Hacker News new | ask | show | jobs
by georgyo 972 days ago
Even if the particular script is not used, the just file there is actually much worse.

Literally everything is running scripts directly from the internet, without any version pinning or check summing.

There is no way to run the same build twice and have any confidence that the result was the same.

https://github.com/ublue-os/bluefin/blob/41bdf294c20a3903f4a...