Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
a10r
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
a10r
1y ago
You are absolutely right, and that's a crucial distinction to make. ShellCheck is a linter, not a security scanner. Its role in vet isn't to find malware, but to act as an automated code quality check. A script full of shellcheck
2.
▲
by
a10r
1y ago
By the way, the excellent discussion here got me thinking about the next logical step for vet: supporting private environments. Running public scripts is great, but what about running deployment scripts from a private GitHub repo or setup s
3.
▲
by
a10r
1y ago
You're right, the README explains what vet does, but it doesn't do a great job of showing how it feels to use it. I'll definitely create a demo GIF for the page. To answer your questions directly in the meantime: - Pager or E
4.
▲
by
a10r
1y ago
Great point. A malicious actor could definitely do that. That’s why vet’s model doesn’t rely solely on ShellCheck—it’s just one layer. The key layer here is the diff. Even if the linter is silenced, the diff reveals any new suspicious # she
5.
▲
by
a10r
1y ago
That’s an excellent point, and thank you for raising it. You are 100% correct—relying on users to inspect a URL that could be spoofed with User-Agent trickery is a flaw in the original recommendation. It's a classic threat model that I
6.
▲
by
a10r
1y ago
Wow, thank you for taking the time to write such a detailed and in-depth critique. First, let me address the bugs you found, because you were 100% right. The wget user-agent issue revealed a significant and regrettable flaw in the server-si
7.
▲
by
a10r
1y ago
You're absolutely right—vet's scope is focused on securing the installer script itself, not the binary it downloads. The goal is to prevent the installer from being maliciously modified to, for example, skip its own checksum verif
8.
▲
by
a10r
1y ago
Love the idea! The two biggest hurdles for a security tool like this are LLM non-determinism and the major privacy risk of sending code to a third-party API. This is exactly why vet relies on ShellCheck—it's deterministic, rules-based,
9.
▲
by
a10r
1y ago
Hi HN, I'm the creator of `vet`. I've always been a bit nervous about the `curl | bash` pattern, even for trusted projects. It feels like there's a missing safety step. I wanted a tool that would show me a diff if a script ch
10.
▲
Show HN: Vet – A tool for safely running remote shell scripts
(getvet.sh)
89 points
by
a10r
1y ago
|
38 comments