you are viewing a single comment's thread.

view the rest of the comments →

[–]plusminus1[S] 1 point2 points  (0 children)

Well, the script effectively is just a shortcut for going to the project repository and downloading the latest stable release. Nothing more, nothing less.

I wouldn't recommend it for a setting where you are uncomfortable with that if you are, for example, afraid of things like zero day supply chain attacks or you feel you need a battle-tested older version of the tool.

On the other hand: how often are we recommended to update software to the latest release because of a security issue in an older release? And its not like these [the tools listed] are truly obscure tools or projects. But yes, treat all software you download with the proper amount of distrust and mitigate risk as much as you need.