After listening to about a dozen first-hand accounts, I’ve published what I know so far about the RubyGems takeover.

https://joel.drapper.me/p/rubygems-takeover/

Shopify, pulling strings at Ruby Central, forces Bundler and RubyGems takeover

Ruby Central recently took over a collection of open source projects from their maintainers without their consent.

@joeldrapper thanks for writing this up, best account i’ve seen of what happened (catching up whole on holidays) — what i don’t get, if The Big S is so worried about supply chain attacks, why don’t they fork the repos themselves? they certainly have all the resources necessary to run their own infra and internal mirrors — the whole angle on rv being a threat is a big 😬😬😬 too.