Security fixes are applied to the latest Kap Native release.
Do not open a public issue for a vulnerability or include recordings, credentials, personal data, or exploit details in a public discussion.
Use GitHub's private vulnerability reporting feature for this repository. The maintainer should acknowledge a complete report as soon as practical, assess its impact, and coordinate disclosure after a fix is available.
If private vulnerability reporting is not enabled yet, contact the repository owner privately through the contact method on their GitHub profile.
Public binary releases should be built from a tagged commit, signed with a Developer ID Application certificate, notarized by Apple, and accompanied by a checksum.