Code from trusted repositories is an entirely different thing compared to running 'wget some_github_repo_shell_script | sh' . That said, the likes of Tailscale are setting a bad example.
You download a dmg and run it blindly? You download an exe and run it blindly. I wish it were in an rpm or deb coming from signed repos, but it's not so here we are
The script, and the code the script downloads, both come from the same repo and were written by the same developer.
If you've already decided you trust the author, what's the actual threat here?