Report it privately, through this repository's Security tab ("Report a vulnerability"), not in a public issue. Say what you found, how to reproduce it, and which release and machine you saw it on.
A confirmed vulnerability is fixed in a release that reaches installed machines through the update channel. It is then described in a GitHub security advisory, crediting you if you want to be.
The newest production release. Production releases, 1.0.0 and later, update over the channel. Development releases (0.x) are pre-releases and get no fixes.
docs/threat-model.md says what Kryptik defends and what it does not. In scope:
- a way across a zone's boundary;
- a flaw in the update chain, the boot chain or the release signing;
- a flaw in Kryptik's own code (kryptikd, kryptik-wlproxy and the tools).
A flaw in an upstream package belongs to its upstream. Tell us as well: Kryptik pins and patches what it ships.