trust, checked

Verify by hand

Every release ships SHA256SUMS.txt and a minisign signature. The signing public key lives at /clawee-release.pub — it is also baked into the installer, which is the trust anchor that verifies each download automatically. To check a download yourself:

minisign -V -P "$(cat clawee-release.pub | tail -n1)" -m SHA256SUMS.txt -x SHA256SUMS.txt.minisig
f=<file>                                      # the file you downloaded
want=$(awk -v f="$f" '{ n = $2; sub(/^\*/, "", n); if (n == f) { print $1; exit } }' SHA256SUMS.txt)
got=$(shasum -a 256 "$f" | awk '{print $1}')  # sha256sum "$f" on Linux
if   [ -z "$want" ];        then echo "NO ENTRY for $f in SHA256SUMS.txt — do not install"
elif [ "$want" = "$got" ];  then echo "OK $f"
else                             echo "MISMATCH for $f — do not install"; fi

A failed signature check means the bytes are untrusted — do not install them.

Both files are published beside every zip; the downloads page links them per release.