remote_file with a url should include a type of hash option to verify the downloaded file is what we expected