Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The greater problem pattern is not running first inside of a sandbox and auditing the various food groups including dependencies, network interactions, modifications, and final results.

In reality, system packaging and configuration management tend to be the preferred way outs at scale rather than creating system entropy of ("here, run this script").

Btw, there is a tool on debian I abuse to replace system dependencies and package things (in lieu of checkinstall) called equivs. And, to find changes, I use cruft-ng which depends upon plocate.



Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: