update_script() compared the upstream tag against /opt/${APP}_version.txt but
never wrote it back, so the stored version stayed at whatever the installer
wrote. Every subsequent run took the update branch, wiping the web root and
re-downloading the full release archive even with no new upstream release.
Write the tag after a successful update, matching what the installer already
does at install/alpine-it-tools-install.sh:42.
Closes#17420