Good reminder to pin dependency versions and verify checksums. SHA256 verification should be standard for any tool that makes network calls.