I would remove the bitbucket link from your post

The reason is that anyone quoting you (or indeed you yourself!

) could change the link to point to modified software (and change the SHA256 to match) that, for example, logs people's passphrases who use it. Anyone remember EvilThomas?

As an example, I have changed the name in the quote above to include 'fkstl' which means, Nxt 'Fakestealing' account and repointed it to megupload.
Did anyone notice that I'd changed it?

Don't worry, it isn't a proper file but it my point is it could be. People might not know the real versions are uploaded to bitbucket under jl's name and would be happy using a mega address

And it looks completely legit!
I would use
https://nxtforum.org/nrs-releases for safety and then name the version when spreading the word. Then just quote any text in the change log without download links