Skip to content

Commit 32a25c0

Browse files
committed
doc: add meeting minutes (#1067)
1 parent 3de3a5a commit 32a25c0

File tree

1 file changed

+58
-0
lines changed

1 file changed

+58
-0
lines changed

meetings/2023-08-03.md

Lines changed: 58 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,58 @@
1+
# Node.js Security team Meeting 2023-08-03
2+
3+
## Links
4+
5+
* **Recording**: https://www.youtube.com/watch?v=fJNDQz9sAQo&ab_channel=node.js
6+
* **GitHub Issue**: https://github.com/nodejs/security-wg/issues/1059
7+
* **Minutes Google Doc**: https://docs.google.com/document/d/1eLSRK2nKeEnWD1YcEjjROYgVOfuVRPupi7BS5kIMH4I/edit
8+
9+
## Present
10+
11+
* Security wg team: @nodejs/security-wg
12+
* Marco Ippolito @marco-ippolito
13+
* Rafael Gonzaga @RafaelGSS
14+
* Michael Dawson @mhdawson
15+
* Ulises Gascon @ulisesgascon
16+
* Ruy Adorno @ruyadorno
17+
18+
## Agenda
19+
20+
## Announcements
21+
22+
*Extracted from **security-wg-agenda** labeled issues and pull requests from the **nodejs org** prior to the meeting.
23+
24+
- [x] Vulnerability Review - https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues
25+
* Wait NVD database to be fixed - Ref: https://github.com/vehemont/nvdlib/issues/26
26+
27+
- [X] OpenSSF Scorecard Monitor Review
28+
- Last report: https://github.com/nodejs/security-wg/pull/1066
29+
- Organic improvements due SAST analysis and variations based on increasing/decreasing unreviewed changesets
30+
- Ulises will apply stepsecurity auto-prs to all the repos in the org
31+
- We will focus on monitoring from now on using the issue generated.
32+
33+
### nodejs/security-wg
34+
35+
* Audit build process for dependencies [#1037](https://github.com/nodejs/security-wg/issues/1037)
36+
* No progress. Just for visibility.
37+
* Marco is investigating this initiative.
38+
39+
* Initiative for CII-Best-Practices for Node.js Projects [#953](https://github.com/nodejs/security-wg/issues/953)
40+
* Ulises will ask TSC for final approval in silver level
41+
* Ulises will prepare the next step: gold level to be reviewed by the team following the previous process.
42+
43+
* Permission Model - Roadmap [#898](https://github.com/nodejs/security-wg/issues/898)
44+
* Discussion around https://github.com/nodejs/security-wg/issues/1039. We agreed to follow option 2 (array/multiple flags)
45+
46+
* Automate security release process [#860](https://github.com/nodejs/security-wg/issues/860)
47+
* OSSF Funding approved by TSC (no objections until the end of the week)
48+
* OSSF is approved the budget is no objections are presented before the end of the week
49+
50+
* Assessment against best practices (OpenSSF Scorecards ...) [#859](https://github.com/nodejs/security-wg/issues/859)
51+
52+
## Q&A, Other
53+
54+
## Upcoming Meetings
55+
56+
* **Node.js Project Calendar**: <https://nodejs.org/calendar>
57+
58+
Click `+GoogleCalendar` at the bottom right to add to your own Google calendar.

0 commit comments

Comments
 (0)