Verified Windows download
Only the exact release named by the current public manifest is offered. Older signed artifacts are stale and must not be installed.
Before running
- Verify the installer SHA-256 against
SHA256SUMS. - Open Properties → Digital Signatures and confirm the publisher and trusted timestamp in
release.json. - Reject the file if Windows cannot build the signature chain or if its source SHA differs from the manifest.
See update and rollback before replacing an existing installation.