Zed is a modern open-source code editor, built from the ground up in Rust with a GPU-accelerated renderer.

  • bionicjoey@lemmy.ca
    link
    fedilink
    arrow-up
    195
    arrow-down
    3
    ·
    2 months ago

    Installer is piping curl into shell

    I thought we were past this as a society 😔

      • timestatic@feddit.org
        link
        fedilink
        arrow-up
        1
        ·
        2 months ago

        As long as they just use it for their community and don’t fucking lock documentation behind discord I don’t really care. But this trend has been so annoying. Due to this I’m in so many servers I have to quit a server just to join a new one

    • kazaika@lemmy.world
      link
      fedilink
      arrow-up
      27
      ·
      2 months ago

      I mean its already in the nix repos as well as homebrew which means its essentially taken care of

        • pukeko@lemm.ee
          link
          fedilink
          English
          arrow-up
          5
          ·
          2 months ago

          It appears to be a couple of versions behind … and have some issues with dynamically linked libraries that hinder LSPs. Neither of these is Zed’s fault. I’m sure the packaged version will be up to date momentarily (given the interest in Zed, sooner rather than later). Not sure how easy the LSP thing will be to fix, though there are some workarounds in the github issue.

          • priapus@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            5
            ·
            2 months ago

            yeah the editor is being updated way too fast for nix to keep up. I’m sure it’ll be easier once it has its stable release. I see the have a nix flake in the repo, it would be great if they added a package to the outputs instead of just a devshell, nix users could easily build it from master or whichever tag they want.

            There are solutions in this issue to the LSP issue. The editor would need to be built in an fhs-env, or they will need to find a way to make it uses binaries installed with nix instead of the ones it downloads itself. VSCode had a similar issue, so there is a version of the package that let’s you install extensions through nix, and another that uses an fhs-env that allows extensions to work out of the box.

    • WFH@lemm.ee
      link
      fedilink
      English
      arrow-up
      17
      arrow-down
      1
      ·
      2 months ago

      A curl piped into a shell or some unofficial packages from various distros.

      At this point I don’t get why these projects are not Flatpak-first.

      • ParetoOptimalDev@lemmy.today
        link
        fedilink
        arrow-up
        6
        arrow-down
        11
        ·
        2 months ago

        Flatpak is worse for debugging, development, and reproducibility.

        Its good for user friendly sandboxing, portability, and convenience.

    • Telorand@reddthat.com
      link
      fedilink
      arrow-up
      6
      arrow-down
      1
      ·
      edit-2
      2 months ago

      That was my first thought as well, but I will say that uBlue distros had a signing issue preventing updates recently, due to an oversight with how they rotated their image signing keys, and the easiest (maybe only?) solution was to pipe a curl command to sh. Even though uBlue is trustworthy, they still recommended inspecting the script, which was only a few lines of code.

      In this case, though, I dunno why they don’t just package it as a flatpak or appimage or put it up on cargo.

      Edit: nvm, they have some package manager options.

    • TunaCowboy@lemmy.world
      link
      fedilink
      arrow-up
      6
      arrow-down
      13
      ·
      2 months ago

      It is worrisome that all the smug elitists are too incompetent to just leave off the pipe and review from stdout, or redirect to a file for further analysis.

      Same people will turn around and full throat the aur screaming ‘btw’ to anyone who dares look in their direction.

      • skilltheamps@feddit.org
        link
        fedilink
        arrow-up
        11
        arrow-down
        1
        ·
        2 months ago

        By that logic you have to review the Zed source code as well. Either you trust Zed devs or you don’t - decide! If you suspect their install script does something fishy, they could do it just as well as part of the editor. If you run their editor you execute their code, if you run the install script you execute their code - it’s the same thing.

        Aur is worse because there usually somebody else writes the PKGBUILD, and then you have to either decide whether to trust that person as well, or be confident enough for vetting their work yourself.

      • krolden@lemmy.ml
        link
        fedilink
        arrow-up
        3
        ·
        edit-2
        2 months ago

        Eh using aur is a bit different since most of# them pull the projects git repo directly anyway. Yeah the project might have vulns but thats on you to inspect before building it as well as the pkgbuild itself