Skip to content

Security policy identifies Mneme as Dioptron #2

Description

@forkwright

Finding

Mneme's public security policy says “Dioptron is in the design phase.” The identity-bearing vulnerability-reporting surface was copied without substituting the repository's product name.

Evidence

SECURITY.md:9-12 names Dioptron. Pinax carried the identical copied sentence and now tracks that instance in forkwright/pinax#2, confirming a scaffold substitution defect rather than an isolated typo.

Why this matters

Security reporters use this document to determine scope and trust that they have reached the intended project. A wrong product name makes the scope ambiguous and demonstrates that public policy artifacts can pass the repository's gate without being instance-correct.

Desired correction

Correct the Mneme instance and make project identity a required scaffold parameter from which SECURITY.md is generated or validated. Add a repo-identity gate that rejects unrelated fleet product names in identity-bearing files, and repair the canonical scaffold so future repositories cannot reproduce the defect.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentation

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions