Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 1 addition & 2 deletions alpha/engagements/2025/Ruby Central/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,12 +23,11 @@ The first phase of the Infrastructure Security work focused on SSO access is est
* [June 2025](update-2025-06.md)
* [July 2025](update-2025-07.md)
* [August 2025](update-2025-08.md)

* [September 2025](update-2025-09.md)

### Primary Contacts

* Marty Haught - Director of Open Source
* Samuel Giddins - Security Engineer-in-Residence

### Announcement / News

Expand Down
18 changes: 18 additions & 0 deletions alpha/engagements/2025/Ruby Central/update-2025-09.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# Update 2025-08

## Samuel Giddins

Samuel resigned from his position with Ruby Central on Sep 5. We will backfill his position to continue the security work.

## Marty Haught

For my monthly update, I will focus on the incident around ownership of the RubyGems, Bundler, and RubyGems.org GitHub repositories. On Sep 18, the Ruby Central board voted for the open source team to temporarily restrict access to the shared GitHub organization where critical repos resided for RubyGems.org, restrict access to the production RubyGems.org systems to those that need it, get new operator agreements in place with operators, and then re-enable access once complete. Here is [the latest post](https://rubycentral.org/news/our-stewardship-where-we-are-whats-changing-and-how-well-engage/) by our executive director.

Though Marty was initially part of the access control, this process has been out of his control. At the time of this update, the board still has not resolved the situation. It has caused significant stress in our community. Marty’s been focused on an accelerated operational transition for rubygems.org. In this situation, most of the team had departed, so we needed to bring in new operators and restructure on call. That is progressing but it's a slow process. Thankfully, it has not impacted production services.

Marty has been pushing Ruby Central leadership to start an open source governance process, which he expects will be announced soon. This has been an incredibly difficult situation, but he hopes Ruby Central will learn and get stronger from it.


## Infrastructure Security - SSO

The acceleration of the operations transition positively pushed this project forward. We expect to complete this in October.
Loading