Have you ever run "./configure" on some open source code you downloaded? That's no more safe. In this case, curl | bash is probably more safe because at least it came over HTTPS.
That is if you don't do a
view ./configure
first and go through it. You do take a look at the configure scripts, don't you?Example: expat's autoconf script is over twenty two thousand lines long.