Security fixes are applied to the current main branch. This project uses undocumented macOS interfaces, so compatibility with future macOS releases is not guaranteed.
Please use the repository host's private vulnerability-reporting feature when available. If private reporting is unavailable, contact the maintainer privately before opening a public issue that contains exploit details or sensitive information.
Include the macOS and Hammerspoon versions, the affected commit, reproduction steps, and the observed impact. Do not include passwords, tokens, personal data, or unrelated system logs.
Space Manager runs locally and does not make network requests. On macOS 26 and newer it compiles and executes native/space_move_helper.m, which uses private SkyLight APIs to move a window between Spaces. Reports involving unexpected command execution, unsafe path handling, or unintended access to windows are in scope.