Check that an Edgely installer is genuine

How each installer is signed, where its checksum is published, and the commands that check a download before you run it.

Applies to
Edgely Console, Edgely Database Manager, Edgely Guard, Edgely Transfer
Updated

Every Edgely installer published on Downloads is signed before it is uploaded, and the site computes the SHA-256 checksum of each file as it stores it. This page says what is signed, by whom, and how to check a download on your own machine before you run it.

Checked on 2026-09-28 against the packaging and the files of the 2026-09-26 and 2026-09-27 releases: the macOS and Linux outputs below are what those files returned.

What is signed, and by whom

PlatformFilesSignatureSigned by
macOS.dmg (one universal image, Apple Silicon and Intel)Apple Developer ID, with a secure timestamp. The disk image is notarized by Apple and the notarization ticket is stapled to it. The app inside is signed with the hardened runtimeDeveloper ID Application: SIGEAD (CSX82KT7A3)
WindowsSetup.exe, .msix, .zipAuthenticode through Microsoft Artifact Signing, with an RFC 3161 timestamp. Every .exe and .dll inside is signed too. A .zip cannot carry a signature itself, so only the files inside it are signedSIGEAD SRL, a certificate that chains to Microsoft's own root: nothing to import
Linux.deb, .rpm, .AppImage (x86_64 and arm64)A detached OpenPGP signature, the .asc beside each file, plus a signed SHA256SUMS manifest. The packages carry no embedded signatureEdgely Release Signing <releases@edgely.io>

One file is not signed: the uninstaller that Inno Setup writes next to an installed app on Windows (unins000.exe).

The Linux key is RSA 4096, created on 2026-05-03 and valid until 2028-05-02. Its fingerprint:

F2BE 8279 C289 AA71 541A  767E 3B5A 5104 FB7A C7B0

The key itself is served at edgely.io/content/keys/edgely-release-signing.asc. Compare the fingerprint you import with the one above, which is also printed on the Security page.

Where the checksums are

The site computes the SHA-256 of every file when a release is uploaded, from the bytes it stores, and prints it on Downloads under each installer, labelled SHA-256. The same value is what the apps' own update check compares a downloaded installer against.

For Linux there is also SHA256SUMS, with its signature SHA256SUMS.asc, in the Alongside row under the Linux build. It lists the files under the names the build gave them (edgely-console_0.8.8-1_amd64.deb), while the file you download is named by the site (edgely-console_0.8.8_linux_x64.deb). So sha256sum -c SHA256SUMS reports every file as missing: compute the hash of your file and look for it in the list instead, or verify the file's own .asc, which signs its bytes whatever it is called.

macOS

Check the disk image before you open it. In Terminal, from the folder it was saved to:

shasum -a 256 <file>.dmg
codesign -dv --verbose=4 <file>.dmg
xcrun stapler validate <file>.dmg
spctl -a -t open --context context:primary-signature -v <file>.dmg

The first line prints the hash to compare with the one on Downloads. The others print, among their lines:

Authority=Developer ID Application: SIGEAD (CSX82KT7A3)
Notarization Ticket=stapled
TeamIdentifier=CSX82KT7A3
The validate action worked!
<file>.dmg: accepted
source=Notarized Developer ID

Once the app is in Applications, the same identity is on the app itself:

codesign --verify --deep --strict --verbose=2 "/Applications/Edgely Console.app"
spctl -a -vv "/Applications/Edgely Console.app"

Expect valid on disk, satisfies its Designated Requirement, source=Notarized Developer ID and origin=Developer ID Application: SIGEAD (CSX82KT7A3). Replace the app name with Edgely Database Manager, Edgely Guard or Edgely Transfer for the others. The notarization ticket is stapled to the disk image, so xcrun stapler validate is a check of the .dmg, not of the app.

Windows

In PowerShell, from the folder the file was saved to:

Get-FileHash -Algorithm SHA256 .\<file>
Get-AuthenticodeSignature .\<file>.exe | Format-List Status, SignerCertificate, TimeStamperCertificate

Get-FileHash prints the hash to compare with Downloads; certutil -hashfile <file> SHA256 gives the same value from a Command Prompt. For Setup.exe, Status should read Valid and the signer certificate should name SIGEAD SRL. With the Windows SDK installed, signtool verify /pa /v <file> checks a .exe or an .msix the same way; without it, open the file's Properties, then Digital Signatures, which lists SIGEAD SRL with its timestamp.

Microsoft SmartScreen can still show "Windows protected your PC" for a signed installer while the publisher's download reputation builds up. Choose More info: it should read Publisher: SIGEAD SRL. Unknown publisher there means the file is not the one Edgely published, so do not run it.

Linux

Import the key once, and check its fingerprint against the one above:

curl -fsSL https://edgely.io/content/keys/edgely-release-signing.asc | gpg --import
gpg --fingerprint releases@edgely.io

Then download the installer and its .asc (the link at the end of its row on Downloads) into the same folder, and verify:

gpg --verify <file>.asc <file>
sha256sum <file>

A good file prints Good signature from "Edgely Release Signing <releases@edgely.io>". The warning that follows it, "This key is not certified with a trusted signature", only says you have not signed the key yourself; the fingerprint comparison above is what establishes that it is Edgely's. The same two lines verify the manifest: gpg --verify SHA256SUMS.asc SHA256SUMS.

dpkg-sig --verify, debsig-verify and rpm --checksig do not apply: the packages carry no embedded signature, so they have nothing to check. The .asc is the signature.

Updates from inside the apps

When an app downloads an update itself, it compares the file's SHA-256 with the value the site publishes and deletes the file if they differ. It does not check a signature itself: it hands the installer to the operating system, and macOS or Windows checks the signature as it would for a download from the browser. Both come from edgely.io over HTTPS, so the checksum catches a damaged download, and the signature is what proves the publisher.

Mobile apps and IDE plugins

Edgely Console Mobile and Edgely Transfer Mobile come from the App Store and Google Play, and the IDE plugin from the JetBrains Marketplace, the Visual Studio Code Marketplace and the NetBeans Plugin Portal. None of them is hosted on this site, so there is nothing of ours to verify: install them from the store's own page, linked from Downloads.

Something missing or wrong?

Documentation gaps are bugs. Tell us which page you were reading and what you expected to find.

Send feedback →

Product names, logos and brands mentioned on this page are the property of their respective owners. They are used for identification and comparison only, and their use does not imply any affiliation with or endorsement by them.