Post #236853
2026-02-05 17:48 UTC
@sethmlarson@mastodon.social @bagder@mastodon.social Couldn't that be achieved by replacing the "sh" pipe target with a (python) script that does the download, signature verification, and (assuming it passes) execs "sh". E.g.:
$ curl http://... | safe-sh -
Certainly, that could be PoC to see how practical it would be.
Replies (0)
No replies.