Skip to content

Security: rioncm/hammer-spoons

Security

SECURITY.md

Security Policy

Supported versions

Security fixes are applied to the current main branch. This project uses undocumented macOS interfaces, so compatibility with future macOS releases is not guaranteed.

Reporting a vulnerability

Please use the repository host's private vulnerability-reporting feature when available. If private reporting is unavailable, contact the maintainer privately before opening a public issue that contains exploit details or sensitive information.

Include the macOS and Hammerspoon versions, the affected commit, reproduction steps, and the observed impact. Do not include passwords, tokens, personal data, or unrelated system logs.

Scope

Space Manager runs locally and does not make network requests. On macOS 26 and newer it compiles and executes native/space_move_helper.m, which uses private SkyLight APIs to move a window between Spaces. Reports involving unexpected command execution, unsafe path handling, or unintended access to windows are in scope.

There aren't any published security advisories