏其实早有前情——前两周就已爆出接管丑闻。 一次恶意收购 RubyGems 是由 Ruby Central 赞助的 Ruby 标准包管理器。Ruby Central 是一家非营利性组织,负责举办包括 RubyConf 及已经停止运营的 RailsConf 在内 的各类相关活动,并赞助多款关键工具。其中包括 RubyGems 和 Bundler,后者为依赖项管理器,可确保应用程序安装所需 gem(即 Ruby 包)的正确版 本。 9 月 9 日,一名匿名 RubyGems 维护者在没有任何解释的情况下,将 RubyGems GitHub 企业版更名为 Ruby Central,并添加了 Ruby Central 开源总监 Marty Haught 作为维护者,同时删除了 RubyGems 项目的其他所有维护者。 六天之后,尽管相关变更被基本撤销,这名匿名维护者表示,在与 Haught 交谈后,Haught 也承认行为不当,但他仍是项目 GitHub 企业版的所有者。在 不久后的 9 月 18 日,Haught 正式从 GitHu ...
开源项目遭“夺权”,原核心维护者全被踢出局后怒批:这是一次恶意接管
3 6 Ke· 2025-09-25 07:36
Core Points - The recent controversy in the Ruby community revolves around the management of the RubyGems and Bundler projects, with accusations of a "hostile takeover" by Ruby Central, the non-profit organization overseeing these tools [1][11][12] - Long-time maintainers, including Ellen Dash, have expressed their outrage over being removed from their roles without prior notice or explanation, leading to significant community backlash [5][10][14] - Ruby Central's justification for these actions is centered on enhancing security and governance, citing the need to protect the Ruby ecosystem from supply chain attacks [11][12] Summary by Sections Project Management and Governance - RubyGems and Bundler, essential tools for the Ruby programming language, have been maintained by a dedicated team for years without formal compensation [2] - The abrupt removal of maintainers, including Ellen Dash, was executed by Marty Haught, Ruby Central's open-source director, raising questions about governance practices [5][6][11] Community Response - The Ruby community has reacted strongly against Ruby Central's actions, with many developers expressing disappointment and anger on social media [14][16] - Critics argue that Ruby Central's actions reflect a shift towards corporate influence over community-driven projects, undermining the principles of open-source collaboration [14][16] Future Implications - The incident highlights the ongoing struggle between professional management and community autonomy in open-source governance, emphasizing the need for transparency and communication [20] - As core maintainers resign, the new management team faces scrutiny to prove their capability and maintain community trust [20]