A security-focused release: every open finding from an external security audit plus a full branch review is closed here. With thanks to Texas Cyber Command for a thorough, actionable report. See the changelog for the full list.
Signed Windows & macOS builds
Thanks to @token2, who signs the Windows and macOS builds on their EV certificate as a contribution to the project:
keyroost-v0.7.5-windows-x86_64-signed.zip— Authenticode-signed (TOKEN2 Sàrl, Sectigo EV). Recommended for Windows: it clears the SmartScreen/Defender warnings that unsigned binaries trigger. The GUI executable also carries the app icon.keyroost-v0.7.5-macos-universal2-signed.pkg.zip— signed & notarized.pkginstaller.
The unsigned keyroost-v0.7.5-* archives are keyroost's own CI builds, covered by GitHub build-provenance attestation (verify with gh attestation verify <file> -R framefilter/keyroost). The signed and attested builds are complementary — Authenticode vouches for the signed ones, CI provenance for the attested ones. Signed builds may land a little after release, since signing happens out-of-band.
Full Changelog: v0.7.4...v0.7.5