Quest builds are now cached under the release file's own name, so an old cached patch can never be installed over a new one - not even by an older hub. This closes the last door on the stale-cache bug: previously every patch of a game shared one cache filename, and a hub that skipped the hash check would keep installing whatever old build was lying there.
Check what you got:
MultiverseVRHub.exe, 3,480,576 bytes
f03599eb7edbebf633727f0acc06f5718f2cd087ca0b1c08c7c8513a63589c22
MultiverseVRHub-1.0.12.zip, 2,856,132 bytes
c28321f6d164bed505e524387f371ba0f5a061ec78499f7c3b15e668fa2c1261
Run this next to the file & compare:
certutil -hashfile MultiverseVRHub.exe SHA256
Doesn't match, don't run it. VirusTotal on that same hash: https://www.virustotal.com/gui/file/f03599eb7edbebf633727f0acc06f5718f2cd087ca0b1c08c7c8513a63589c22
Antivirus warnings:
It isn't code signed yet, so Windows throws up the blue "unrecognized app" box the first time & a few scanners flag it on machine learning guesses alone.. 4 of 71 on VirusTotal, the usual Wacatac.B!ml & ML.Attribute.HighConfidence unsigned-exe stuff. The other 67 see nothing.
No ports or game files are hosted anywhere.. every install grabs the official vanilla release from that project's own GitHub plus my patch, applied on your machine. Each patch's source is up on its game's repo.
I'm working on getting it signed through Microsoft so the warnings go away.