Comment by antihero
1 hour ago
Absolutely love the fact that they reference a "real package manager" like npm, which has been used in countless supply chain attacks, and brew, which can also run arbitrary scripts (though less likely in the mainline brew stuff, which many packages aren't able to be in).
Avoiding curlbashing is masking a deeper problem.
No comments yet
Contribute on Hacker News ↗