Artifact security status
- Windows assets ending in
-unsigned.exeare validation installers without Authenticode signing. - Android assets ending in
-android-debug.apkuse a runner-generated debug certificate and are for testing only. - Verify every downloaded file against
SHA256SUMS.txtand the GitHub artifact attestation.