Replies: 2 comments 1 reply
-
Homebrew is a third-party package manager and thus increases the attack surface, so it is not misleading. Users will not deal with homebrew so intensively, only to find out that individual aspects are more insecure than others. So it would be very negligent to recommend the program anyway. |
Beta Was this translation helpful? Give feedback.
-
Sure!
Both aren't good. Best for security is the AppStore. |
Beta Was this translation helpful? Give feedback.
-
This referenced security issue only relate to homebrew casks
When you use Homebrew to install formulae (aka packages) Homebrew does not ask for that permission.
I think it should be paraphrase to "Avoid using Homebrew casks"
Regarding the security of installing Homebrew packages this section from their FAQ page implies some security measures by use of macOS sandbox.
Beta Was this translation helpful? Give feedback.
All reactions