Installation hygiene / SHA-256

Verify before
you run.

A checksum confirms that your downloaded file matches the file represented by the publisher’s checksum. It is one useful control, not a complete security audit.

Last updated:

Technical creative workspace representing verified software downloads
Visual brief / 01Use stable official sources and compare cryptographic checksums locally.

Download from the official product page or GitHub Release, then retrieve the checksum file from that same release. Never trust a checksum copied from the mirror that supplied an unfamiliar binary.

Windows PowerShell

CommandGet-FileHash .\downloaded-file.exe -Algorithm SHA256

macOS

Commandshasum -a 256 downloaded-file.dmg

Linux

Commandsha256sum downloaded-file.AppImage

Compare the complete value

The computed hash must match the official release value character for character. A mismatch means you should not run the file. Delete it, revisit the official release, and download again.

What a matching checksum does not prove

It does not independently audit source code, guarantee the publisher’s account was never compromised, or prove that early software will preserve every project correctly. Continue to use test files and backups.