`mdrs selfupdate` replaced the running binary with whatever the release
endpoint returned, checking only that the transport succeeded. Nothing
proved the archive was the one the release publishes.
- Compare the downloaded archive against the release's `.sha256` asset
and abort the update on a mismatch.
- Report a release that publishes no checksum as unverified, rather
than letting its absence pass for a verified download.
- Exclude `.sha256` assets when matching the archive for the build
target: those assets carry the target name too.
- Write and upload a checksum beside every archive, from the Gitea
release workflow and the three local build scripts.