How QCUL Captures the Exact Update Package

Exact-package capture is the bridge between laboratory evidence and production: QCUL stores the actual update ZIP used by the test instead of relying only on a version number.

Capture sequence

  1. Resolve the selected Joomla extension/core update metadata.
  2. Download the package into protected run-specific QCUL storage.
  3. Record the filename and byte size.
  4. Calculate SHA-256 over the package bytes.
  5. Validate vendor checksum metadata when available.
  6. Pass only the allowed run-owned package path/hash into the laboratory runtime.

Protected storage

The package must remain inside QCUL’s allowed private package vault. Runtime calls include signed authorization and the expected SHA-256 so the lab does not accept an arbitrary filesystem path/package.

Later production use

Before production install, QCUL rechecks the stored package and hash, copies that same tested package to Joomla temporary storage, hashes again, then invokes Joomla Installer/core update logic.

Keep the evidence chain intact

The value of How QCUL Captures the Exact Update Package depends on preserving one traceable transition: known starting version, one selected update, exact captured package/hash, resulting laboratory version, automated evidence, and human review. Avoid manual package installs or unrelated lab changes that make that chain ambiguous before a production decision.


Community Discussion

Want to compare update-testing workflows, share practical tips, or discuss how you use this QCUL feature? Visit the QC Update Laboratory Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.