We take the security and safety of local-first code execution very seriously. If you discover a security vulnerability or execution safety bypass inside Ghostwheel or the Merlin Framework, please do not file a public GitHub issue.
Instead, please submit a detailed report using the Support Form on the application website under the Security category (routed at #support), which transmits submissions securely to our private support system.
- We will acknowledge receipt of your report within 48 hours.
- We will provide a status update and target fix timeline within 7 days.
- A public advisory and software update release will be coordinated once the patch is verified.