Have a mirror of our checksums of all versions and validate the checksum of the download against the official repo and the mirror. This gives us the ability to validate correct updates and not having to worry about viruses in a breach in our system.