Hacker News new | past | comments | ask | show | jobs | submit login

> curl -Ls http://bit.ly/gh-install-package | sudo sh

Yes let us pipe a script from a changeable uri controlled by a third-party.

But then again Homebrew, Chocolatey, GitLab, etc is also guilty of this!




GitLab only does this on https sites as far as I know and offer a link so people that are concerned can copy the whole script.


Some PHP garbage in the dock on the example video, too.

Safe to disregard.


You can just download the files, check it and then execute




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: