Download from the official product page or GitHub Release, then retrieve the checksum file from that same release. Never trust a checksum copied from the mirror that supplied an unfamiliar binary.
Windows PowerShell
Get-FileHash .\downloaded-file.exe -Algorithm SHA256macOS
shasum -a 256 downloaded-file.dmgLinux
sha256sum downloaded-file.AppImageCompare the complete value
The computed hash must match the official release value character for character. A mismatch means you should not run the file. Delete it, revisit the official release, and download again.
What a matching checksum does not prove
It does not independently audit source code, guarantee the publisher’s account was never compromised, or prove that early software will preserve every project correctly. Continue to use test files and backups.
