Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

FWIW, Homebrew (no longer) deserves quite such ire as you will note that it explicitly does NOT pipe the result to a copy of bash: by downloading it first it and quoting it using a subshell it prevents the web server from being able to get interactive access.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: