@marcan
I think the scariest thing is to make curl|bash normalized and then people running this from random websites for every single tool all the time. Then I don't have the same guarantees that a project like Asahi has.
Maybe a project is malicious, or their website is compromised.
I'm mostly scared about malicious project personally.
@portaloffreedom @marcan I donβt see this as a counter-argument against curl|bashβif youβre pulling a malicious project or from a compromised backend, itβs already game over anyway? Itβs no different from pulling a random software dependency from whatever registry your ecosystem offers.