logoalt Hacker News

bee_rider • yesterday at 5:13 PM • 1 reply • view on HN

The intended workflow is to download the install scripts, download the source code, read them both, and then start running things. That’s how Open Source is secured. Piping from bash to curl is just the most obvious warning flag.


Replies

majorchord • yesterday at 5:34 PM

And practically zero people are actually using this "intended workflow" in the real world.

➕ show 1 reply