Need to verify that the downloaded u-boot file is correct size and has correct SHA256 checksum
The code of the librem5-flash-image/scripts/librem5_flash_image.py script verifies that the downloaded image file is the correct size in bytes and its SHA256 hashing checksum is correct. However, it doesn’t verify whether the downloaded u-boot file is correct. From a security point of view, the u-boot file is arguably just as important as the image.