That said, we have not completely ditched idea of using NPM as installation mechanism, but we haven't convinced ourselves yet - maybe we should give it more thought though. What do you think is the benefit of using NPM vs our install script? Why would you trust NPM package more? Both NPM package and our install script are open source and you can see the code, both have equal execution privileges on your machine - why would you trust NPM package more?
SE says it better than me: https://security.stackexchange.com/questions/213401/is-curl-...
Particularly the first link, which outlines how to return different things depending on whether it's being piped into bash or not: https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...
In our case, server is github so that is allright, but script is on master, so that is tricky because we might update it at any moment, so you should check it once it is downloaded. That is a concern for sure, and there are ways to remove that concern.
One thing that goes to our benefit though is that we are not requiring `sudo`.
Thanks for pointing all this out, we will certainly be looking into better ways to install Wasp in the future!