| ▲ | walrus01 4 hours ago | |
I mean it's probably not, I just haven't got used to it yet. It's about the same level of security as installing a windows app on win2000 25 years ago and blindly downloading a .exe off the internet and running it to get into the install wizard. But indeed I also kind of blindly trust that whatever I'm getting from the debian trixie officially gpg-signed packages isn't backdoored. One thing I do not do as a matter of practice is install things with a ridiculous number of recursive npm dependencies. | ||
| ▲ | uecker 2 hours ago | parent [-] | |
I do not blindly trust anything, and come to the conclusion that downloading binaries from Debian trixie is a lot more safe. There is a world of difference between "curl | sh" and downloading from a curated package repository maintained by a respected community with well-defined processes. | ||