2 ms·
I just wish it wouldn't ask me to pipe an install script directly to shell to install. Yes, I can probably inspect that but I do think installing through packa
by Systemerror7A69 2mo ago
I just wish it wouldn't ask me to pipe an install script directly to shell to install.
Yes, I can probably inspect that but I do think installing through package managers is the best practice.
It looks better than pi with XDG and not being JS but that is it's own red flag for me.
- rescbr 2mo agoI personally also don't like this, so use cargo to install it, it's in the readme. Takes a reasonable time to build on my X220, but on a modern computer it is plenty fast. cargo install --locked --git https://github.com/tontinton/maki.git maki
- lantry 2mo agoIs there a meaningful security difference between curl-pipe-bash and cargo install --git? Couldn't the cargo install include a buildscript that jumps right into a shell?
- rescbr 2mo agoSure, but you can review the git repo's content/commits in plain text, while curl-pipe-bash would require you to reverse engineer the binary that's downloaded. If somebody hacks the project's home page and switches the download location to a hacked binary, you'd be none the wiser. Of course, somebody could hack the repo and add a deliberate vulnerability as well, but at least you would have a trail of it.
- zbentley 2mo agoYou can review the contents of the git repo before building it. For curl | bash, you cannot. “But you can pipe to a fil—“ nope: https://tferdinand.net/en/why-curl-bash-is-a-dangerous-bad-habit/#can-a-server-detect-curl--bash https://tferdinand.net/en/why-curl-bash-is-a-dangerous-bad-h...