Skip to content
Blackfrost_AI software / FrostBytePUBLIC BETA
FROST/BYTEFile sharing. With a fresh coat of frost.

Download verification

0.4.0

Verify the Blackfrost release

The authoritative list of all six release files is authenticated by a detached GPG signature. Verify the signature first, then the checksum of the package you downloaded. Linux x64 is available as an AppImage and Debian package; this remains beta software.

SHA-256 file list · GPG signature (.asc) · Blackfrost public key

Publisher key fingerprint
585A 5E6E D8E5 0B38 90A4 4CBB 5CFE 2F13 0753 BD6E

Save these three files beside your downloaded package. First display the key fingerprint:

gpg --show-keys --with-fingerprint FrostByte-release-key-585A5E6ED8E50B3890A44CBB5CFE2F130753BD6E.asc

It must match the full fingerprint above. For independent confirmation, contact Blackfrost support through a channel you already trust. A “Good signature” alone is not proof of who owns a key.

Then verify using only that public key:

gpg --dearmor --output FrostByte-release-key.gpg FrostByte-release-key-585A5E6ED8E50B3890A44CBB5CFE2F130753BD6E.asc
gpg --no-default-keyring --keyring ./FrostByte-release-key.gpg --no-auto-key-retrieve --verify SHA256SUMS-0.4.0.asc SHA256SUMS-0.4.0 && \
  sha256sum --check --ignore-missing SHA256SUMS-0.4.0

Your downloaded package must report OK. Stop if the signature fails, the key differs, the checksum fails, or no file is verified. Do not run the installer in that case. Missing packages for other operating systems are intentionally ignored.

A GPG signature authenticates this file list; it is not Apple notarization, Windows signing, an APT repository, or a guarantee that software is bug-free. The AppImage still uses --no-sandbox; the Debian package installs its sandbox helper.

Get FrostByte · Installation help