Objective
Harden install.sh with checksum pinning guidance and clear rollback instructions for failed upgrades.
Target area
install.sh, docs
Context
Curl-to-bash installs need stronger integrity UX for security-conscious users.
Requirements
- Document checksum verification flow
- Support version pinning
- Provide rollback steps if binary misbehaves
Acceptance criteria
Pull request merge requirements
Pull requests that resolve this issue must not be merged until all of the following are true:
- All required CI checks are green on the latest commit of the PR (build, tests, lint/format, and any workflow jobs required by branch protection).
- The branch has no merge conflicts with the target branch (
master / default), and a clean merge or rebase is possible without unresolved conflicts.
- Review feedback is addressed, and the change remains focused on this issue’s acceptance criteria.
Contributors should run the local CI-equivalent checks before opening or updating the PR (see CI_ENFORCEMENT.md and CONTRIBUTING.md).
Objective
Harden
install.shwith checksum pinning guidance and clear rollback instructions for failed upgrades.Target area
install.sh, docsContext
Curl-to-bash installs need stronger integrity UX for security-conscious users.
Requirements
Acceptance criteria
Pull request merge requirements
Pull requests that resolve this issue must not be merged until all of the following are true:
master/ default), and a clean merge or rebase is possible without unresolved conflicts.Contributors should run the local CI-equivalent checks before opening or updating the PR (see
CI_ENFORCEMENT.mdandCONTRIBUTING.md).