Verification guidance
## Verification steps
1. Download the installer bundle, checksum, release notes, and any additional trust artifacts for this version.
2. Verify that `cerberus-installer-v0.1.0.tar.gz.sha256` matches the approved digest for `cerberus-installer-v0.1.0.tar.gz`.
3. Confirm the expected SHA-256 for `cerberus-installer-v0.1.0.tar.gz` is `7d641e4db657763f77489f9ec0f7c9f89b8b73c91346b3fe8d4f16bca5b8a662`.
4. Verify the detached signature `cerberus-installer-v0.1.0.minisig` with your minisign trust root.
5. Confirm the signature was produced by key `cerberus-release-2026q2`.
6. Review `cerberus-sbom-v0.1.0.spdx.json` (SPDX JSON) so your internal approval record includes the shipped component inventory.
7. Read the release notes and capture any known issues, upgrade constraints, and rollback requirements in your own change record.
8. Approve rollout only after your team has validated backups, maintenance windows, and rollback ownership.