Once you agree to install software, it had local access with your accounts privileges.
Once you agree to install software, it had local access with your accounts privileges.
and SSL has nothing to do with it. packages are not cryptographically signed either and once on the system can easily become root.
{ # Prevent execution if this script was only partially downloaded
# installation code here
} # End of wrapping
I'm not sure if this is a bulletproof solution.Put it in ~/opt with xstow, and add ~/opt/bin to your path, ~/opt/man to your man-path, ~/opt/include, ~/opt/lib... to the various paths.
In this case, it seems like a lot of effort to get a tgz-archive just to download a single executable. I gather it's distributed as an archive in order for the Changelog, Readme and License to be available -- but as it's all downloaded from github anyway, it's hard to see why that really matters (rather than just have -h spit out a link or two).
As, if you're using a normal, full-featured web browser, there's no way of knowing if what you select, is what you copy and then paste -- it would probably be better to just link directly to the latest binary release for the various platforms (linux32, linux64, linux-arm, OSX 32bit, OSX 64bit) -- and let the user save the binary somewhere.
Limit the "command line instructions" to:
go get github.com/asciinema/asciinema
rather than fighting idiomatic go practices.If you really want to be clever, why not just use 0install?
hashpipe does exactly that:
Eh? Both debs and rpms can be signed with GPG keys.
rm -rf /$INSTALLER_TEMP_DIRSeriously - you pretty much just have to make a .dep and a .rpm and you're covered. Is that so hard?
Author already did that [1] and has both .deb and .rpm: