@bagder Hey. They're talking about your stuff over at OSI discuss. Not sure if you knew or not. Maybe you could shed some light on the topic. https://discuss.opensource.org/t/curl-bash-trust-as-a-privilege/1011
`curl | bash`: Trust as a privilege?

We often hear that using curl | bash is insecure. That no one should ever pipe remote scripts directly into a shell. And yet… the biggest open source projects do it all the time. Docker installs with curl | sh. nvm, oh-my-zsh, Homebrew – all follow the same pattern. And we trust them. Why? Because they’re popular? Because they have a logo? Because their websites look professional? Meanwhile, smaller projects are held to a different standard. They are questioned, scrutinized, distrusted – e...

OSI Discuss
@marcia thanks for highlighting that. I don't think I have anything particular to add there for now.