32-bit
exestatic.rust-lang.org · publisher domain- File name
- rustup-init.exe
- SHA-256
- f574ea2bd6d798b6072b3a45e3053f3cabcc2cb48d6b4bd59b661b41d675b31a
- Silent install
- -y -q
by The Rust Programming Language · Apache-2.0 or MIT
The Rust toolchain installer
These URLs are the ones The Rust Programming Language declares in its own manifest. We do not proxy or shorten them, and we do not host a copy.
More than one architecture below. Check which one your Windows is if you are not sure.
Run this against the file on disk. If the output does not match the hash below, the file is not what The Rust Programming Language published. Delete it.
Windows · PowerShell
Get-FileHash "rustup-init.exe" -Algorithm SHA256macOS · Linux
shasum -a 256 "rustup-init.exe"Expected output
86478e53f769379d7f0ebfa7c9aa97cb76ca92233f79aa2cc0dbee2efaac73c7
Got a different hash, or one you cannot place? Paste it into the hash checker and it will tell you which program and version it belongs to, past releases included.
The unattended switch below is the one The Rust Programming Language declares in the installer manifest, not one we guessed by trying flags.
32-bit · publisher-declared
.\rustup-init.exe -y -qRun it from the folder holding the downloaded file, in a terminal opened as administrator when the package installs for all users. Silent means no window and no prompts, so check the exit code rather than waiting for something to appear: 0 is success and 3010 means it worked but wants a reboot.
| Signal | Finding | Points |
|---|---|---|
| SHA-256 hash published | 3 of 3 installers ship a SHA-256 hashWithout a published hash there is no way to prove the file you downloaded is the file the publisher built. | 30 / 30 |
| Binary provenance | 3 on the publisher's own domainThe strongest signal against a repackaged installer: the file should come from the publisher, not from a mirror nobody vouches for. | 35 / 35 |
| Served over HTTPS | 3 of 3 over HTTPSAn installer fetched over plain HTTP can be modified in transit. | 15 / 15 |
| Release recency | last release about 6 months agoSoftware that has not shipped in years accumulates unpatched vulnerabilities. | 15 / 15 |
| Licence declared | Apache-2.0 or MITA declared licence tells you what you are actually allowed to do with the software. | 5 / 5 |
Yes, in the sense we can actually verify: the installer downloads from rust-lang.org, which is a domain we have tied to The Rust Programming Language.
Every one of the 3 installers on this page comes with the SHA-256 The Rust Programming Language declared, so you do not have to take our word for it: hash the file you downloaded and compare.
What this does not tell you is whether the software itself is any good, or whether you want what it does once installed. A publisher can ship something you would rather not run and the download is still authentic. We answer the question we can measure and leave the other one to you.
If Windows says “Windows protected your PC” when you run it, that is SmartScreen reporting reputation, not a malware verdict — it shows up on perfectly legitimate software from small publishers and on releases that are simply new. The reverse matters more: no warning does not mean the file was checked.
How the 100/100 score is calculated · why the source matters more than the reputation
Windows ships with a package manager, and this program is in it. The identifier below is the one Microsoft's repository uses, which is also where the download URL and hash on this page come from.
Install
winget install --id Rustlang.Rustup --exactUpgrade later
winget upgrade --id Rustlang.RustupWhy --exact: without it winget matches on name as well as identifier, and a search that returns more than one package makes it stop and ask rather than install. Pinning the identifier is what makes the command safe to put in a script.
Not installing anything, or getting an error back? The commands that actually come up covers upgrading everything at once, what --include-unknown is for, and why winget can be missing from a machine that should have it.
The version history of Rustup: the Rust toolchain installer, each release with the download URL the publisher declared at the time and the SHA-256 to check it against. Useful when an update breaks something and you need to downgrade to a build that worked.
We do not host any of these files and never re-upload them, which is the difference between this and an old-version download site.
D33375F474F105E529FF3225529A8D6A79A8A4E23F6EAB88FBA427889E538F34
88D8258DCF6AE4F7A80C7D1088E1F36FA7025A1CFD1343731B4EE6F385121FC0
DE9F7D29CCD39EFA59A3DDA3EC363B396E09B92681229B9B8F6AAA4C84285E9C
494BBEB52BD102891BE4E7E5ADC74EEB1C532ADFDC33D51AE1AA9FD2FF5F1048
7B83039A1B9305B0C50F23B2E2F03319B8D7859B28106E49BA82C06D81289DF6
9054AD509637940709107920176F14CEE334BC5CFE50BC0A24A3DC59B6F4D458
1DA78BB84B8F25265A0E36BC883520FD9038AC0DFFD5C9F0EF9FAFDFCA86A17D
EF50173E02CB8ADFBCF675414353060C2349550C9767674545560F0F67D24EE0
5AE5C31DE49625C30EE89D756F08D1D08BDC119A6B747C2577E93A9C7DE12219
011185BD2BFCE79F5389C19247B6E45242D17C697FE135EC6CDD23948445803A
193D6C727E18734EDBF7303180657E96E9D5A08432002B4E6C5BBE77C60CB3E8
5F4697EE3EA5D4592BFFDBE9DC32D6A8865762821B14FDD1CF870E585083A2F0
6F9AD11ABD642A7CBA4EE6F386B84D56045EE12F921C5D9832913D937E0F3547
743BBD6B5A622DDC5C5234CE0FD3EAB6CA74499A119FBF484DC55755A6A7E443
A984F32312A49224DEACB4B301B78305FE72A47C6141B1FFD4B8D6F00051F4CF
365D072AC4EF47F8774F4D2094108035E2291A0073702DB25FA7797A30861FC9
F7DDACCE04969A59F7080A64C466B936D7C2AE661B4FDA44BE8FE54AAC0972EC
2220DDB49FEA0E0945B1B5913E33D66BD223A67F19FD1C116BE0318DE7ED9D9C
Publishers take old builds offline without warning, so a link here can stop working even though the hash stays correct forever. If you already have the file, the hash is what matters: it tells you whether what you have is what they published.
Every Rustup: the Rust toolchain installer version with a published manifest, newest first. The most recent ones are listed above with their file names and hashes.
Not related to Rustup: the Rust toolchain installer — just other entries, each with its own official URL and published hash.