Hi, I have a case where a manually modified secret contains a kubectl.kubernetes.io/last-applied-configuration label with three-way-merge, containing the whole JSON of the previous secret version. The label is unfortunately printed out unredacted through helm diff. Maybe the plugin should handle this.