Skip to content

Security policy identifies Mneme as Dioptron #2

Description

@forkwright

Finding

Mneme's public security policy says “Dioptron is in the design phase.” The identity-bearing vulnerability-reporting surface was copied without substituting the repository's product name.

Evidence

SECURITY.md:9-12 names Dioptron. Pinax carried the identical copied sentence and now tracks that instance in forkwright/pinax#2, confirming a scaffold substitution defect rather than an isolated typo.

Why this matters

Security reporters use this document to determine scope and trust that they have reached the intended project. A wrong product name makes the scope ambiguous and demonstrates that public policy artifacts can pass the repository's gate without being instance-correct.

Desired correction

Correct the Mneme instance and make project identity a required scaffold parameter from which SECURITY.md is generated or validated. Add a repo-identity gate that rejects unrelated fleet product names in identity-bearing files, and repair the canonical scaffold so future repositories cannot reproduce the defect.

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentation

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions