• 1984@lemmy.today
    link
    fedilink
    arrow-up
    1
    ·
    2 months ago

    It’s not really an alternative yet, it’s in alpha versions…

    But I think it will be great in a year.

  • davehtaylor@beehaw.org
    link
    fedilink
    arrow-up
    1
    ·
    2 months ago

    Might be neat. Might check it out. But devs really need to stop asking me to install things by curling a script and piping it into my shell. There are better ways to do this. Doing this leaves a massive possible attack surface.

    • erwan@lemmy.ml
      link
      fedilink
      arrow-up
      0
      ·
      2 months ago

      No matter how they package it, running a binary downloaded from Internet has the same attack surface

      • 4dpuzzle@beehaw.org
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        You are right, except for one detail. Package managers almost always validate the packages using digital signatures, to avoid man-in-the-middle attacks. You don’t need to trust the network anymore. Shell scripts piped to a shell don’t have that protection. You still have to trust the developers and maintainers, though.

  • Auzy@beehaw.org
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    2 months ago

    What’s with these posts using misleading info recently?

    This doesn’t look anything like vs code.

    The only similarity might be they’re both ide’s