Fortunately docs go into better detail, https://zed.dev/docs/linux
I'm on Debian anyway so who am I kidding expecting this to be in apt :D
Fortunately docs go into better detail, https://zed.dev/docs/linux
I'm on Debian anyway so who am I kidding expecting this to be in apt :D
I'm thinking of the recent xz attack. Imagine how bad that would have been if xz was commonly installed via `curl | sh`.
All this is to say `curl | sh` is probably fine if the org is reputable, however, you should be having second thoughts if this is a repo ran with a bus factor of 1.
Their full install docs is like 5 lines of code so it is much preferred to do it that way. Every distribution is different. The ideal install here would be to add a unique apt repo for zed and then it becomes part of my normal update process. Updating a binary in a directory is not the end of the world... but I would prefer to know that upfront versus needing to hunt down where it was placed in order to do the updates.
edit its 4 lines. seeing this is much preferred to parsing a bash script that is intended to support all distributions:
wget https://zed.dev/api/releases/stable/latest/zed-linux-x86_64.tar.gz
mkdir -p ~/.local
tar -xvf zed-linux-x86_64.tar.gz -C ~/.local
ln -sf ~/.local/bin/zed ~/.local/zed.app/bin/zedIn the end, at some point you either have to inspect every line of code yourself or trust others to have done it for you. Package managers fall into the latter category.
I then proceeded to install tens of thousands of lines of code I didn’t read onto my machine.
My point? People really seem to be bike shedding this install script bit. If I was a malicious actor I wouldn’t be hiding the bad parts in the install script.
It is incredibly ironic when looking at your post history that you state that you have "been involved on[sic] [...] the nuances of interface and user experience". Does my comment not meet that very criteria?
It's been in the main repos since May.
Same as running random .exe from emails, but even without M$ signature.
Apt packages also have the root access, but official repositories at least have some paper trail and release process.
It doesn't require root. You can read it before you run.
Then read the script you complain about.
With proper installers I never read it's install scripts.
A debian package relieves them of the overhead you describe by having a few people do the work for anyone else that uses the package.
> You just described how the script is less convenient to meet the preferences of the commenter you replied to.
Well… no. The person I reply to doesn’t say anything about preferences. They want to know how to update the software, the script is the best reference.
What about AUR or Fedora packages? ;D
That script for the editor is code, too…