fix: trust the system's certificate authorities when checking for updates
The update check pinned Mozilla's bundled roots, so behind a TLS-intercepting proxy
whose root lives only in the system store it failed with "invalid peer certificate:
UnknownIssuer". Downloads now trust the system's roots (keychain trust settings,
the Windows root store, the distribution's CA bundle) plus the bundled ones, which
cover a store that is missing or stale. Signature checks of builds are unchanged.
Assisted-by: claude-opus-5.5
bf28ad621cclover caruso committed on 10/2/2026, 7:55:30 AMparent01e73fd