What changed
- The pinned signed-update public key is embedded in macOS, Windows, and Linux packages.
- Windows verification checks the unpacked application resources before accepting the installer.
- Linux verification opens both the AppImage and Debian package and validates the embedded Ed25519 key.
- Expanded mobile navigation stays above page content instead of covering long headings on narrow screens.
Why this update matters
Version 0.2.1 Windows and Linux packages were published with valid checksums but without a resource required during application initialization. Version 0.2.2 replaces those packages with corrected, newly versioned artifacts and makes the same omission a release-gate failure.
Platform trust
macOS and Windows signing remains bypassable as disclosed in the download manifest. Use only the branded download host and compare the published checksum before installing.