Please report suspected vulnerabilities privately through GitHub Security Advisories.
Do not open a public issue containing:
- plaintext content;
- encryption keys;
- credentials;
- private storage paths;
- exploit details that would put existing stores at risk.
Include the affected revision or version, the violated invariant, the expected and observed behavior, reproduction information, and any known recovery or data-integrity implications.
Keep has not published a stable release. Security fixes will target the active development line until a supported-version policy is established.