add cryptographic assurances when fetching the toolchain