4 ms·
why?
by mtkocak 10y ago
why?
- psylence519 10y agoYou’re executing a script directly off of a git repo. There’s a lot of trust involved there. One sneaky pull-request away from an exploit. That said, I do it all the time like everyone else. :)
- lsaferite 10y agoAs others have said, blinding executing a ruby script directly out of a GH repo is risky (to put it mildly). Sure, you have to have some trust in the whole infrastructure at some point, but the number of times I've seen this type of thing blindly posted and followed boggles my mind. Here is a post talking about the issue and pointing out non-malicious issues: https://www.seancassidy.me/dont-pipe-to-your-shell.html https://www.seancassidy.me/dont-pipe-to-your-shell.html