Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Amen. I avoid any container-based or blindly 'curl |sudo' install (the latter only after manual inspection of such a script).

Apps which only offer containers are untrustworthy black boxes. And it indicates devs who are too ignorant and/or lazy to make even basic efforts at distribution-neutral or portable code.

Gentoo and Funtoo keep devs honest to some extent, as packages must be built, not just slurped down in whatever alien form the project decided to use.



I'm not sure about other container solutions, but Docker isn't a black box at all. It's fully introspectable -- I often dump a container's file system to see what's actually included.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: