Some pedantic points:
> Ruby Central, whose dependence on one big sponsor then produced the 2025 takeover
Ruby Central had two major sponsors at the time: Alpha Omega and Shopify. Also the events had much more to do with interpersonal conflicts than sponsors.
My report: https://rubycentral.org/news/rubygems-fracture-incident-repo...
That is the GitHub only portion, but the AWS root happened immediately after/during and has its own timeline https://rubycentral.org/news/rubygems-org-aws-root-access-ev...
> a depleted team
The named people we lost from the report: Sam was already way out the door. Andre was most of the way. Ellen wasn't doing that operational work. Deivid was only working on bundler and not the registry. Josef is the main operational loss, he removed himself. I'm unsure of which attack exactly Is being referenced, but Colby was promoted to full time (was planned before, just waiting on paperwork).
Other prior maintainers and security researchers did NOT leave. Maciej Mensfeld Was especially crucial. Jenny Shen. To name a few. These people are “the maintainers” too. We’ve (I’m a volunteer, came on in October 2025) brought on a number of in-kind engineers as well (companies donating engineer hours via letting employees work on company time).
I reached out to everyone unnamed that lost GitHub access. Of them, one asked for admin back (granted). None were active in operations.
Seldo’s overall point: about the fragility of all of this still stands. But I also believe the details and the nuance matter. I reached out to Laurie on bsky when this was first published but didn’t hear back.