> The easiest way to download the latest version is with the following command:
> curl https://clickhouse.com/ | sh
Like, sure, there is some risk downloading a binary or running an arbitrary installer. But this is just nuts.
> The easiest way to download the latest version is with the following command:
> curl https://clickhouse.com/ | sh
Like, sure, there is some risk downloading a binary or running an arbitrary installer. But this is just nuts.
Please don't say that. It denigrates the work of all the packagers that actually keep our supply chains clean. At least in the major distributions such as Red Hat/Fedora and Debian/Ubuntu.
The distro model is far from perfect and there are still plenty of ways to insert malware into the process, but it certainly is far better than running binaries directly from a web page. You have no idea who have access to that page and its mirrors and what their motives are. The binary isn't even signed, let alone reviewed by anyone!
Previously discussed here: https://news.ycombinator.com/item?id=11348798
Article now resides here: https://www.davidhaney.io/npm-left-pad-have-we-forgotten-how...
It's literally exactly the same thing