Skip to content

Security: GhostwheeI/project-merlin

SECURITY.md

Security Policy

Reporting a Vulnerability

We take the security and safety of local-first code execution very seriously. If you discover a security vulnerability or execution safety bypass inside Ghostwheel or the Merlin Framework, please do not file a public GitHub issue.

Instead, please submit a detailed report using the Support Form on the application website under the Security category (routed at #support), which transmits submissions securely to our private support system.

Process and Disclosure

  • We will acknowledge receipt of your report within 48 hours.
  • We will provide a status update and target fix timeline within 7 days.
  • A public advisory and software update release will be coordinated once the patch is verified.

There aren't any published security advisories