Finding
Mneme's public security policy says “Dioptron is in the design phase.” The identity-bearing vulnerability-reporting surface was copied without substituting the repository's product name.
Evidence
SECURITY.md:9-12 names Dioptron. Pinax carried the identical copied sentence and now tracks that instance in forkwright/pinax#2, confirming a scaffold substitution defect rather than an isolated typo.
Why this matters
Security reporters use this document to determine scope and trust that they have reached the intended project. A wrong product name makes the scope ambiguous and demonstrates that public policy artifacts can pass the repository's gate without being instance-correct.
Desired correction
Correct the Mneme instance and make project identity a required scaffold parameter from which SECURITY.md is generated or validated. Add a repo-identity gate that rejects unrelated fleet product names in identity-bearing files, and repair the canonical scaffold so future repositories cannot reproduce the defect.
Finding
Mneme's public security policy says “Dioptron is in the design phase.” The identity-bearing vulnerability-reporting surface was copied without substituting the repository's product name.
Evidence
SECURITY.md:9-12names Dioptron. Pinax carried the identical copied sentence and now tracks that instance in forkwright/pinax#2, confirming a scaffold substitution defect rather than an isolated typo.Why this matters
Security reporters use this document to determine scope and trust that they have reached the intended project. A wrong product name makes the scope ambiguous and demonstrates that public policy artifacts can pass the repository's gate without being instance-correct.
Desired correction
Correct the Mneme instance and make project identity a required scaffold parameter from which SECURITY.md is generated or validated. Add a repo-identity gate that rejects unrelated fleet product names in identity-bearing files, and repair the canonical scaffold so future repositories cannot reproduce the defect.