Discussion in #94 For released versions, we should download the tarball, and check it against an embedded SHA-256