Skip to content

Security: mopsprotocol/mops-lite

Security

SECURITY.md

Security Policy

MOPS-Lite is a reference SDK and developer starting point. Reports may relate to runtime behaviour, conformance artefacts, packaging, release process, repository automation, or documentation that could mislead implementers about safe usage.

Supported versions

The current supported review line is:

  • mops-lite v0.1.0

Earlier pre-release states are historical unless explicitly referenced by a maintained release branch or tag.

Reporting process

Please do not publish sensitive report details in a public issue.

Use GitHub private vulnerability reporting if enabled for this repository. If private vulnerability reporting is not enabled, contact the maintainers through GitHub and provide only enough public information to establish a private reporting path.

What to include

Useful reports include:

  • affected file, test, workflow, or package artefact;
  • why the issue affects release integrity or implementation safety;
  • a minimal reproduction where appropriate;
  • whether the problem affects runtime behaviour, generated artefacts, CI, packaging, or documentation;
  • suggested mitigation if known.

Scope

Security reports may include issues in canonicalisation, hashing, validation gates, chain integrity, storage parsing, schema handling, package distribution, or examples that could cause unsafe implementation behaviour.

The local JSONL adapter is explicitly single-process scoped and is not designed as a hardened multi-tenant storage system. Reports that rely only on documented profile limitations may be closed as out of scope, but reports showing behaviour beyond those limitations are welcome.

Ordinary issues

Documentation problems, test failures, conformance concerns, and ordinary SDK defects may be reported through repository issues after the repository becomes public.

There aren't any published security advisories