Verify a release with its live report
After installers are published, our release workflow submits them to VirusTotal. When the current report is available, the results, file hashes and report links appear below; otherwise this page says that results are unavailable.
Files and checksums
These are the exact files the download buttons serve. Compare the SHA-256 of your download with the value here: if they match, you have the file we published.
Check it yourself
Run this against the file you downloaded and compare the result with the hash above.
What this proves, and what it does not
- VirusTotal is an independent Google service that runs a file past 70+ antivirus engines at once. We publish whatever comes back, detections included.
- A fresh installer sometimes trips one or two engines on heuristics alone: it is new, it is signed by us rather than by a household name, and it ships a coding agent that runs commands. When that happens we name the engine and link the report instead of rounding the number down.
- The macOS build is signed with our own certificate rather than an Apple Developer one, so the first launch shows a Gatekeeper warning. That is about the signature, not about the scan.
- A matching hash proves the file is byte-for-byte the one we published. It is the check worth doing whenever you downloaded from anywhere but this site.