• davehtaylor@beehaw.org
    link
    fedilink
    arrow-up
    0
    ·
    4 months ago

    Might be neat. Might check it out. But devs really need to stop asking me to install things by curling a script and piping it into my shell. There are better ways to do this. Doing this leaves a massive possible attack surface.

    • erwan@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      4 months ago

      No matter how they package it, running a binary downloaded from Internet has the same attack surface