Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For me the insecurity isn't even the worst thing about curl | sh.

I like package managers, and I tolerate tarballs, because I know what they do and how to reverse it. I care about the organisation of my filesystem and suspect that the people who suggest I pipe their script into my shell do not care at all.



I have similar concerns. Also, these scripts pretty much never have an accompanying "uninstall" or "reset system state" scripts.

For parent: check out http://github.com/awalGarg/curl-tap-sh (disclaimer: I am the author, and it was on HN's frontpage already a while ago)


Will add uninstall func, and reset func. I will have a look at your project




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: