logoalt Hacker News

kingstnapyesterday at 8:18 PM1 replyview on HN

You can curl stuff and run it just gotta have hashes in place.


Replies

theamkyesterday at 9:35 PM

In theory, yes.

In practice, very rarely. Lots of 'curl | sh' do secondary fetches, and those don't come with hash checks. And even if they come with hash checks _today_, there is no guarantee next version won't quietly remove them.