cross-posted from: https://jlai.lu/post/8476122

Zed on Linux is out!

You are viewing a single thread.
View all comments View context
5 points

You are right, except for one detail. Package managers almost always validate the packages using digital signatures, to avoid man-in-the-middle attacks. You don’t need to trust the network anymore. Shell scripts piped to a shell don’t have that protection. You still have to trust the developers and maintainers, though.

permalink
report
parent
reply
2 points

Shell scripts have md5 signatures

permalink
report
parent
reply

Free and Open Source Software

!foss@beehaw.org

Create post

If it’s free and open source and it’s also software, it can be discussed here. Subcommunity of Technology.


This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

Community stats

  • 1.5K

    Monthly active users

  • 408

    Posts

  • 2.1K

    Comments