Confirm that the app you're using was built from our public source by an auditable, signed pipeline — not just a claimed commit hash.
With the GitHub CLI, this checks the signed provenance attestation binding the running image to the commit and workflow that produced it:
{@build.verify_command}
The digested filenames embed each bundle's content hash — your browser downloads exactly these, so the front-end is verifiable end to end.
Looking for plain-language answers about your funds and safety? See how it works & your safety.
We can't find the internet
Attempting to reconnect
Something went wrong!
Attempting to reconnect