`mdrs selfupdate` replaced the running binary with whatever the release
endpoint returned, checking only that the transport succeeded. Nothing
proved the archive was the one the release publishes.
- Compare the downloaded archive against the release's `.sha256` asset
and abort the update on a mismatch.
- Report a release that publishes no checksum as unverified, rather
than letting its absence pass for a verified download.
- Exclude `.sha256` assets when matching the archive for the build
target: those assets carry the target name too.
- Write and upload a checksum beside every archive, from the Gitea
release workflow and the three local build scripts.
Add scripts/build-release-linux.sh for building musl-linked release
archives (x86_64 and aarch64) on Linux. Uses `cross` for cross-
compilation so no host toolchain beyond Docker/Podman is required.
Also add mdrs-*.tar.gz and mdrs-*.zip to .gitignore to prevent
generated release archives from being tracked.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>