Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For those saying curl | sh isn't that bad, remember that the codecov script was breached, and attackers used it to upload environment variables containing secrets, and it took months to get noticed [1].

If they had provided a versioned URL and checksum validation as part of their copy & paste snippet, the breach would have been noticed right away.

[1] https://www.reuters.com/technology/codecov-hackers-breached-...



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: