Download verification
PhotoCraft checksums — verify a download with SHA-256
Compare the checksum of the exact file you downloaded with its line in the official release manifest.
Get the matching checksum manifest
Use SHA256SUMS.txt (opens a new tab) (0.0 MB) from v0.7.0 release assets (opens a new tab). Keep it with your downloaded package. A manifest from another version is not the reference for your file, even when the platform is the same.
- Note the downloaded filename, including version and architecture.
- Open
SHA256SUMS.txtand find that exact filename. - Calculate the downloaded file’s SHA-256 digest using one of the commands below.
- Compare every hexadecimal character with the corresponding manifest line.
The following commands are examples to run on your own downloaded files. This site has not downloaded and hashed each release package.
Official sources: PhotoCraft README (opens a new tab) · Latest GitHub release (opens a new tab).
Calculate SHA-256 on your computer
Open a terminal in the folder containing the download, or use its full path. On Windows, this PowerShell example checks the x64 MSI:
Get-FileHash -Algorithm SHA256 -LiteralPath '.\photocraft-0.7.0-windows-x64.msi'On macOS, check the Universal DMG:
shasum -a 256 'photocraft-0.7.0-macos-universal.dmg'On Linux, check the x86_64 AppImage:
sha256sum 'photocraft-0.7.0-linux-x86_64.AppImage'Replace the filename with the actual ZIP, installer or bundle you chose. On Linux, sha256sum --check SHA256SUMS.txt checks every manifest entry, so missing packages you did not download can produce file-not-found messages. Compare your one required file explicitly when checking a single download.
Understand a match or mismatch
A match means your file has the digest recorded in the chosen manifest. It helps detect a partial transfer, changed file or wrong package. A checksum does not independently establish who published the manifest, validate a code-signing identity, or guarantee the application’s behavior.
If the result differs, do not run that file. First confirm exact name and version, then obtain a fresh package and manifest from the same official release. Keep the mismatch details if you report a reproducible problem.
Once it matches, follow your platform’s installation guide and test with an image copy. Keep the release tag and package filename in your notes so a later update does not confuse this verification result.