Provider boundary
Keep the controlled channel within its exact scope
Listed modules
The private channel serves only the Devenia plugins named in its list.
Outside this scope
All remaining plugins stay with their own trusted providers.
Package acceptance
Checks that precede acceptance
Installed plugins remain unchanged when update information is unavailable or invalid.
01
Signed information
A valid Devenia signature is required before the update can be considered.
02
Approved destination
The package URL must remain under https://downloads.devenia.com/.
03
Published digest
Downloaded bytes must match the published SHA-256 hash.
Independent operation
Self-hosted operation
Update discovery, package delivery, and continued operation do not require external Git hosting.
Dependencies
What the update workflow requires
These four dependencies define the runtime, verification layer, and package source.
6.8 or later
WordPress 6.8 or laterSupplies native scheduled checks and the filesystem update workflow.
7.4 or later
PHP 7.4 or laterRuns the updater at runtime.
Required
PHP Sodium extensionVerifies the signed manifest before an update can be accepted.
Required
Devenia update channelProvides the manifest and content-addressed plugin packages.
Stable package
Put the channel in place
Use the stable self-hosted ZIP to install the updater. Native scheduled checks then look for eligible packages.
