Repository navigation
Keep 2.21.4
Keep 2.21.4 fixes security findings and makes release validation faster.
- Email validation uses a bounded linear check while preserving the existing address policy. Mobile activity filters use a fixed local path with encoded filter values. Recovery trial credentials are clearly identified as synthetic API tokens; account passwords continue to use Argon2.
- The installer, launchers, Compose image, and installation guides consistently use 2.21.4. Fast regression checks now catch release-version mismatches before native image validation.
- Required main commits build and fully validate amd64 and arm64 images once. Approved publication reuses those exact images, matching sources, and original evidence, and rejects missing, expired, altered, or wrong-commit validation records.
- Allowlisted documentation changes can skip native image validation after the current version is published. Independent source downloads run concurrently with all checksum, signature, and source-coverage checks preserved. Superseded validation drafts are removed while protecting current and active work.
Both native images passed the application, security, installation, recovery, and corresponding-source checks in main validation run 37174545292. Windows PowerShell and filesystem checks also passed. GitHub CodeQL reports no open alerts. Full Windows Docker Desktop and physical-device fresh-install acceptance remain separate manual checks.
Use brspoon/keep:2.21.4 to pin this release or brspoon/keep:stable to follow the current stable release. The image supports Linux amd64 and arm64. Back up configuration and data before upgrading both Keep services together.
Matching source archives, license notices, checksums, and the original native verification evidence are attached below. See the installation guide, changelog, and Docker Hub repository.