32-bit
wixmachine scopegithub.com · known platform- SHA-256
- 786a25282a466c384e45d4d974ccd8d0528cd3cb70f1858bf7510266b095f2bb
- Product code
- {8290B40E-B469-415C-9060-4AE4DE263642}
by Kitware · BSD-3-Clause
CMake is a cross-platform, open-source build system generator.
These URLs are the ones Kitware declares in its own manifest. We do not proxy or shorten them, and we do not host a copy.
Run this against the file on disk. If the output does not match the hash below, the file is not what Kitware published. Delete it.
Windows · PowerShell
Get-FileHash "cmake-4.4.0-windows-x86_64.msi" -Algorithm SHA256macOS · Linux
shasum -a 256 "cmake-4.4.0-windows-x86_64.msi"Expected output
82db53fcb8f38be541a26093489f39d5ed79b71b53cd121fc32a022a6bf310b1
| Signal | Finding | Points |
|---|---|---|
| SHA-256 hash published | 6 of 6 installers ship a SHA-256 hashWithout a published hash there is no way to prove the file you downloaded is the file the publisher built. | 30 / 30 |
| Binary provenance | 6 on a recognised distribution platformThe strongest signal against a repackaged installer: the file should come from the publisher, not from a mirror nobody vouches for. | 29.8 / 35 |
| Served over HTTPS | 6 of 6 over HTTPSAn installer fetched over plain HTTP can be modified in transit. | 15 / 15 |
| Release recency | last release about 1 months agoSoftware that has not shipped in years accumulates unpatched vulnerabilities. | 15 / 15 |
| Licence declared | BSD-3-ClauseA declared licence tells you what you are actually allowed to do with the software. | 5 / 5 |
Every version with a published manifest, newest first. Useful when you need an older build for compatibility.