Security fixes are provided for the latest published version of Mergewell.
Do not open a public issue for a suspected vulnerability or include sensitive documents, logs, credentials, or personal data in a report.
Use the repository host's private vulnerability reporting feature when available. Otherwise, contact the repository owner privately and include the affected version, reproduction steps, and expected impact using non-sensitive sample files.