Updates and channels
The application and plugins have separate channel selections. macOS uses a ZIP for first installation and a DMG for updates.
Alpha
The newest test builds, which may change quickly.
Beta
More functionally complete builds intended for broader testing.
Stable
Verified releases intended for normal use.
Verify signature and file
Download the package and its .asc file from the same release details. Check the public key fingerprint through an independent trusted channel, import the key and run gpg --verify. Then compare the complete SHA-512 with the catalog. Do not run the file if verification fails or values differ. Replace <file> with the actual filename.
CH-J primary signing key fingerprint:
0D92 778A D8EC F85C 80E3 9248 48F2 433A D9CD F453
Public OpenPGP key · Release archive
gpg --show-keys --fingerprint ch-j-signing-public.asc gpg --import ch-j-signing-public.asc gpg --verify <file>.asc <file>
Calculate SHA-512 for your system:
# macOS shasum -a 512 <file> # Linux sha512sum <file> # Windows PowerShell Get-FileHash -Algorithm SHA512 <file>
The OpenPGP signature verifies the distributed file. It does not replace a trusted Windows publisher signature or Apple notarization; alpha releases may therefore trigger system warnings.