If you don’t trust the authors, don’t install it (duh).
Just because I trust the authors to write good rust/javascript/etc code, doesn't mean I trust them to write good bash, especially given how many footguns bash has.
Steam once deleted a users home directory.
But: I do agree with you. I think curl | bash
is reasonable for package managers like nix or brew. And then once those are installed, it's better to get software like the Bun OP mentions from them, rather than from curl | bash
.
Soatok's post about matrix opens with this: