We need to kick off a dedicated security committee #61
Replies: 4 comments 5 replies
-
Hi Jessica - you can count me in on this. You captured many of the core elements well. I'll build upon what you listed to help clarify (at least for me) what we would want to include as deliverables of the committee:
|
Beta Was this translation helpful? Give feedback.
-
I have a question. I saw this earlier today and am interested in working on this. I’m not an expert per se, but I would love to join. Is there an Incident Response Plan in place? Although I am currently looking into Snyk, CodeQL, Trivy, and HashiCorp Vault to understand their capabilities. |
Beta Was this translation helpful? Give feedback.
-
Thank you so much for your comments! Will let this discussion run little longer to see if we can get more volunteers. Ideally, I would like to have someone from the tech teams or expert on SDKs to help out building the response plans and actions to take in parallel with day to day development. While I agree that all devs should be mindful and working on integrating security fixes in their code, having a security dedicated developer responsible to making sure this is happening across our repos would be nice to have. |
Beta Was this translation helpful? Give feedback.
-
After running Snyk on hiero-consensus-node locally, it identified 15 medium vulnerabilities in the codebase. There were 30 in total, but some were in the test code, which is not quite important for now. The general guideline is to have a CI/CD pipeline with security integration—something like
|
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
The Hiero project should consider the formation of a dedicated security committee to assist on the following tasks:
Please let me know if anyone would like to volunteer or can help with your expertise on these topics.
Beta Was this translation helpful? Give feedback.
All reactions