Vault Prospector 0.3.0-preview.20
0.3.0-preview.20 is the current unsigned Windows x64 manual-test Preview.
Fixed
- Install and verify update now completes the update workflow inside Vault Prospector instead of opening a website and requiring a separate manual download.
- One explicit action checks the newest trusted release, downloads its exact MSI, verifies the GitHub digest and adjacent SHA-256 checksum, rehashes the retained file immediately before launch, starts Windows Installer with administrator approval, and exits the app only after the installer starts.
- Release metadata redirects, non-GitHub asset redirects, malformed or incomplete downloads, checksum mismatches, and post-verification file changes fail closed.
Important upgrade note
Preview 19 contains the old discovery-only updater and cannot gain this behavior retroactively. Install Preview 20 once from the public release. Starting with Preview 20, Settings > Product updates > Install and verify update handles future available updates inside the app.
Download and trust
The direct installer is intentionally unsigned and displays Unknown Publisher. Preview 20 verifies the GitHub asset digest and adjacent checksum in-app, but it does not independently verify the Sigstore bundle. The public verification guide remains available for that additional check. Trusted Windows signing or Store identity remains required for GA.
Validation boundary
The governed build passed 504/504 tests with zero warnings or errors and no known vulnerable NuGet packages. Protected PR CI, exact-main Windows/portable/lifecycle gates, and immutable-tag publication passed. Fresh downloads of all five public packages matched their GitHub digests and adjacent checksums, and all five Sigstore bundles verified against the exact tagged workflow identity.
The exact public Preview 20 MSI and a real Preview 20-to-later in-app upgrade have not yet been installed and exercised by the product owner. No installed/live pass is claimed.
See the release evidence.