Hacker News new | ask | show | jobs
by jwilk 3040 days ago
--force-yes is bad, but for reasons that have nothing to do with replay attacks.

This option effectively disables package authentication. This is because it forces "yes" answer to all questions, including the question about installing unauthenticated packages.