Ruby Central's Destructive Legacy
At conferences and meetups, and in conversations online, many Ruby developers have asked me about Ruby Central and my disagreement with them. This post is my attempt to answer the questions I’ve been getting over and over, covering: 1) what is Ruby Central doing now? 2) has the dispute over Bundler and RubyGems been resolved? 3) what has Ruby Central said about the dispute? and 4) what can Ruby developers do now?
What is Ruby Central doing now?
To talk about what Ruby Central is doing now, we need to start with a bit of historical context. What was Ruby Central doing before this saga began? About 18 months ago, Ruby Central:
- ran 2 conferences every year, RubyConf and RailsConf
- had an Open Source Committee with 3 members (Ufuk, Gabi, Mike)
- funded 7 part-time community OSS contributors (André, Arun, Ellen, Gift, Irene, Josef, Martin)
- funded 3 full-time OSS developers (Colby, Samuel, David)
- coordinated those 10 OSS contributors across 3 major OSS projects:
- RubyGems
- Bundler
- RubyGems.org
Then, about 10 months ago, Ruby Central began what core team member Ellen Dash called a “hostile takeover” of the RubyGems, Bundler, and RubyGems.org open source projects, seizing control of the projects and locking out the team that had nurtured and maintained them for over a decade.
Today, 10 months after their takeover, Ruby Central has:
- lost 2 of 2 conferences, after ending RailsConf, cancelling a significant portion of the last RubyConf, and providing no future conference locations or dates for the first time in decades
- lost 2 of 3 major OSS projects, by transferring Bundler & RubyGems away to Matz
- lost 9 of 10 contributors to open source work, including:
- 6 of 7 operators of RubyGems.org (André, Samuel, Arun, Josef, Ellen, Martin)
- 2 of 3 full-time contributors to OSS (Samuel, David)
- 2 of 2 OSS writers (Gift, Irene)
- lost 3 of 3 members of the Open Source Committee (Gabi, Mike, Ufuk)
- lost 5 of 7 board members (Kinsey, Valerie, Naijeria, Ben, Ufuk)
- lost 3 of 3 Executive Directors (Adarsh, Chelsea, Shan)
- lost 2 of 2 major financial sponsors (Sidekiq and Shopify, although Shopify seemingly just returned after a 9 month break)
Unlike many community non-profits (including the Python Software Foundation), Ruby Central does not hold elections for their board of directors. Despite rewriting their bylaws entirely this year, new directors are still selected exclusively by existing directors, with no public process for input or feedback. The current board consists of just 2 of the 7 members who initially approved the hostile takeover, plus 3 new members chosen by the previous board (Brandon, Jey, and Ran).
Based on Ruby Central’s public announcements, they have added exactly one new program after ending both conferences and transferring away half of their open source software: a new security project, funded by a grant from Alpha-Omega. The security project’s goal is to use Anthropic’s Project Glasswing to search for security issues in gems that have already been published. In their first monthly report for June, they reported finding a total of 5 vulnerabilities, with 1 issue at medium severity, and 4 at low or unclassified severities.
Ruby Central’s current sponsorship drive, the Ruby Alliance, has found three members willing to join: Gusto, Thoughtbot, and (very recently) Shopify. What none of the sponsorship announcement posts have mentioned is that Gusto and Thoughtbot employ two of the five Ruby Central board members. David Corson-Knowles is both a board member and a Senior Staff Engineer at Gusto. Ran Craycraft is not just President of the Ruby Central board, he is also Managing Director, Americas at Thoughtbot. That means the board members who allocate the sponsorship money are also providing that sponsorship money, a conflict of interest which neither the companies nor Ruby Central have disclosed. The final sponsor is Shopify, coming back 9 months after it was reported they demanded Ruby Central start this disaster in the first place.
Has our dispute been resolved?
No, our dispute has not been resolved. Since last October, Ruby Central has been threatening to sue me. They have not withdrawn that threat as of today.
The core of our dispute is that last September, Ruby Central hijacked the Bundler and RubyGems GitHub projects from their maintainers of over ten years. When I informed Ruby Central that I own the name Bundler, they retaliated with a threat to sue me for supposed “hacking”, a position I have always disputed.
Ruby Central has stated they will only withdraw their threat if I drop my claim they infringed the name Bundler. After I also questioned if my work as a contractor had been allowed by state labor law, they additionally started demanding that I drop any claims regarding employment as well. So far, Ruby Central has consistently said they will only withdraw their lawsuit threat if I give up my infringement claim for Bundler and any possible back pay I believe they owe me.
When the lawsuit threat did not make me drop my claims, Ruby Central then chose to give away the Bundler gem and rubygems GitHub repo to Matz. After that, all of the former maintainers made a new offer to settle. Ruby Central never replied to our offer. Instead, they restated their original offer, and only to me: they would withdraw their threat to sue only if I dropped all of my claims. I did not accept, and after four months with no further progress, I wrote a public update.
In response to my post, Ruby Central did two things at once:
First, Ruby Central told me they were actively seeking outside funding to pay a settlement to me that would end our dispute. They asked me for an amount that would fully compensate me for my attorney’s fees, the amount they might owe in back pay, plus compensation for an additional six months after I was fired. With help from an expert, I calculated an amount around $450,000, and provided that number as requested.
Despite providing that number, I have never asked for that amount of money. I provided that number at Ruby Central’s request, so they could seek funding. What I have instead asked for, consistently, is an apology for the attacks on my reputation without evidence, and the far smaller amount of reimbursement for my attorneys’ fees.
Second, at the same time as they sought funding for a settlement, Ruby Central also reported me to the FBI through their lawyer, requesting that I be criminally investigated. On March 9, 2026, Ruby Central’s lawyer informed my lawyer that he had made the report, and suggested I would need to hire a criminal defense attorney. As far as I have been able to learn, Ruby Central’s lawyer was not able to provide any evidence to the FBI with his report, since Ruby Central has not been able to find evidence that I caused any harm during their three audits of the RubyGems AWS account.
Unfortunately, it is impossible to withdraw a report to the FBI. Despite Ruby Central’s later statement to me that they don’t intend to pursue the FBI report, they gave up the ability to make that decision when they filed the report — it’s up to the FBI now, not up to them.
A few weeks after saddling me with a permanent possibility of criminal prosecution by the FBI, Ruby Central ran out of money. Their post said they “want to move forward together”, but did not take any action or answer any questions regarding their past actions. Nonetheless taking that post as a promising sign, I offered Ruby Central a new option to resolve our disagreement.
I did not ask them to return Bundler. I did not ask them for fair payment under employment law. I didn’t even ask for an apology. Instead, I asked for 1) public confirmation that I did not cause any harm to RubyGems, and 2) reimbursement for the lawyer fees I have had to pay because of their threatened lawsuit. Ruby Central then ignored that post, and multiple attempts to reach out, for six weeks.
After six weeks, Ruby Central sent me a rerun of their settlement offer, with some specific…