Comment by bee_rider
5 hours ago
The intended workflow is to download the install scripts, download the source code, read them both, and then start running things. That’s how Open Source is secured. Piping from bash to curl is just the most obvious warning flag.
And practically zero people are actually using this "intended workflow" in the real world.
Yes, the status quo is quite bad, which is why it gets complained about a lot.