data:image/s3,"s3://crabby-images/66f95/66f95b4d217bf0d4e3a7bd8aac165e2f778cb0fc" alt=""
data:image/s3,"s3://crabby-images/bc4ae/bc4ae0393d200f9dd41eaddfb25c8d1895742343" alt=""
You can use things like dependabot or renovate to update versions in a controlled manner, rather than automatically using the latest of everything.
On the other side, when it comes to docker containers, you can use github actions or some other CI/CD system to automate the container build.
Just because I trust the authors to write good rust/javascript/etc code, doesn’t mean I trust them to write good bash, especially given how many footguns bash has.
Steam once deleted a users home directory.
But: I do agree with you. I think
curl | bash
is reasonable for package managers like nix or brew. And then once those are installed, it’s better to get software like the Bun OP mentions from them, rather than fromcurl | bash
.