3 ms·
I'm using maki (https://maki.sh https://maki.sh), it has 1, 2 and 3.
by rescbr 2mo ago
I'm using maki (https://maki.sh https://maki.sh), it has 1, 2 and 3.
- coffinbirth 2mo agoMe too, maki in --yolo mode within an incus NixOS container, giving maki rootless (nested) podman and nix flakes powers (so it can install and run whatever tools it needs), with 100% ds4-flash it's extremely powerful and super cheap.
- Systemerror7A69 2mo agoI just wish it wouldn't ask me to pipe an install script directly to shell to install. Yes, I can probably inspect that but I do think installing through package managers is the best practice. It looks better than pi with XDG and not being JS but that is it's own red flag for me.
- rescbr 2mo agoI personally also don't like this, so use cargo to install it, it's in the readme. Takes a reasonable time to build on my X220, but on a modern computer it is plenty fast. cargo install --locked --git https://github.com/tontinton/maki.git maki
- lantry 2mo agoIs there a meaningful security difference between curl-pipe-bash and cargo install --git? Couldn't the cargo install include a buildscript that jumps right into a shell?
- rescbr 2mo agoSure, but you can review the git repo's content/commits in plain text, while curl-pipe-bash would require you to reverse engineer the binary that's downloaded. If somebody hacks the project's home page and switches the download location to a hacked binary, you'd be none the wiser. Of course, somebody could hack the repo and add a deliberate vulnerability as well, but at least you would have a trail of it.
- zbentley 2mo agoYou can review the contents of the git repo before building it. For curl | bash, you cannot. “But you can pipe to a fil—“ nope: https://tferdinand.net/en/why-curl-bash-is-a-dangerous-bad-habit/#can-a-server-detect-curl--bash https://tferdinand.net/en/why-curl-bash-is-a-dangerous-bad-h...