Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Since the script comes from GitHub repo, and the source is also on the repo, isn't building the source the same as getting the shell script and running it? I mean if one is compromised, the other might be compromised too.


Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: