Hacker News new | ask | show | jobs
by winstonwinston 54 days ago
These are often to install a repository and a package.

The alternative is to run something like rpm -i from_url.rpm to install some package directly. Which is not exactly any different from security perspective.

There is no easy way around this when the software is not in a system repo or without attestation in some way.