# Platform Quality and Security Workstream
The PQS workstream is dedicated to the assessment, maintenance and enhancements to security and quality of the Mojaloop platform, encompassing connectivity to participating DFSPs (including transactions) and the security of hub operator portals, and of the Mojaloop Open source codebase and related artefacts.
# Business Justification
This ensures the Mojaloop platform quality & security is maintained; vulnerability management is done and mitigations planned. Working with adopters, community members to improve security and quality incrementally. Provide features to support compliance and address gaps.
# Contributors
| Workstream Lead | Contributors |
|---|---|
| Sam Kummary | Juan Correa Devarsh Shah Shuchita Prakash Shashi Hirugade |
# Latest Update (Summary)
The Platform Quality and Security workstream redirected effort during the PI to conduct a detailed review of Mojaloop’s software supply chain security following wider industry supply chain attacks, arising from the application of AI in this area. This resulted in significant improvements to the licence scanning process through adoption of the Linux Foundation’s SPDX licence standard and remediation of weaknesses in existing tooling. With this work largely complete, the team has returned to routine vulnerability management while preparing repositories for the next release candidate.
# Applicability
This version of this document relates to Mojaloop Version 17.2.0 (opens new window)
# Document History
| Version | Date | Author | Detail |
|---|---|---|---|
| 1.2 | 28th July 2026 | Paul Makin | Added latest update |
| 1.1 | 4th December 2025 | Paul Makin | Added latest update |
| 1.0 | 25th November 2025 | Paul Makin | Initial version |
